https://github.com/depthsecurity/RelayKing-Depth/
- Scan: SMB, LDAP/S, MSSQL, HTTP/S, RPC, WinRM
- Find: WebDAV WebClient, CVE-2025-33073 (NTLM reflection), NTLMv1 with PrinterBug, PetitPotam etc.
- Supporting full domain audit.
- Collection list of targets for ntlmrelayx and another softs.
- Saving report in plaintext/JSON/CSV/Markdown
Article about it: https://www.depthsecurity.com/blog/introducing-relayking-relay-to-royalty/