
Dominate the domain. Relay to royalty.

RelayKing is a comprehensive relay detection and enumeration tool designed to identify relay attack opportunities in Active Directory environments. Actual reporting options. Comprehensive attack coverage. Find the hidden relay vectors and report in your favorite output format. Feed Impacket's ntlmrelayx.py a curated target list of detected, relay-able hosts. Never miss a critical, exploitable NTLM relay path in the domain again.
See the associated blog released on the Depth Security website for more details: https://www.depthsecurity.com/blog/introducing-relayking-relay-to-royalty/
**RelayKing is NOT AN OPSEC-FRIENDLY TOOL IN CERTAIN MODES, PARTICULARLY IN --audit MODE.
RelayKing is provided AS-IS WITH NO GUARANTEES. See bottom of readme.
# Use a venv. Save yourself the hassle.
# Clone repo:
git clone https://github.com/depthsecurity/RelayKing-Depth.git
#Navigate to cloned dir:
cd RelayKing-Depth/
# Configure Python venv:
virtualenv --python=python3 .
source bin/activate
# Install deps:
pip3 install -r requirements.txt
# Validate RelayKing installation was successful:
python3 relayking.py -h
--remove-mic. Reported as HIGH. Uses the UBR already queried per-host, no additional network requests.--audit mode, queries Active Directory for Service Principal Names whose hostnames have no DNS record. An attacker can register the missing DNS name to intercept NTLM authentication intended for that service principal. Findings are split into vulnerable (no DNS record at all) and probably vulnerable (resolves only via wildcard DNS). Reported as MEDIUM. Full findings written to possible-ghost-spns.txt. Suppress with --no-ghosts.--ntlmv1 or --ntlmv1-all - cross-protocol detection only when confirmed Net-NTLMv1 usage discovered)--remove-mic)possible-ghost-spns.txt(--audit): Enumerate all computers from AD via LDAP. Requires low-priv AD credentials and functional DNS within environment. Force with --dc-ip or edit /etc/resolv.conf.10.0.0.0/24)10.0.0.1-254)python3 relayking.py -u blah -p pass -d domain.local <your_target_ip_or_hostname>)--coerce-all combined with --audit and low-priv creds to coerce EVERY domain machine for mass computer account relaying. Highly useful in environments with Net-NTLMv1 enabled.--ntlmv1 or --ntlmv1-all to detect LanMan GPOs at domain level. --ntlmv1-all checks ALL hosts from AD and their registry values using RemoteRegistry. (requires local admin).--gen-relay-list <file> to produce a readily-importable target file for ntlmrelayx.py's -tf switch.--audit mode when credentials are present. Suppress with --no-ghosts. Full findings are written to possible-ghost-spns.txt alongside the main report; the report itself shows the first 5 to avoid clutter.--dc-ip) should work pretty nicely. If the environment has domain controllers that have NTLM disabled entirely but tolerate it everywhere else, you can use --krb-dc-only so it doesn't mess with any checks. Also, --dns-tcp and -ns are available for work conducted over SOCKS/other proxy pivots. Even kerb works in this scenario pretty easily.-h, as expected:python3 relayking.py -h