Scan .NET mod assemblies from the command line or during a build. MLVScan reports suspicious behavior, known malware families, and guidance for reviewing findings.
Install the CLI globally:
dotnet tool install --global MLVScan.DevCLITo update it:
dotnet tool update --global MLVScan.DevCLIFor a project-local installation, create a tool manifest if your project does not already have one, then install the tool:
dotnet new tool-manifest
dotnet tool install MLVScan.DevCLIRun a local installation with dotnet tool run mlvscan -- followed by the scan
arguments. Use dotnet tool restore after cloning a project with a tool manifest.
Download mlvscan-win-x64.zip from GitHub Releases,
extract it, and run mlvscan.exe from the extracted folder:
.\mlvscan.exe info --format jsonmlvscan MyMod.dllThe console report shows the overall disposition, findings, and any matched threat families. Findings may include remediation advice, documentation links, call chains, or data-flow evidence.
Use --verbose to include advanced diagnostics:
mlvscan MyMod.dll --verboseUse the schema format for scripts and CI:
mlvscan MyMod.dll --format schema > scan-results.jsonThe report includes disposition, threatFamilies, findings, and scan metadata.
The legacy JSON format remains available with --format json or --json.
If a scan reaches an analysis limit, use retry to run deeper analysis when needed:
mlvscan MyMod.dll --scan-mode retry --format schemaUse --scan-mode deep to apply the larger analysis budgets from the start.
Deeper scans can take longer and may still need manual review if an analysis
limit is reached.
To fail a build when the disposition is Suspicious or KnownThreat:
mlvscan MyMod.dll --fail-on-disposition SuspiciousThe command returns exit code 1 when the threshold is met. Without a failure
threshold, a completed scan returns 0 even if it reports findings. Scan errors
also return 1.
For workflows that use finding severity, --fail-on High fails on High or
Critical findings.
Install MLVScan as a local tool in your project, then add this target to your
.csproj:
<Target Name="MLVScanCheck" AfterTargets="Build">
<Exec Command="dotnet tool run mlvscan -- "$(TargetPath)" --fail-on-disposition Suspicious" />
</Target>Run dotnet tool restore before building on a new machine or in CI.
This example builds a project and scans its assembly. Replace MyMod.csproj and
the DLL path with your project's paths.
name: Build and scan
on: [push, pull_request]
jobs:
scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: actions/setup-dotnet@v5
with:
dotnet-version: '8.0.x'
- name: Install MLVScan
run: dotnet tool install --global MLVScan.DevCLI
- name: Build
run: dotnet build MyMod.csproj -c Release
- name: Scan
run: mlvscan ./bin/Release/netstandard2.1/MyMod.dll --format schema --fail-on-disposition Suspicious > scan-results.json
- name: Save report
if: always()
uses: actions/upload-artifact@v6
with:
name: scan-results
path: scan-results.jsonmlvscan <assembly-path> [options]
mlvscan info [--format text|json]
mlvscan --schema-version
| Option | Behavior |
|---|---|
--format, -o |
Output console (default), schema, or legacy json. |
--json, -j |
Use legacy JSON output. |
--fail-on-disposition |
Return 1 at or above Clean, Suspicious, or KnownThreat. |
--fail-on, -f |
Return 1 at or above Low, Medium, High, or Critical severity. |
--verbose, -v |
Include advanced diagnostics. |
--scan-mode |
Use standard (default), retry, or deep analysis. |
--help, -h |
Show command help. |
--version |
Show the CLI version. |
Start with the disposition and any threat-family matches, then read the supporting findings. Severity describes individual findings; it is not the overall verdict. Review incomplete analysis and uncertain findings before deciding what to do with an assembly.
The CLI scans compiled assemblies, so source code is not required. If you suspect a false positive, report it with the scan output and enough context to explain the assembly's intended behavior.