reverse-engineering-dotnet-malware-with-dnspy

mukul975/reverse-engineering-dotnet-malware-with-dnspy · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Analyze .NET malware by decompiling and debugging assemblies with dnSpy, deobfuscating with de4dot, and extracting C2 configurations and IOCs.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.5 KB
  • 📁scripts
  • ⚙️agent.py 8.1 KB
  • 📄LICENSE 11.0 KB

Related

  1. dotnet-reverse · zhaoxuya520 bundle
    Provides a structured workflow for reverse engineering .NET and C# binaries, including deobfuscation with de4dot, static analysis via dnSpyEx IL view, dynamic debugging, and reliable IL patching for red-team tools and malware.
    12.8k
    repo stars
  2. reverse-skill-router · zhaoxuya520 bundle
    Routes reverse engineering, exploitation, penetration testing, malware, mobile, firmware, browser automation, documentation, and security tasks to the appropriate specialist skill. Use when a task spans modules or the correct reverse-skill entrypoint is unclear.
    12.8k
    repo stars
  3. reverse-engineering-malware-with-ghidra · mukul975 bundle
    Reverse engineer malware binaries using NSA's Ghidra disassembler and decompiler to understand internal logic, cryptographic routines, C2 protocols, and evasion techniques at the assembly and pseudo-C level.
    24.6k
    repo stars
  4. deobfuscating-powershell-obfuscated-malware · mukul975 bundle
    Systematically deobfuscate multi-layer PowerShell malware using AST analysis, dynamic tracing, and tools like PSDecode and PowerDecode to reveal hidden payloads and C2 infrastructure.
    24.6k
    repo stars
  5. reverse-engineering-ransomware-encryption-routine · mukul975 bundle
    Identify cryptographic algorithms, key generation flaws, and potential decryption opportunities in ransomware samples using static and dynamic analysis.
    24.6k
    repo stars
  6. malware-analysis · zhaoxuya520 bundle
    Analyze suspected malware through static, dynamic, and behavioral techniques, including IOC extraction, YARA or Sigma rules, sandboxing, and anti-analysis behavior detection.
    12.8k
    repo stars

Frequently asked questions

How do I install the reverse-engineering-dotnet-malware-with-dnspy skill?

Run npx skillmds add mukul975/reverse-engineering-dotnet-malware-with-dnspy in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the reverse-engineering-dotnet-malware-with-dnspy skill do?

Analyze .NET malware by decompiling and debugging assemblies with dnSpy, deobfuscating with de4dot, and extracting C2 configurations and IOCs. It is listed under Security, Coding & Dev Tools, Penetration Testing, Secure Coding on SkillMD.

Is reverse-engineering-dotnet-malware-with-dnspy safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: CAUTION, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with reverse-engineering-dotnet-malware-with-dnspy?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is reverse-engineering-dotnet-malware-with-dnspy free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published reverse-engineering-dotnet-malware-with-dnspy?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.