Remote Desktop — check NLA, spray creds, and connect. Watch for BlueKeep.
nmap -p3389 -sV -sC $tnmap -p3389 --script rdp-ntlm-info,rdp-vuln-ms12-020 $thydra -L users.txt -P pass.txt rdp://$tnxc rdp $t -u users.txt -p passwords.txtxfreerdp /v:$t /u:<user> /p:<pass> /cert:ignore +clipboardrdesktop -u <user> -p <pass> $t