UnderlayCopy. PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads
257NTLMPasswordChanger. PowerShell tool that shows how to read and write NTLM OWF values via samlib.dll.
74WinAuthLogParser. Parses and Analyse Authentication on Windows Event Log
1