Sign in

Wesley Shields

@wxs.bsky.social
771 followers 55 following 255 posts

Working at Google TAG. Retired FreeBSD committer. May or may not be a robot.

PostsRepliesMedia
Wesley Shields @wxs.bsky.social · 5h
resident.ngo/lab/writeups... - resident.ngo wrote up a nice post on some recent activity they saw. They only claim it is very similar to Star Blizzard (COLD RELIC in our terms) but if it looks like a duck and quacks like a duck... ;)
resident.ngo
RESIDENT.NGO Digital security for Civil Society
121
Wesley Shields @wxs.bsky.social · 24/09/2026
This warms my cold, dispassionate robot heart: www.isyeet.io/wxsbsd/ Though anyone who knows me knows I don't put noses in my smiley faces, so they got that part wrong. ;)
isyeet.io
All I want is text. | ISYEET
A dispatch from the woods. In defense of ASCII, quiet computers, and telling your family you made it home.
141
Wesley Shields @wxs.bsky.social · 17/09/2026
Been traveling this week, and left my favorite water bottle at the hotel. RIP to my YARA water bottle, hope whoever ends up with it likes it.
130
Wesley Shields @wxs.bsky.social · 10/09/2026
And another publication, this time from @volexity.com, on the Chrome 0-day chain that Proofpoint also published on. All great work and worth reading if you're into this kind of stuff!
000
Wesley Shields @wxs.bsky.social · 09/09/2026
Nice work on this! It cost me a bit of my sanity last week but was definitely interesting to see.
132
Wesley Shields @wxs.bsky.social · 04/09/2026
I just had to look it up but "base64 ascii" modifiers in combination DO NOT include the ascii version of the string. This is well documented (yara.readthedocs.io/en/latest/wr...) but something I had forgot. If I forget it (and I'm the one who wrote that feature) then I bet others do too.
yara.readthedocs.io
Writing YARA rules — yara 4.5.0 documentation
121
Wesley Shields @wxs.bsky.social · 27/08/2026
I updated vscode just now and noticed it is spawning this: /Users/wxs/Library/Application Support/Code/agent-host/sdk-cache/claude/0.3.220/darwin-arm64/node_modules/@anthropic-ai/claude-agent-sdk-darwin-arm64/claude - I didn't ask for this, don't enable it by default and even better: don't ship it.
100
Wesley Shields @wxs.bsky.social · 24/08/2026
New release with lots of new features and bug fixes. Again, congratulations to Victor and everyone who contributed to making this happen! It’s great to see the continued progress. github.com/VirusTotal/y...
github.com
Release v1.20.0 · VirusTotal/yara-x
Implement SIMD-accelerated masked literal matching (#691). Improve atom extraction heuristics for better performance (#690, 1e14f60). Improve scan performance by applying file size and file header ...
032
Wesley Shields @wxs.bsky.social · 21/08/2026
This stuff is the same as UNC5976 (and yes, i had to go look that up because we dont use the UNC designation internally on my team) discussed in our post yesterday: cloud.google.com/blog/topics/...
cloud.google.com
Distinct Clusters Target Individuals of Interest to Russia | Google Cloud Blog
Distinct Russian clusters have been conducting phishing activity focused on Application Specific Passwords (ASP), OAuth flows, and malware delivery. All of these operations seem focused on account com...
064
Wesley Shields @wxs.bsky.social · 20/08/2026
virustotal.github.io/yara-x/blog/... I've seen this exact issue more times than I can count, and getting support for recognizing it in the compiler is great!
virustotal.github.io
Beware of the wildcard
Introducing the new unintended_pattern_in_set compiler warning in YARA-X to catch overlapping variable prefixes and pattern set collisions.
000
Wesley Shields @wxs.bsky.social · 20/08/2026
So @gabagool.ing and I had some stuff to say on some RU activity. If you're into tracking and understanding interesting RU groups here's some new ones and a revisit of one from last year. Thanks for our friends who helped shine a light on some of this activity! cloud.google.com/blog/topics/...
cloud.google.com
Distinct Clusters Target Individuals of Interest to Russia | Google Cloud Blog
Distinct Russian clusters have been conducting phishing activity focused on Application Specific Passwords (ASP), OAuth flows, and malware delivery. All of these operations seem focused on account com...
