no relevance to original sourceWhat do you have just the rdp or u have login access to rdp?
If the port 3389 then its rdp is it open or password protected?
Bruteforce the pass using tools such as ncrack etc
Once u get into the rdp sniffing data aint hard
Use packet sniffers that sniff the data from the network
Such as wireshark etc
But what exactly do u have internal access to the rdp?