ILSpy is an open-source .NET decompiler that reads compiled assemblies and reconstructs readable C# source code from them. Security researchers use it to analyze .NET malware without executing it, pentesters use it to inspect compiled web application binaries, and developers use it to understand third-party libraries with no documentation. This guide covers every frontend ILSpy ships with, the features that matter most for security work, and how to build it from source on Windows and Linux.
Tip: ILSpy collects zero telemetry, sends no files to third-party services, and uses no crash reporting. That makes it safe to use on proprietary or sensitive assemblies during a security assessment.
Most compiled languages strip structural information during compilation. .NET does not. .NET assemblies compile to Common Intermediate Language (CIL), a bytecode format that retains type names, method signatures, and structural metadata. A capable decompiler can reconstruct close-to-original C# from that metadata.
ILSpy exploits that property to give you readable source from any assembly you point it at. The quality of the reconstruction depends on how aggressively the original code was obfuscated, but for standard unobfuscated binaries, the output is clean and navigable.
One thing to know upfront: Visual Studio 2022 already ships with ILSpy’s decompiler engine (version 7.1). Press F12 on a definition with no source code available, and VS2022 is already using ILSpy under the hood. Most .NET developers use it every day without realizing it.
ILSpy is not a single application. The decompilation engine lives in the ICSharpCode.Decompiler NuGet package, and multiple frontends sit on top of it. Here’s every frontend currently available:
| Frontend | Platform | Notes |
|---|---|---|
| ILSpy WPF UI | Windows | Main desktop GUI, available via GitHub Releases |
| Avalonia UI | Linux / Mac / Windows | Cross-platform GUI built on Avalonia |
| Visual Studio 2022 Extension | Windows | F12 decompilation enabled by default |
| Visual Studio 2019 Extension | Windows | F12 support requires manual opt-in in settings |
| VS Code Extension | Cross-platform | Enable “Decompilation Support” in C# extension settings |
| ILSpyCmd (dotnet tool) | Linux / Mac / Windows | Command-line decompilation via dotnet tool |
| PowerShell Cmdlets | Linux / Mac / Windows | Scriptable decompilation for automation workflows |
| ICSharpCode.Decompiler NuGet | Cross-platform | Embed the engine directly in your own .NET projects |
The ICSharpCode.Decompiler NuGet is the most underused option. It lets you embed ILSpy’s engine in your own security tools, automated malware analysis pipelines, or custom decompilation scripts. You’re not limited to the GUI or the bundled CLI.
For Visual Studio 2019, F12 decompilation is off by default. Go to Tools > Options > Text Editor > C# > Advanced and check “Enable navigation to decompiled source.” For VS Code, enable “Decompilation Support” in the C# extension settings.
| Feature | Why It Matters |
|---|---|
| Decompilation to C# | Reconstructs readable source from IL bytecode |
| Whole-project decompilation | Exports an entire assembly as a Visual Studio project |
| Type / method / property search | Find specific code in large assemblies without manual browsing |
| Hyperlink navigation | Click through type and method references like browsing real source |
| BAML to XAML decompiler | Reconstructs WPF UI definitions from compiled binary XAML |
| ReadyToRun binary support | Handles .NET Core AOT-compiled binaries that most tools fail on |
| Assembly metadata explorer | View raw IL, metadata tokens, and module structure directly |
| Plugin extensibility | Add custom decompilation targets or output formats |
The BAML to XAML decompiler is a specific gotcha worth calling out. BAML is the compiled binary format of XAML in WPF applications. Analyzing a WPF app without source code would otherwise leave the UI definitions unreadable. ILSpy decompiles them back to XAML. Most other .NET tools skip BAML entirely.
The ReadyToRun support matters for modern .NET Core targets. ReadyToRun is a form of ahead-of-time compilation that pre-JITs code for faster startup, which makes assemblies significantly harder to analyze. ILSpy handles R2R binaries where simpler decompilers bail out completely.
You need PowerShell 5.0 or later and Visual Studio 2022 with two workloads: .NET Desktop Development and Visual Studio extension development. Clone the repo and initialize the test submodule before opening the solution:
git clone https://github.com/icsharpcode/ILSpy.git cd ILSpy git submodule update --init --recursive
The submodule step downloads the ILSpy-Tests repository. Skipping it won’t stop the project from opening, but tests will silently fail later. Run it now.
Open ILSpy.sln in Visual Studio. NuGet restore runs automatically. Set the startup project to “ILSpy” and run. If you only need a specific part of the project, use the solution filters: ILSpy.Wpf.slnf for the WPF frontend, ILSpy.XPlat.slnf for the cross-platform CLI, or ILSpy.AddIn.slnf for the Visual Studio plugin.
One stack size detail: ILSpy optionally uses editbin.exe from the MSVC toolset to increase its stack from 1MB to 16MB. The decompiler is heavily recursive. On complex methods with deep call chains, a 1MB stack causes crashes. The MSVC component is optional but worth installing.
Install the .NET 7.0 SDK and PowerShell Core first. On Kali or any Debian-based system, confirm your CPU architecture with the uname command (uname -m) and verify your SDK with dotnet --version before building.
git clone https://github.com/icsharpcode/ILSpy.git cd ILSpy git submodule update --init --recursive dotnet build ILSpy.XPlat.slnf
This builds the cross-platform CLI (ILSpyCmd) and PowerShell cmdlets. The WPF GUI is Windows-only. The Avalonia UI gives you a graphical option on Linux and Mac. If you prefer working from a Linux shell without a GUI, ILSpyCmd handles command-line decompilation directly.
ILSpy is distributed under the MIT License. You can use it commercially, modify the source, and embed the NuGet engine in proprietary tools without restriction. The full license and third-party notices are in the official ILSpy GitHub repository.
Contributing requires one setup step: add the pre-commit hook to .git/hooks that enforces tab formatting. The build server runs the same check, so pull requests with spaces instead of tabs fail CI automatically. Current and past contributors are listed in the repository.
ILSpy collects no personally identifiable information and sends no user files to third-party services. No APM, no telemetry. That matters specifically when you’re decompiling assemblies that contain embedded credentials, proprietary logic, or sensitive configuration during an engagement.
ILSpy is the most capable open-source .NET decompiler available. It handles ReadyToRun binaries, BAML-based WPF UIs, and modern .NET Core assemblies that most other tools miss. If .NET reverse engineering is part of your workflow, whether for malware analysis, CTF challenges, or penetration testing, ILSpy is the tool to have installed and ready.
A data protection platform is a unified system that helps organizations discover, classify, monitor, and…
AI companies operating in or around Switzerland face a compliance challenge that most legal teams…
Two major data privacy laws now govern how organizations handle personal data across Europe; the…
This cheat sheet covers the essential Kali Linux commands every pentester and ethical hacker uses…
When I first started learning malware analysis and reverse engineering, I thought the hardest part…
Both git fetch and git pull talk to a remote repository, but they do very different things to your…