Reverse engineers .NET malware samples using the dnSpy decompiler and debugger to read C#/VB.NET source, deobfuscate code protected by tools like ConfuserEx or SmartAssembly, and extract hardcoded C2 configurations, keys, and credentials. Use when a sample is identified as a .NET assembly (e.g. AgentTesla, AsyncRAT, RedLine Stealer, Quasar RAT) and needs decompilation, deobfuscation, or config extraction.