One Day Sec

Can you export Chrome passwords offline just by having the user's NTLM hash?

No, it is not possible to decrypt Chrome passwords using only the user's NTLM hash. DPAPI uses the SHA1 algorithm for protecting the Master Key, while NTLM hashes are generated with the weaker MD4 algorithm, so they are incompatible. The Master Key must be decrypted with the plaintext login password or extracted from the lsass process. This conclusion is explained in the referenced article Penetration Techniques - Offline Export of Passwords Saved in Chrome Browser.
NTLM hashoffline exportChrome passwordsMaster Key decryptionSHA1

Browse all Q&A →