.NET Resource Extractor
Extract and decode embedded resources from .NET source code. Detects Base64 encoded strings, hex-encoded byte arrays, GetManifestResourceStream calls, ResourceManager lookups, Convert.FromBase64String payloads, and embedded configuration data. Shows every detection with encoded and decoded values side by side, confidence ratings, and source context. Free, private, and no signup required.
Extract and decode embedded resources from .NET source code. Detects Base64 strings, hex-encoded byte arrays, GetManifestResourceStream calls, ResourceManager lookups, Convert.FromBase64String usage, and embedded configuration data. Shows encoded and decoded values side by side with confidence ratings.
Paste .NET source code above and click Extract Resources to detect and decode embedded resources. The tool identifies Base64 strings, hex-encoded byte arrays, GetManifestResourceStream calls, ResourceManager lookups, and embedded configuration data. Try loading an example to see how it works!
Features
6 Resource Detection Methods
Automatically detects embedded Base64 strings, hex-encoded byte arrays, GetManifestResourceStream calls, Convert.FromBase64String patterns, ResourceManager lookups, and embedded configuration strings in .NET source code. Each method uses targeted pattern matching with confidence scoring.
Live Base64 & Hex Decoding
Base64-encoded resources are automatically decoded using the browser's native atob() to reveal URLs, connection strings, API keys, and configuration data. Hex-encoded byte arrays are converted to readable strings with character reconstruction.
Resource Access Pattern Detection
Identifies .NET resource access patterns including Assembly.GetManifestResourceStream, ResourceManager.GetString, .resx resource lookups, and embedded file references. Each detection includes source line numbers and surrounding code context for easy navigation.
100% Browser-Local & Private
All resource extraction runs entirely in your browser. Your .NET source code, detected resources, and decoded values never leave your device. No server uploads, no API calls, no data storage, and no tracking of any kind.
Use Cases
Malware & Payload Analysis
Analyze .NET malware samples to extract hidden C2 URLs, encrypted payloads, embedded shellcode, and configuration blobs from resource sections. Many .NET droppers and loaders store their core payload as embedded Base64 or hex-encoded resources within the assembly.
Reverse Engineering .NET Applications
Extract embedded configuration strings, API endpoints, database connection strings, license keys, and hardcoded credentials from decompiled .NET assemblies. Reveal hidden functionality gated behind resource lookups in obfuscated applications.
Security Auditing & Compliance
During .NET application security audits, extract all embedded resources to identify hardcoded secrets, internal network paths, staging environment URLs, and other sensitive configuration that should not be embedded in compiled assemblies.
Incident Response Forensics
During incident response on compromised .NET systems, analyze decompiled assemblies for hidden backconnect URLs, data exfiltration endpoints, embedded scripts, and encoded command-and-control configurations stored as embedded resources.
Third-Party Library Assessment
Audit third-party .NET libraries and NuGet packages for suspicious embedded resources. Detect hidden telemetry endpoints, tracking URLs, or unexpected network calls encoded within resource sections of compiled assemblies.
Educational Tool for .NET Resource Internals
Learn how .NET assemblies store and access embedded resources. Understand GetManifestResourceStream, ResourceManager, .resx files, and how obfuscators hide sensitive data within resource sections of compiled applications.
About .NET Resource Extraction
What Is .NET Resource Extraction?
.NET resource extraction is the process of identifying and decoding embedded data within .NET assemblies. .NET applications commonly embed resources like configuration files, strings, images, and serialized data directly into compiled assemblies using the Embedded Resource build action or theResources.resx file system. Obfuscated and malicious .NET applications take this further by encoding sensitive data — such as C2 URLs, API endpoints, license keys, and encrypted payloads — as Base64 strings, hex-encoded byte arrays, or obfuscated resource streams accessed viaAssembly.GetManifestResourceStream() orResourceManager.GetString(). Extracting and decoding these resources is essential for understanding what an obfuscated or unknown .NET application actually does.
How Our Resource Extractor Works
The extractor scans .NET source code using specialized pattern detectors for each resource encoding technique. For Base64 strings, it detects long Base64-encoded literals and decodes them using the browser's built-inatob() function, revealing hidden URLs, connection strings, and serialized data. For hex-encoded byte arrays, it identifies patterns like new byte[] {0x48, 0x65, ...} and converts hex pairs to readable characters. For resource stream access, it detectsGetManifestResourceStream(), ResourceManager.GetString(), and GetObject() calls, extracting the resource names and parameters. For configuration data, it identifies string literals containing URLs, file paths, and other embedded configuration patterns. Each detection includes source line numbers and surrounding context.
.NET Resource Encoding Techniques
.NET obfuscators and malware use several techniques to hide resources in compiled assemblies. Base64 encoding is the most common — entire payloads and configuration files are Base64-encoded and decoded at runtime viaConvert.FromBase64String(). Hex byte arrays store data as arrays of hex literal bytes that are converted usingEncoding.UTF8.GetString(). XOR encryption applies XOR operations with a key byte to obfuscate embedded data.Resource streams use GetManifestResourceStream() to access data hidden in assembly resource sections with misleading names.ResourceManager access patterns index into compiled .resx data using string keys. Understanding these techniques helps in identifying what kind of data might be hidden and how to decode it.
Privacy & Security
This tool runs entirely in your browser. Your .NET source code, detected resources, decoded values, and analysis results are never uploaded to any server, stored in any database, or transmitted over the network. All parsing, pattern matching, and decoding execute locally on your device using client-side JavaScript. There are no API calls, analytics tracking, cookies, or data collection of any kind. This makes it completely safe for analyzing proprietary .NET applications, third-party assemblies, malware samples, or sensitive enterprise source code.