n0fate’s Forensic Lab – Chainbreaker. Chainbreaker can extract encrypted user credentials in OS X Keychain and decrypt it using one of the Master Key, user password and SystemKey. More detailed information here: Keychain Analysis with Mac OS X Memory Forensics (PDF)