1. identify the wallet software that the wallet.dat was created using.
2. Google "crack <wallet software name> wallet file" or google "hashcat <wallet software name>" or google "john <wallet software name>".
3. follow whichever blog post or articles instructions.
4. Identify possible password used by the individual that is the owner of that wallet. This could mean infecting them with a stealer to discover other passwords they have used. Checking breached databases for previous password they have used.
5. Generate permutations and alterations of passwords that you've identified they have used previous or for other services.
6. Try a generic wordlist. google "seclists github" for a repository with a bunch of basic ones.
7. If you have or can infect the users machne, identify if they are using a password manager and keylog/steal their password manager password. Or just keylog them opening the wallet file.