175
Wesley Shields @wxs.bsky.social · 10/08/2026
Three positions opened up in GTIG. If you have questions I'd be happy to answer! Koreas: www.google.com/about/career... Exploits (US and CH based): www.google.com/about/career... www.google.com/about/career...
021
Wesley Shields @wxs.bsky.social · 28/07/2026
This came out while I was traveling last week and it's a good read on a single campaign from this group we've been tracking: dslua.org/publications... - They are fairly active doing this kind of phishing and also other nefarious activities.
dslua.org
Phishing Campaign Against “Civil Network OPORA” – Gmail Account Takeover via OAuth – Лабораторія цифрової безпеки
042
Wesley Shields @wxs.bsky.social · 15/07/2026
I found the newly added feature in YARA-X to ignore certain rules on compilation errors to be interesting and exposed it in the python API. The original requester (and implementer) raises a good point that this makes using large rulesets much easier.
100
Wesley Shields @wxs.bsky.social · 08/07/2026
Turns out there was a small bug in the "private" modifier on hex and RE patterns in YARA-X, in that they were not honored at all. Fixed that in github.com/VirusTotal/y... - original issue spotted by someone else: github.com/VirusTotal/y...
github.com
fix: Do not ignore private modifier on hex and RE patterns. by wxsBSD · Pull Request #698 · VirusTotal/yara-x
This fixes the "private" modifier on hex strings so they are properly hidden from output and also fixes it so the modifier is properly displayed in both AST and CST representations. This ...
020
Wesley Shields @wxs.bsky.social · 04/07/2026
Happy early Fourth of July from my front porch!
100
Wesley Shields @wxs.bsky.social · 30/06/2026
Jordan doing good work deep diving into Turla related malware we’ve been tracking for a while now. If you’re into Turla this is a good read. cloud.google.com/blog/topics/...
cloud.google.com
The Latest Addition to Turla’s Intelligence Gathering Apparatus | Google Cloud Blog
Analysis of a backdoor, STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla.
1103
Wesley Shields @wxs.bsky.social · 26/06/2026
Patrick sharing some good work on activity of this PRC nexus actor that is quite broad!
020
Wesley Shields @wxs.bsky.social · 24/06/2026
github.com/VirusTotal/y... This fixes an issue with certain header constraints that you really should update for. There are other nice bug fixes and features too, but the header constraints is a big one.
github.com
Release v1.19.0 · VirusTotal/yara-x
Add missing machine architecture types to pe module (#687). Add warning for single-byte patterns (71baa67). Add warning for duplicate patterns in a rule (9061803). Small optimization when generatin...
042
Wesley Shields @wxs.bsky.social · 07/05/2026
github.com/VirusTotal/y... Performance improvements and some nice new features. It only gets better with each release! Congratulations to all contributors and Victor!
github.com
Release v1.16.0 · VirusTotal/yara-x
Multiple performance improvements (#623, #624, #626, #627, #629, #631, #632, #635, #649, #654). Implement constant folding for bitwise operations (#634). Allow specifying context size for matches (...
021
Wesley Shields @wxs.bsky.social · 29/04/2026
Next time AI makes up a garbage answer just remember wxs' first law of AI: "Never trust robots, a bunch of assholes if you ask me."
010
Wesley Shields @wxs.bsky.social · 23/04/2026
So @xorhex.bsky.social asked (in our YARA keybase chat) how one might only iterate through the last 10 matches of a string in YARA. I took a shot at answering it by logging the last 10 locations of a match in descending order: for all i in (0..10): (console.log(@a[#a - i]))
132
Wesley Shields @wxs.bsky.social · 13/04/2026
github.com/VirusTotal/y... - congrats to all involved! These new features are really great!
github.com
Release v1.15.0 · VirusTotal/yara-x
Add full support for WASM. The whole yara-x create now can be built for WASM (#583, #588, #598). New playground at https://virustotal.github.io/yara-x/playground/ (#601). The yr check command now n...
