I don't know why this was downvoted, because that is precisely what we did.
I used 'hashcat', which is an open-source tool available on GitHub.
A few hours of GPU time will reverse about 50-80% of typical NT-hashed passwords, and 90% or more given a few days or weeks.
Once you have passwords of admin users or service accounts, you can use those to "trawl through" servers looking for plain-text passwords in scripts, scheduled tasks, documentation, source code, etc...
I used 'hashcat', which is an open-source tool available on GitHub.
A few hours of GPU time will reverse about 50-80% of typical NT-hashed passwords, and 90% or more given a few days or weeks.
Once you have passwords of admin users or service accounts, you can use those to "trawl through" servers looking for plain-text passwords in scripts, scheduled tasks, documentation, source code, etc...