> For the complete documentation index, see [llms.txt](https://docs.easy2patch.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.easy2patch.com/deployment/installing-wsus-console/wsus-manegement-tool.md).

# Wsus Manegement Tool

<https://dl.easy2patch.com/dl/arksoft/WSUSMgmt/WSUSMgmtTool.exe>

**WSUS Management Tool — Free WSUS and SCCM Software Update Admin App**

WSUS Management Tool is a free Windows utility that streamlines patch management for Windows Server Update Services (WSUS) and Microsoft Configuration Manager (MECM / SCCM). It delivers bulk decline/undecline/delete of updates, phased server cleanup, orphan category removal, WSUS signing certificate lifecycle management, third-party update analysis, offline HTML reporting with embedded Chart.js graphs, scheduled automation, auto-decline rules, Slack/Teams/Email/ServiceNow notifications, and full audit logging — all from a single console. Built on .NET Framework 4.7.2, portable, no installer required. Ideal for WSUS admins, SCCM engineers, and Windows patch management teams on Windows Server 2016/2019/2022/2025.

| **Feature**                                          | **Description**                                                                                                                           |
| ---------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- |
| **Bulk Decline / Undecline / Delete**                | Parallel bulk action (8 threads) on filtered updates; includes undecline — which the WSUS SDK does not expose natively                    |
| **Rich Text Filtering**                              | #digits, #nodigits, #len>=5, #num>=5000000, /regex/, wildcard, and NOT toggle                                                             |
| **Cache + Delta Refresh**                            | On connect the list loads instantly from disk cache; only updates arrived since last sync are pulled from WSUS                            |
| **Superseded Chain Viewer**                          | View an update's superseded ancestors and descendants in a single screen                                                                  |
| **Category Manager**                                 | Detect orphan / duplicate categories (like a rogue duplicate ARKSOFT); delete updates in a category + trigger cleanup                     |
| **WSUS Signing Certificate Management**              | Wipe a broken/private-key-less certificate from all 3 stores + SDK, install self-signed or a PFX, distribute to Root and TrustedPublisher |
| **Phased Server Cleanup**                            | Splits the WSUS Server Cleanup Wizard into 4 phases so it survives WCF timeouts; reports disk space freed                                 |
| **WSUS and SCCM Sync Trigger**                       | One-click WSUS sync and SCCM software update sync; 4 fallback paths across WMI and PowerShell                                             |
| **HTML Reports (Offline)**                           | Full WSUS report + SCCM-3rd-party report; Chart.js is embedded, so the report opens without internet                                      |
| **Interactive HTML Tables**                          | Sticky headers, per-table search box, click-to-sort columns (numeric + text aware)                                                        |
| **SCCM WMI + SQL Integration**                       | Queries v\_UpdateInfo, v\_AuthListInfo, v\_CIAssignment, v\_DeploymentSummary in the CM\_\<SITECODE> database                             |
| **Compliance Rollup**                                | Required / Installed / Not Applicable / Unknown metrics from v\_UpdateSummaryPerCollection at the All Systems collection                  |
| **3rd Party Update Analytics**                       | Vendor + Product breakdowns, deployed / superseded / expired distributions, dashboard charts                                              |
| **Auto-Decline Rules**                               | Rule engine on Superseded / Expired / NotApproved / age / product / classification criteria; run now or schedule                          |
| **Scheduled Tasks**                                  | In-app cron-like scheduler — cleanup, reports, sync, and rule engine run automatically at a chosen time                                   |
| **Slack / Teams / Email / ServiceNow Notifications** | Push cleanup / decline / sync results to any configured channel                                                                           |
| **Audit Log**                                        | Every bulk action (decline, delete, cert change, cleanup) is written to a timestamped, user-stamped log file                              |
| **CVE / MSRC Enrichment**                            | Enrich CVEs found in Bulletin/Title fields with CVSS scores via the NVD API                                                               |
| **Update Aging Report**                              | Age distribution of approved updates; flags such as "no deployment in 6+ months"                                                          |
| **Bandwidth Analysis**                               | WSUS content directory size + classification-based footprint estimate                                                                     |
| **Compliance Drift**                                 | KB-level delta comparison between two cache/report snapshots taken at different times                                                     |
| **Deployment Failure Root Cause**                    | SCCM deployments sorted by error count (SQL-backed)                                                                                       |
| **PDF Export**                                       | One-click HTML → PDF via Edge / Chrome / wkhtmltopdf headless                                                                             |
| **SCCM Client Force Scan**                           | Pick machines from the auto-loaded WSUS list; trigger Software Updates Scan + Deployment Evaluation Cycle via WMI                         |
| **Not-Contacted-Since Widget**                       | List of machines that haven't reported to WSUS in the last N days                                                                         |
| **Reboot Pending Report**                            | Machines stuck in "installed / pending reboot" state                                                                                      |
| **WSUS Content Folder Analysis**                     | Content directory size + top 20 largest subfolders                                                                                        |
| **Duplicate SUG Detector**                           | Detects Software Update Groups that share the exact same member set                                                                       |
| **SUSDB Reindex**                                    | Auto rebuild/reorganize on all SUSDB indexes with fragmentation > 5%, then sp\_updatestats                                                |
| **Cert Store Schema Compare**                        | Thumbprint-level compare of WSUS certificates across LocalMachine\WSUS, Root, and TrustedPublisher stores                                 |
| **WSUS Log Viewer**                                  | Filtered viewer for logs under %ProgramFiles%\Update Services\LogFiles\\                                                                  |
| **Filter Presets**                                   | Save complex filter combinations (e.g. "Critical + last 30 days + not-approved") under a name                                             |
| **Grid Column Manager**                              | Right-click to show/hide columns; layout persists to settings.json next to the exe                                                        |
| **Dashboard**                                        | On connect, KPI cards for Total / Approved / Declined / Superseded / Computer states                                                      |
| **Multi-Tenant Connection Switch**                   | Session switcher across multiple WSUS/SCCM environments; each environment gets its own cache/settings                                     |
| **Portable, No Installer**                           | Single exe (\~600 KB) + Newtonsoft.Json.dll; cache/settings/logs live next to the exe; runs on Windows Server and Windows 10/11           |
