Quarks PwDump by Sebastien Kaczmarek Windows XP/2003/Vista/7/2008/8, free ( GPL v3 ) Source code on GitHub (no pre-compiled binary) Quarks PwDump is open source tool to dump various types of Windows credentials: local account, domain accounts, cached domain credentials, and bitlocker.
An easy to use program to reset Windows NT2000XP2003 secure boot options.
Like the previous pwdump utilities, pwdump3 does not represent a new exploit since administrative privileges are still required on the remote system.
GPL v2 download local copies of pwdump3 version 2 (87 KB) and pwdump3e (217 KB) pwdump3 enhances the existing pwdump and pwdump2 programs developed by Jeremy Allison and Todd Sabin, respectively. Windows NT/2000/XP/2003, free Download local copy of pwdump5 (28 KB) pwdump5 is an application that dumps password hashes from the SAM database even if syskey is enabled on the system. GPL v2 download local copy of pwdump4 (72 KB) pwdump4 is an attempt to improve upon pwdump3. After trying numerous Password cracking programs I came across the Offline NT Password Registry Editor. Now, how can you keep your network safe? It uses Diffie-Hellman key agreement to generate a shared key that is not passed across the network, and employs the Windows Crypto API to protect the hashes. Offline NT Password Registry Editor by Petter Nordahl-Hagen Windows NT. Authentication Protocols, win2K and later can use four authentication protocols: LAN Manager, ntlm, ntlmv2, and Kerberos. Set, reset account lockout counter after to 1 minute (the smallest possible value). Changing the names of highly privileged accounts to something other than their well-known default names will defeat many automated password-guessing programs.

The AD database is used for logons to Windows 2000 and later domains.
Disable LM password hashes.
From Group Policy or Local Security Policy, navigate to Computer ConfigurationWindows SettingsSecurity SettingsLocal PoliciesPassword Policy and set the Maximum password age setting to no more than 90 days. Do this by using a registry editor or Group Policy Object (GPO). Windows NT/2000, free. The authentication protocol determines the mathematical routine that the client and server use during the challenge-response process. Kerberos uses an entirely different form of authentication based on preauthentication packet exchange. The editor works offline, that is, you have to shutdown your computer and boot off a floppy disk. Recommendations are in descending order of importance. Navigate to Computer ConfigurationWindows SettingsSecurity SettingsLocal PoliciesSecurity OptionsNetwork.