Safe sourcing
Where to get each tool
Nothing is stored on NetPulse24 — not now, not later. Below: the real home of each tool, plus the few checks to run before a fresh binary lands on an admin laptop.
Last reviewed · Husanjon Ruzaliev, editor
Why we don’t keep copies
Admin utilities are a favourite disguise for malware precisely because the people who use them run them with elevated rights. Look-alike sites borrow the names of popular SSH clients and scanners, then serve a repackaged binary that looks right and behaves right, with something extra attached. The defence is a habit rather than a product: get every tool from the organisation that makes it, and check what you received before it runs. A copy from us could never be more trustworthy than the original, so there are no copies here — only links to each vendor’s own product page.
The vendor’s own page for all 8 tools
| Tool | Made by | Licence | Official page | What to check |
|---|---|---|---|---|
| Angry IP Scanner | Anton Keks | GPLv2 | Visit angryip.org | Start at angryip.org, which points to the project’s own release page. The Windows setup package bundles a Java runtime; the standalone Windows build and the Linux packages expect Java 21 or newer. |
| Advanced IP Scanner | Famatech | Freeware | Visit advanced-ip-scanner.com | Windows only. The file’s Authenticode signature should name Famatech. The same package offers an install or a portable run. |
| LizardSystems Network Scanner | LizardSystems | Paid for business | Visit lizardsystems.com | Windows only. The product page publishes a SHA-256 for the current build — compare it with Get-FileHash before running. |
| PuTTY | Simon Tatham | MIT | Visit chiark.greenend.org.uk | The home page lives on chiark.greenend.org.uk. It publishes signed checksum files, and the Windows builds are code-signed. There is also a Microsoft Store listing from the same team. |
| WinSCP | Martin Přikryl | GPLv3 | Visit winscp.net | winscp.net only. Confirm the Authenticode signature is valid and names the WinSCP author, and compare the checksum shown for the release. |
| Sysinternals Suite | Microsoft | Freeware | Visit learn.microsoft.com | learn.microsoft.com, the Microsoft Store, or live.sysinternals.com. Every binary is signed by Microsoft Corporation. |
| Wireshark | Wireshark Foundation | GPLv2 | Visit wireshark.org | Grab it from wireshark.org, where each release has its SHA-256 hashes in a signed file. Windows and macOS packages are code-signed; the Windows setup also offers to add Npcap. |
| LizardSystems LanCalculator | LizardSystems | Paid for business | Visit lizardsystems.com | Windows only. Get it from the LanCalculator page on lizardsystems.com; if a SHA-256 is listed next to the current build, compare it with Get-FileHash. |
Links open the vendor’s site in a new tab. NetPulse24 is not any of these vendors and receives nothing when you follow a link.
A five-minute check before first run
- Arrive by address, not by ad. Type the vendor’s domain or use the links above. Look-alike domains usually add a word (“-free”, “-client”, “-app”), swap the top-level domain, or sit on a generic hosting subdomain.
- Walk away from anything unusual. None of the tools on this site asks you to disable antivirus, type a password to open an archive, or accept “recommended offers”. A page that does is not the vendor.
- Check the Authenticode signature on Windows. Right-click the file, open Properties, then Digital Signatures — or from PowerShell:
Get-AuthenticodeSignature .\the-file-you-received.exe | Format-List Status, StatusMessage, SignerCertificateStatusshould beValid, and the signer should match the vendor in the table. - Compare the published hash. Wireshark, PuTTY and WinSCP publish checksums for their releases, and LizardSystems lists one for Network Scanner. Compute yours and compare every character, not just the first few:
# Windows (PowerShell) Get-FileHash .\the-file-you-received.exe -Algorithm SHA256 # macOS Terminal shasum -a 256 the-file-you-received # Linux shell sha256sum the-file-you-received - Stage it once, then distribute. If a tool goes on every admin laptop, verify one copy, store it on an internal share with its hash alongside, and deploy from there — through Intune, a GPO software installation, or winget pointed at the vendor’s own package — rather than having five people fetch it five ways.
Package managers and stores
winget’s community repository includes manifests for several of these tools, and each manifest points at the vendor’s own release URL with a SHA-256 attached, so winget refuses a file that doesn’t match. PuTTY and the Sysinternals tools are also listed in the Microsoft Store by their own publishers. On Linux, your distribution’s packages for Wireshark and PuTTY are signed by the distribution and are usually the simplest trustworthy route.
When antivirus complains
Security products sometimes flag scanners, remote-execution tools such as PsExec, and packet-capture drivers as “potentially unwanted”, because those are exactly the capabilities an intruder would want. If a file you obtained from the vendor passes the signature and hash checks above, raise a change request and exclude just that file or its folder. Turning protection off across the board is never the fix — and a site advising you to do so is not your friend. If a signature or hash doesn’t match, delete the file and start again from the vendor’s page.
After it’s installed
Point it only at networks and hosts you administer, or have written permission to work on. TheLAN scanner comparison helps you pick a sweeper, and thehow-tos walk through the common jobs with the actual settings and commands.