171
Wesley Shields @wxs.bsky.social · 08/04/2026
Not so fun fact: The imphash implementation in pefile has diverged from the implementation in YARA and YARA-X... and any other one in the last 15 years. This has existed for 2 years and I'm pushing to get it reverted and a new pefile release made. github.com/erocarrera/p...
github.com
Imphash implementation does not follow convention · Issue #141 · erocarrera/pefile
https://www.mandiant.com/blog/tracking-malware-import-hashing/ Mandiant's imphash convention requires the following: Resolving ordinals to function names when they appear Converting both DLL names ...
030
Wesley Shields @wxs.bsky.social · 01/04/2026
It really annoyed me that we could not return multiple tag linter errors, but returned multiple errors for other linters. The root cause is kind of interesting. More importantly, I put up a fix for it: github.com/VirusTotal/y...
github.com
fix: Properly handle multiple errors with the tag linter. by wxsBSD · Pull Request #614 · VirusTotal/yara-x
When the tag linter comes across multiple errors only the first one is returned. This is due to an oversight in the API where we can only return a single error, not a vector of errors. I realize th...
010
Wesley Shields @wxs.bsky.social · 30/03/2026
Two for one today! Added support for console.log(offset, length) to the console module in YARA-X, per the suggestion of a user. Makes it nicer to work with arbitrary sequences of bytes. Hopefully it makes it in the next release!
media.tenor.com
two men are standing next to each other and one of them is wearing a shirt that says nuts
ALT: two men are standing next to each other and one of them is wearing a shirt that says nuts
041
Wesley Shields @wxs.bsky.social · 29/03/2026
I've been struggling to find time to write code during the week, and I know I need to get better at that as I still very much enjoy contributing to this project. Anyways, here's the PR that adds the linter functionality the compiler has to the Python API: github.com/VirusTotal/y...
000
Wesley Shields @wxs.bsky.social · 22/03/2026
One of those days. I have a bit of time to work on some code, so I start in on it. I quickly realize I want a feature that was added sometime after I started my branch. Fine, I pull it down into my repository BUT COMPLETELY FORGET TO REBASE MY WORK ON IT! Took me a solid 20 minutes of debugging.
media.tenor.com
a man in a suit and tie sits at a desk with the words " i don 't even really work here " above him
ALT: a man in a suit and tie sits at a desk with the words " i don 't even really work here " above him
010
Wesley Shields @wxs.bsky.social · 21/03/2026
So @tlansec.bsky.social asked about exposing the linter capabilities of `yr check` (sometimes called the "checker") in the python API. It is done modulo test cases and some minor tweaks to the API I'm considering to make it a bit nicer. PR up hopefully by the end of this weekend.
020
Wesley Shields @wxs.bsky.social · 14/03/2026
Did some work to expose the functionality of the “yr check” command (what I call the linter) in the python bindings. The basic gist is done, just need to clean it up this weekend. Should have a PR up soon.
000
Wesley Shields @wxs.bsky.social · 06/03/2026
Victor just released v1.14.0 - improvements in macho module, tighter code generation in the compiler and the new “deps” command. Congratulations to everyone involved! github.com/VirusTotal/y...
032
Wesley Shields @wxs.bsky.social · 03/03/2026
Spent some time yesterday cleaning up my dependency graphing code for yara-x. No longer outputs graphviz. Instead it dumps an ascii tree. You can try it with “yr deps” in the next release.
030
Wesley Shields @wxs.bsky.social · 11/02/2026
Some of the analysis I've done over the past few years is referenced in various places in this overview. I might be most happy that my sneaky reference to the time a half-dozen of us ate a Vermonster in a single attempt made it into the report. cloud.google.com/blog/topics/...
cloud.google.com
Threats to the Defense Industrial Base | Google Cloud Blog
The defense sector faces a relentless barrage of operations conducted by state-sponsored actors and criminal groups.
030
Wesley Shields @wxs.bsky.social · 06/02/2026
github.com/VirusTotal/y... - Once again, new release with some good bug fixes and nice improvements.
github.com
Release v1.13.0 · VirusTotal/yara-x
Add crx and dex modules to Python invoke API (#534). Add Python API for specifying the metadata that should be passed to modules (6bebe34): Output filenames that needs reformatting when using yr fm...
