Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
RelayKing-Depth — Dominate the domain. Relay to royalty. | Kitploit
Tools/GitHubGitHub/depthsecurity/relayking-depth
Privilege EscalationReconnaissanceVulnerability ScannersVulnerability AnalysisExploitationIDS/IPS EvasionLateral MovementInformation GatheringNetwork SecurityPenetration Testing
GitHub
34230616 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
depthsecurity/relayking-depth

RelayKing-Depth

Dominate the domain. Relay to royalty.

View Repository

RelayKing v1.10

Dominate the domain. Relay to royalty.

RelayKing is a comprehensive relay detection and enumeration tool designed to identify relay attack opportunities in Active Directory environments. Actual reporting options. Comprehensive attack coverage. Find the hidden relay vectors and report in your favorite output format. Feed Impacket's ntlmrelayx.py a curated target list of detected, relay-able hosts. Never miss a critical, exploitable NTLM relay path in the domain again.

Blog/Recommended Reading:

See the associated blog released on the Depth Security website for more details: https://www.depthsecurity.com/blog/introducing-relayking-relay-to-royalty/

Table of Contents

  • Blog/Recommended Reading
  • Read Before Using
    • OPSEC Considerations
  • Features
    • Protocol Detection
    • Advanced Detection
    • Relay Path Analysis
    • Targeting Options
    • Output Formats
    • Misc Features
  • Installation
  • Usage
    • Command-Line Options
    • Examples
  • Functionality Notes
    • Performance
    • Grouping
    • Feature Behavior Notes
  • To-Do
  • Current Known Bugs/Limitations
  • Submitting Issues/Pull Requests
    • Issues
    • Pull Requests
  • Credits
  • Disclaimer
  • License

READ BEFORE USING:

OPSEC CONSIDERATIONS:

**RelayKing is NOT AN OPSEC-FRIENDLY TOOL IN CERTAIN MODES, PARTICULARLY IN --audit MODE. RelayKing is provided AS-IS WITH NO GUARANTEES. See bottom of readme.

Installation

# Use a venv. Save yourself the hassle.

# Clone repo:
git clone https://github.com/depthsecurity/RelayKing-Depth.git
#Navigate to cloned dir:
cd RelayKing-Depth/
# Configure Python venv:
virtualenv --python=python3 .
source bin/activate
# Install deps:
pip3 install -r requirements.txt
# Validate RelayKing installation was successful:
python3 relayking.py -h

Protocol Detection

  • SMB/SMB2/SMB3: Signing requirements, channel binding, version detection (no auth required)
  • HTTP/HTTPS: EPA/CBT enforcement (Auth required for reliable HTTPS checks)
  • LDAP/LDAPS: Signing requirements, channel binding (Auth required for reliable CBT check on LDAPS)
  • MSSQL: EPA enforcement (Auth required for reliable check)
  • RPC: MS-RPC endpoint enumeration, authentication requirements (Auth required for reliable check)
  • WINRM/WINRMS: WS-Management, EPA enforcement, channel binding (Authed check) (WIP)
  • SMTP: NTLM authentication detection, STARTTLS support (WIP)
  • IMAP/IMAPS: NTLM authentication, encrypted mail access (WIP)

