Launch cmd.exe as local system w/ psexec
psexec -s cmd.exe
Enable rdp with CLI
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f
Launch ARP scan
for /L %i in (1,1,255) do @start /b ping -n 1 -w 1 192.168.1.%i
Capture all IPv4 traffic, TCP only, which matches the IP address on a 64 bit Windows 7/Windows 2008 or newer box, continue the capture even if the computer restarts, save capture to a nondefault location. Captures can then be analysed with Microsoft's Message Analyser
netsh trace start capture=yes Ethernet.Type=IPv4 IPv4.Address= Protocol=TCP persistent=yes traceFile=C:\Users\Public\trace.etl
Stop the capture
netsh trace stop