#dnspy
#MalwareAnalysis is a valuable field & useful for your #cybersecurity career! Want tools & tips!?

🛠️:
PeStudio - www.winitor.com/download
Process Hacker 2 - processhacker.sourceforge.io
Procmon - learn.microsoft.com/en-us/sysint...
CyberChef - gchq.github.io/CyberChef/
DnSpy - github.com/dnSpy/dnSpy
November 13, 2024 at 7:36 PM
The fun thing about dotnet is you can just open that dll with dnSpy or dotPeek.
February 5, 2026 at 8:46 PM
i am determined to try and figure out how to query the status database programmatically tonight. it’s just a matter of figuring out how to use dnspy effectively.
March 26, 2026 at 1:15 AM
"dnSpyEx is an unofficial continuation of the dnSpy project which is a debugger and .NET assembly editor."

github.com/dnSpyEx/dnSpy
GitHub - dnSpyEx/dnSpy: Unofficial revival of the well known .NET debugger and assembly editor, dnSpy
Unofficial revival of the well known .NET debugger and assembly editor, dnSpy - dnSpyEx/dnSpy
github.com
January 17, 2025 at 1:40 PM
December 9, 2023 at 9:46 PM
A PSA for those interested in the Mega Man X8 demake (more specifically, interested in playing the mods made for it).
#megaman #megamanx #rockman
July 15, 2025 at 12:09 AM
Hackers Clone Ghidra, dnSpy and Other Tool Sites to Spread Malware

Hackers are cloning Ghidra, dnSpy, ILSpy and other free tool sites to spread Malware like RemusStealer, crypto clippers and loaders through fake downloads.
#hackernews #news
Hackers Clone Ghidra, dnSpy and Other Tool Sites to Spread Malware
Hackers are cloning Ghidra, dnSpy, ILSpy and other free tool sites to spread Malware like RemusStealer, crypto clippers and loaders through fake downloads.
hackread.com
June 9, 2026 at 2:08 PM
this is how dnSpy looks like:
December 29, 2024 at 8:26 PM
ilspy[.org] and dnspy[.org] ... both either fake or compromised. yikes.
April 3, 2026 at 8:17 PM
this was inspired by Kaitai Struct (kaitai.io, which is amazing, but it didn't have full .NET coverage). Also dnSpy has a similar feature (but no tree and no full PE coverage).

I also borrowed the metadata table parsing code from the venerable @jb.evain.net (github.com/jbevain/cecil).
December 29, 2024 at 8:14 PM
I have Hopper, Ghidra, Binja, IDA Pro, x64Dbg, Wireshark, mitmproxy, Charles, Fiddler, ReClass, DNSpy, GDB, LLDB, Detect it Easy, Procmon, Process Hacker, HxD. I need more tools please recommend some.
April 18, 2025 at 7:36 PM
guess its dnspy time again.
August 25, 2026 at 7:07 PM
UnityでビルドしたDLLに dnSpy って .NET アプリの解析ツールを使うと…こうなる。ネットワーク機能は、ほとんどソースコードが丸見えの前提で、認証などを考えないといけない。 #unity
July 22, 2025 at 2:08 AM
ILSpyこの前初めて使ったけど
軽くてよかった(・ω・ )

DnSpy結構メモリ食っててVSCと同時起動きつかったから…()
June 8, 2024 at 12:39 PM
[RSS] How to write dnSpy extension


kant2002.github.io ->


Original->
November 6, 2025 at 5:11 PM
that checks out with what i saw in dnSpy
March 30, 2025 at 10:22 PM
ヒントだけどReactorのDiscordを見るとAmongUsのソースコードが入ってるdllが配布されてるからDnspyとかILspyとかで中身見るとわかるよ
後これは独り言だけどAprilFoolsManager
March 28, 2024 at 1:10 PM
Continuing the theme of the night, i also think .net malware is dumb.

If I can dump your binary in dnspy or ilspy, you need to do better. There are ways to compile .net without making it so easily decomp'd.
March 14, 2026 at 3:07 AM
Well I absolutely didn't expect that to work, couldn't figure out how to get dnspy to add something to Assembly-CSharp.dll for a Unity game.. so I just compiled the change in and copied the dll from the build dir to the game dir and it just..works?! nice.. I expect some issues at some point though
April 27, 2025 at 6:16 AM
ILSpy、VSCodeの拡張あるから使ってるけど演算子を展開してくれなかったりするのがアレで結局いつもDnSpy立ち上げる
June 8, 2024 at 11:42 AM
crazy that dnSpy doesn't work on linux

there's just no good c# decompiler that works on linux
May 27, 2025 at 7:44 PM
Watch out, security researchers! If you search for "Ghidra download," you may be sent to a spoofing site that will gift you an infostealer instead of a disassembler. Multiple tools have spoof sites like this.

discourse.ifin.netwo...

#ThreatIntel #ThreatIntelligence #IFIN
TDS/Clickjacking Campaign Lures with Security Tools
Last Updated: 2026-06-04T21:40:11Z (UTC) What’s Happening Check Point Research a click hijacking/TDS campaign spoofing security tools like Ghidra and dnSpy. Delivers Remus and other infostealers. Actions Refer to IOC table at the bottom of the CHeck Point post for stealers/C2 domains/hashes. Not listed in that table, however, are the initial access domains. Value Type Description d33f51dyacx7bd.cloudfront[.]net Domain Malicious JS fetch ghidralite[.]com Domain Ghidra spoof dnspy...
discourse.ifin.network
June 4, 2026 at 9:58 PM
HTB | Cascade — Reverse Engineering - DnSpy and AD Recycle
HTB | Cascade — Reverse Engineering - DnSpy and AD Recycle
This is the Box on Hack The Box Active Directory 101 Track. Find the box here.
infosecwriteups.com
October 27, 2024 at 11:36 PM