.NET Attribute & Metadata Analyzer
Scan C# and VB.NET source code to detect and categorize .NET metadata attributes. Identifies obfuscation-related attributes ([Obfuscation], [SuppressIldasm], [DebuggerHidden]), security attributes ([SecurityCritical], [AllowPartiallyTrustedCallers]), serialization attributes ([Serializable], [DataContract], [DataMember]), COM/Interop attributes ([DllImport], [ComVisible]), Code Access Security permissions, and custom obfuscator markers (ConfuserEx, Dotfuscator, Obfuscar, SmartAssembly, Babel, CryptoObfuscator, .NET Reactor). Each attribute includes a detailed explanation of its purpose, significance rating, surrounding code context, and line number. Free, private, and no signup required.
Scan C# or VB.NET source code to detect and categorize metadata attributes. Identifies obfuscation-related attributes ([Obfuscation], [SuppressIldasm], [DebuggerHidden]), security attributes, serialization attributes, COM interop attributes, and custom obfuscator markers (ConfuserEx, Dotfuscator, Obfuscar, SmartAssembly, Babel). Each attribute includes a detailed explanation of its purpose and relevance to obfuscation analysis.
Paste C# or VB.NET source code above and click Analyze Attributes to detect and categorize metadata attributes. The analyzer identifies obfuscation-related attributes, security attributes, serialization attributes, COM interop attributes, debugger attributes, and custom obfuscator markers. Each detection includes a detailed explanation. Try loading an example to see how it works!
Features
7 Attribute Categories with 30+ Detection Patterns
Automatically scans for attributes across 7 categories: obfuscation ([Obfuscation], [SuppressIldasm], [Obfuscate]), security ([SecurityCritical], [AllowPartiallyTrustedCallers]), serialization ([Serializable], [DataContract], [DataMember]), COM interop ([DllImport], [ComVisible], [Guid]), debugger ([DebuggerHidden], [DebuggerNonUserCode]), code access security ([PermissionSet], [SecurityPermission]), and custom obfuscator markers (ConfuserEx, Dotfuscator, Obfuscar, SmartAssembly, Babel).
Significance Ratings & Detailed Explanations
Every detected attribute includes a significance rating (High/Medium/Low/Info) and a detailed explanation of its purpose, what it does, and why it matters for obfuscation analysis. High-significance attributes like [DebuggerHidden] flag anti-debugging measures, while [ConfuserEx] directly identifies the obfuscation tool used.
Categorized Output with Annotated Code View
Attributes are grouped by category with color-coded cards for instant visual scanning. The annotated code view adds inline comments at each line containing detected attributes, showing the category and attribute name directly in the source context alongside the original code.
100% Browser-Local & Private
All .NET attribute analysis runs entirely in your browser. Your C#/VB.NET code, all detected attributes, and analysis results never leave your device. No server uploads, no API calls, no data storage, and no tracking. Safe for analyzing proprietary code or potentially malicious .NET assemblies.
Use Cases
Malware & Backdoor Analysis
Analyze decompiled .NET malware for suspicious attributes. [DllImport] with Win32 API functions indicates system interaction. [DebuggerHidden] and [DebuggerNonUserCode] suggest anti-debugging measures. [OnDeserialized] can hide post-exploitation execution logic in serialization callbacks.
Identifying Anti-Debugging & Anti-Analysis Techniques
Quickly identify anti-debugging attributes like [DebuggerHidden], [DebuggerNonUserCode], and [DebuggerStepThrough] that obfuscated .NET code uses to evade dynamic analysis. [SuppressIldasm] indicates an attempt to block IL disassembly, though it provides minimal real protection.
Obfuscation Tool Identification
Detect custom obfuscator attributes that identify which .NET obfuscation tool was used. [ConfuserEx] and [Obfuscar] are open-source tools, while [Dotfuscator], [SmartAssembly], and [Babel] are commercial products. Knowing the obfuscator helps you choose the right deobfuscation approach.
Security Audits of .NET Applications
During .NET application security audits, scan for [SuppressIldasm] which may indicate attempts to hide code from reviewers. Check for [AllowPartiallyTrustedCallers] which can expose assemblies to untrusted callers. Review [SecurityCritical] and [SecuritySafeCritical] for proper security transparency usage.
Educational Tool for .NET Metadata
Learn what different .NET metadata attributes do and how they affect code behavior. Understand the difference between [Serializable] and [DataContract], why [DllImport] is used for Win32 interop, and how [Obfuscation(Exclude=true)] preserves specific members during obfuscation.
Reverse Engineering Decompiled Assemblies
When reverse engineering decompiled .NET assemblies, use the attribute analyzer to quickly identify key attributes that reveal the code structure. [Guid] identifies COM interfaces, [DataMember] marks serialized fields, and [Obfuscation] shows what the original author tried to protect or exclude.
About .NET Metadata Attributes
What Are .NET Metadata Attributes?
.NET metadata attributes are declarative tags applied to assemblies, types, methods, parameters, and other code elements to control behavior at compile-time or runtime. They are stored in the assembly metadata and are visible to the CLR, tools, and other code through reflection. Attributes are written inside square brackets [AttributeName] in C# or angle brackets <AttributeName> in VB.NET. For security researchers and reverse engineers, these attributes provide critical clues about code behavior, obfuscation techniques, and the tools used to protect the assembly.