Advanced Detection

  • NTLM Reflection: Identifies hosts vulnerable to NTLM reflection attacks (CVE-2025-33073)
  • CVE-2025-54918: Detects unpatched Windows Server 2025 hosts vulnerable to NTLM reflection via PrintSpooler RPC coercion to LDAPS. Reported as MEDIUM on any unpatched Server 2025 host; escalates to CRITICAL when the host is a DC with PrintSpooler enabled. Checked via UBR (Update Build Revision) queried from the registry.
  • CVE-2019-1040 (Drop the MIC): Detects hosts with UBRs below the June 2019 patch threshold, enabling MIC field stripping for cross-protocol relay (SMB to LDAP/LDAPS) with ntlmrelayx's --remove-mic. Reported as HIGH. Uses the UBR already queried per-host, no additional network requests.
  • Ghost SPN Detection: In --audit mode, queries Active Directory for Service Principal Names whose hostnames have no DNS record. An attacker can register the missing DNS name to intercept NTLM authentication intended for that service principal. Findings are split into vulnerable (no DNS record at all) and probably vulnerable (resolves only via wildcard DNS). Reported as MEDIUM. Full findings written to possible-ghost-spns.txt. Suppress with --no-ghosts.
  • WebDAV/WebClient: Detects hosts with the WebDAV WebClient service running
  • NTLMv1 Support: Checks for NTLMv1 authentication support (individually or at GPO level)
  • Coercion Vulnerabilities: Detects unauthenticated (if specified) PetitPotam, PrinterBug, DFSCoerce

Relay Path Analysis

  • Automatically identifies viable relay attack paths (Functioning, needs more work)
  • Prioritizes paths by impact (critical, high, medium, low)
  • Cross-protocol relay detection (requires --ntlmv1 or --ntlmv1-all - cross-protocol detection only when confirmed Net-NTLMv1 usage discovered)
  • NTLM reflection paths (including partial MIC removal paths/cross-protocol relay)
  • CVE-2025-54918 paths: MEDIUM on any unpatched Server 2025 host, CRITICAL on unpatched DC with PrintSpooler enabled
  • CVE-2019-1040 paths: HIGH, SMB-to-LDAP cross-protocol relay via MIC stripping (--remove-mic)
  • Ghost SPN paths: MEDIUM, up to 5 shown in the report with full output in possible-ghost-spns.txt
  • Severity rating logic is WIP, submit PRs for upgrades/improvements! Not 100% of situations/scenarios are accounted for currently - the goal is to cover all possible primitives.

Targeting Options

  • Active Directory Audit (--audit): Enumerate all computers from AD via LDAP. Requires low-priv AD credentials and functional DNS within environment. Force with --dc-ip or edit /etc/resolv.conf.
  • File Input: Load targets from text file
  • CIDR Notation: Scan entire subnets (e.g., 10.0.0.0/24)
  • IP Ranges: Scan IP ranges (e.g., 10.0.0.1-254)
  • Individual Hosts: Target specific hosts or FQDNs (python3 relayking.py -u blah -p pass -d domain.local <your_target_ip_or_hostname>)

Output Formats

  • Plaintext: Human-readable output with detailed findings
  • JSON: Structured data for programmatic analysis
  • XML: Hierarchical data format
  • CSV: Spreadsheet-compatible format
  • Grep-able: One-line-per-result format for easy parsing
  • Markdown: Documentation-ready format

Misc Features

  • Mass Coercion: --coerce-all combined with --audit and low-priv creds to coerce EVERY domain machine for mass computer account relaying. Highly useful in environments with Net-NTLMv1 enabled.
  • Net-NTLMv1 Discovery: --ntlmv1 or --ntlmv1-all to detect LanMan GPOs at domain level. --ntlmv1-all checks ALL hosts from AD and their registry values using RemoteRegistry. (requires local admin).
  • Relay List Generation: --gen-relay-list <file> to produce a readily-importable target file for ntlmrelayx.py's -tf switch.
  • Ghost SPN Check: Automatically runs in --audit mode when credentials are present. Suppress with --no-ghosts. Full findings are written to possible-ghost-spns.txt alongside the main report; the report itself shows the first 5 to avoid clutter.
  • Flexible Kerberos Auth Features: Kerberos auth via -k (and a FQDN for --dc-ip) should work pretty nicely. If the environment has domain controllers that have NTLM disabled entirely but tolerate it everywhere else, you can use --krb-dc-only so it doesn't mess with any checks. Also, --dns-tcp and -ns are available for work conducted over SOCKS/other proxy pivots. Even kerb works in this scenario pretty easily.

Usage

Print command line args/usage with -h, as expected:

python3 relayking.py -h

Examples

Download Tool