Safe sourcing
Where to get each tool
There are no files on TopNet247, and there never will be. Below: the real source of every tool we review, and the checks to run before any of them gets admin rights.
Signed off by Husanjon Ruzaliev (editor) · checked
Why this matters more for admin tools
A tool you run as a domain or local administrator inherits all of that access. A tampered copy of a session manager or a remote process tool is therefore far more dangerous than a tampered media player: it runs with the keys to your servers. Look-alike sites borrow well-known admin tool names and bundle extras into repackaged copies. The only sensible habit is to get each tool from the organisation that makes it and check the signature before it runs. We could not make a copy safer than the original, so we do not make copies — every link below goes to the vendor’s own product page.
The vendor’s own page for all 10 tools
| Tool | Made by | Licence | Official page | What to check |
|---|---|---|---|---|
| LizardSystems Terminal Services Manager | LizardSystems | Personal free / paid | Visit lizardsystems.com | From lizardsystems.com only. Check the Authenticode signature before installing it on an admin workstation. |
| LizardSystems Remote Desktop Audit | LizardSystems | Commercial | Visit lizardsystems.com | From lizardsystems.com only. Run it from an admin workstation, not on the session hosts themselves. |
| LizardSystems Remote Process Explorer | LizardSystems | Personal free / paid | Visit lizardsystems.com | From lizardsystems.com only. Check the file’s digital signature before first run. |
| Sysinternals Suite | Microsoft | Freeware | Visit learn.microsoft.com | From learn.microsoft.com, the Microsoft Store, or \\live.sysinternals.com\tools. Signer should be Microsoft Corporation. |
| Windows Admin Center | Microsoft | With Windows licence | Visit learn.microsoft.com | From Microsoft’s Windows Admin Center pages on learn.microsoft.com. Signer should be Microsoft Corporation. |
| Remote Server Administration Tools (RSAT) | Microsoft | With Windows licence | Visit learn.microsoft.com | Nothing to fetch: add it in Settings > Optional features or with Add-WindowsCapability. Ignore third-party “RSAT” packages. |
| ManageEngine ADManager Plus | ManageEngine (Zoho Corp.) | Commercial | Visit manageengine.com | From manageengine.com. Install on a dedicated Windows server, never a domain controller you cannot rebuild. |
| Netwrix Auditor | Netwrix | Commercial | Visit netwrix.com | Start from a trial request on netwrix.com; the product itself is delivered through the vendor’s own portal. |
| Angry IP Scanner | Anton Keks | GPLv2 | Visit angryip.org | Follow the release links from angryip.org itself; on Linux, a distribution package is fine. |
| Wireshark | Wireshark Foundation | GPLv2 | Visit wireshark.org | Every release on wireshark.org comes with a signed list of SHA-256 hashes, and the Windows and macOS builds carry code signatures. |
Each “Visit” link opens the maker’s own site in a new tab. None of these vendors is us, and following a link earns us nothing.
Five minutes of checking before a server sees it
- Arrive at the right address. Start from the table above or type the maker’s domain by hand, and read the address bar before running a single file. Look-alike domains usually add a word (“-free”, “-tools”, “-pro”) or change the ending.
- Walk away from wrappers. Close any page that wants you to turn off endpoint protection, type a password to unpack an archive, or tick “recommended offers”. No tool reviewed here requires any of those steps.
- Check the Authenticode signature. Right-click the file, choose Properties and openDigital Signatures, or check it in PowerShell:
Get-AuthenticodeSignature .\the-file-you-received | Format-List Status, StatusMessage, SignerCertificateStatusshould readValid, and the signer should be the vendor in the table. - Compare the hash when the vendor publishes one. Wireshark publishes signed SHA-256 values for every release, and some vendors print a hash on the product page. Compare every character:
Get-FileHash .\the-file-you-received -Algorithm SHA256 - Try it somewhere disposable first. Install new admin tools on a test VM or a single admin workstation, not straight onto a domain controller or session host. Note which services, scheduled tasks and firewall rules the install adds.
Tools that are already part of Windows
RSAT is not a separate package on current Windows: on Windows 10 (October 2018 update or later) and Windows 11 Pro or Enterprise it is a set of optional features. Add it with Settings or from an elevated prompt:
Get-WindowsCapability -Online -Name RSAT* | Where-Object State -ne Installed
Add-WindowsCapability -Online -Name Rsat.ActiveDirectory.DS-LDS.Tools~~~~0.0.1.0On Windows Server, the same consoles are added through Server Manager or Install-WindowsFeature. Any website offering a separate “RSAT package” for current Windows should be treated with suspicion.
Keep endpoint protection on
Some security products flag remote-process or session tools as “potentially unwanted” because of what they can do. When that hits a file that came from the vendor and passed the signature and hash checks above, take it with whoever owns your endpoint policy and add a narrow, documented exception — never switch protection off wholesale. If the signature or hash does not match, delete the file and start again from the vendor’s site.
After you have it
Point each tool only at systems you administer, with your organisation’s authorization. For help choosing, see the drawers for RDS and session tools,Active Directory management andserver triage, or the how-tos.