How the Analyzer Works
The analyzer scans .NET (C#/VB.NET) source code using a comprehensive database of attribute pattern definitions across 7 categories. Each definition includes one or more regex patterns to match the attribute name and its variations. When a match is found, the attribute is categorized (Obfuscation, Security, Serialization, Interop, Debugger, Code Access Security, or Custom Obfuscator) and given a significance rating. Each detected attribute includes a detailed explanation of its purpose, how it affects code behavior, and why it matters for obfuscation analysis. All processing is local and private.
Attribute Significance Ratings Explained
Each detected attribute is rated for its relevance to obfuscation analysis. High significance attributes directly relate to obfuscation or anti-debugging: [Obfuscation], [SuppressIldasm], [DebuggerHidden], [DebuggerNonUserCode], and custom obfuscator markers like [ConfuserEx] or [Dotfuscator]. Medium significance attributes are commonly found in obfuscated code but have legitimate uses: [SecurityCritical], [AllowPartiallyTrustedCallers], [Serializable], [DataContract], [DllImport], [OnDeserialized], and [DebuggerStepThrough]. Low significance and Info attributes provide context but are not direct indicators of obfuscation.
Privacy & Security
This tool runs entirely in your browser using client-side JavaScript. The .NET code you paste, all detected attributes, and analysis results are never uploaded to any server, stored in any database, or transmitted over the network. All pattern matching and categorization execute locally on your device. There are no API calls, analytics tracking, cookies, or data collection of any kind. This makes it safe for analyzing proprietary .NET code, commercial software, or potentially malicious assemblies.
Related Deobfuscation Tools
Java Obfuscation Technique Detector
Scan Java code to identify which obfuscation tool was used - ProGuard, DashO, Zelix KlassMaster, Allatori, or yGuard.
Go Deobfuscator / Symbol Restorer
Detect and reverse Go obfuscation: short identifiers, hex escapes, Base64 strings, XOR cipher patterns, and obfuscated numeric literals.
Binary Data Unpacker
Detect and unpack obfuscated binary data. Supports Base64, hex, XOR, GZIP, and more with confidence scoring.
Obfuscated Text Diff & Comparison
Compare two text versions to detect invisible differences: zero-width characters, homoglyph substitutions, and Unicode tricks.
Frequently Asked Questions About .NET Attribute Analysis
The tool detects attributes across 7 categories: obfuscation ([Obfuscation], [SuppressIldasm], [Obfuscate]), security ([SecurityCritical], [SecuritySafeCritical], [AllowPartiallyTrustedCallers]), serialization ([Serializable], [DataContract], [DataMember], [OnDeserialized]), COM interop ([DllImport], [ComVisible], [Guid], [MarshalAs]), debugger ([DebuggerHidden], [DebuggerNonUserCode], [DebuggerStepThrough]), code access security ([PermissionSet], [SecurityPermission]), and custom obfuscator attributes (ConfuserEx, Dotfuscator, Obfuscar, SmartAssembly, Babel, CryptoObfuscator, .NET Reactor).
High significance attributes are directly related to obfuscation, anti-debugging, or custom obfuscator identification. Medium significance attributes are commonly found in obfuscated code but also have legitimate enterprise uses. Low significance attributes provide context about code structure. Info attributes are informational and help understand the code better without indicating obfuscation.
No. This tool specifically detects metadata attributes - it does not analyze string encryption, control flow obfuscation, or renaming patterns. It can identify the obfuscation tool used if the tool leaves attribute markers (like [ConfuserEx] or [Dotfuscator]), but many obfuscators do not leave such traces.
Paste C# or VB.NET source code - either original source or decompiled output from tools like dnSpy, ILSpy, or dotPeek. The tool works best with full class/struct definitions that include their attributes. Decompiled code from .NET assemblies preserves all metadata attributes, making it ideal for analysis.
[SuppressIldasm] is an attribute that prevents the ILDASM (IL Disassembler) tool from viewing the assembly. It was an early anti-reverse-engineering measure introduced in .NET Framework 1.0. Modern tools like dnSpy and ILSpy ignore it completely, so it provides minimal actual protection. However, its presence indicates that the developer tried to protect the assembly from analysis.
[DebuggerHidden] prevents breakpoints from being hit inside the marked method and stops the debugger from stepping into it. It is commonly used by malware and obfuscated code to hinder dynamic analysis. While it can have legitimate uses (like framework internals), in decompiled code it is often a sign that the developer wanted to hide execution from debuggers.
[Serializable] is the legacy .NET serialization attribute used by BinaryFormatter, SoapFormatter, and remoting. [DataContract] is the modern WCF serialization attribute that works with DataContractSerializer. Both mark types for serialization, but [DataContract] requires explicit [DataMember] on each field/property, while [Serializable] serializes all fields by default.
Yes, absolutely. The tool runs entirely in your browser. Your C#/VB.NET code, all detected attributes, and analysis results are never uploaded to any server. All processing is local with no API calls or data collection. You can safely analyze proprietary code, commercial software, or potentially malicious assemblies.
Yes - 100% free with no signup, no account, and no usage limits. Analyze as much .NET code as you need, as many times as you want. There are no premium tiers, hidden charges, or rate limits. The tool runs entirely in your browser - your code never leaves your device.