021
Wesley Shields @wxs.bsky.social · 26/01/2026
YARA-X 1.12.0 is out. Some small bug fixes but still worth upgrading! Once again, congrats to Victor and the contributors as the project keeps getting better. github.com/VirusTotal/y...
github.com
Release v1.12.0 · VirusTotal/yara-x
Improvements in the parser to produce better Concrete Syntax Trees (#531, c46b3bd). BUGFIX: avoid panic when parsing some regular expressions (136ab9f).
130
Wesley Shields @wxs.bsky.social · 09/01/2026
github.com/VirusTotal/y... - 1.11.0 is out! Lots of new features, modules and bug fixes. Read the release notes and congrats to Victor and the contributors!
github.com
Release v1.11.0 · VirusTotal/yara-x
Make the parser stricter (#502). Implement dex module (#458). Implement C api console log (#515). Implement permhash for the crx module (#510). Implement the imports() method for the Rules object i...
063
Wesley Shields @wxs.bsky.social · 13/12/2025
One wheel Jesus was at the Christmas parade again. All praise be to one wheel Jesus and his crew.
000
Wesley Shields @wxs.bsky.social · 09/12/2025
Quality of life improvement for yara-x: I realized the functions that output hash values do not have constraints on them like the hash module functions do. See virustotal.github.io/yara-x/blog/... for details on why this is useful to extend everywhere. PR that fixes it: github.com/VirusTotal/y...
github.com
feat: More constraints on hashes by wxsBSD · Pull Request #509 · VirusTotal/yara-x
The imphash implementation always returns a lowercase md5. This commit switches the type of the returned value so that it can be used to generate warnings. Warnings are now generated if you use an ...
021
Wesley Shields @wxs.bsky.social · 20/11/2025
Yara-x 1.10.0 released today! It can now automatically fix some warnings, and some improvements in code generation. This is another great step forward for the project. github.com/VirusTotal/y...
github.com
Release v1.10.0 · VirusTotal/yara-x
New yr fix warnings command (#493). Generate more efficient WASM code for some expressions, reducing the size of compiled rules (5efc214, a865681). Improve the API for traversing the AST in DFS ord...
072
Wesley Shields @wxs.bsky.social · 14/11/2025
Don't ask why but you may now refer to me as "Sir Wesley, robot, esq." (thanks @gabagool.ing for that one) and gemini thinks this is what I look like. It may have had some help with the Pikachu hoodie and hot dogs. You're welcome for this visual.
020
Wesley Shields @wxs.bsky.social · 14/11/2025
Finally put this up for review in a PR (github.com/VirusTotal/y...) - it's now in it's own command and has been tested on some pretty gnarly graphs of rules. If you have huge dependency graphs the output gets messy, but it works well otherwise.
github.com
feat: Add "deps" command to generate a graph of rule depdendencies. by wxsBSD · Pull Request #498 · VirusTotal/yara-x
This branch adds a "deps" command that generates dependency information for a set of rules. It walks the AST looking for identifiers of rules, modules and unknown identifiers (hopefully e...
111
Wesley Shields @wxs.bsky.social · 09/11/2025
If you're interested in my dependency querying code for yara rules check out my deps branch: github.com/wxsBSD/yara-... You can build it with "cargo build --features=debug-cmd" and use it like "yr debug deps -h". My TODO list for this is basically: - Write tests - Move to it's own command
github.com
GitHub - wxsBSD/yara-x at deps
Experimenting with YARA and Rust. Contribute to wxsBSD/yara-x development by creating an account on GitHub.
021
Wesley Shields @wxs.bsky.social · 05/11/2025
@pdub5.bsky.social does great work! If you’re going to be at the conference go see his talk and maybe heckle him for me.
091
Wesley Shields @wxs.bsky.social · 04/11/2025
I've got something built on Victor's new DFSIter for yara-x AST that takes a set of rules and outputs the dependencies and modules used (based upon the compiled list of modules). Ultimately I want to make it output a graphviz file for visualization but for now it's dumping them to stdout...
121
Wesley Shields @wxs.bsky.social · 03/11/2025
yara-x 1.9.0 is out! The DFSIterator for AST traversal is what I was finishing up this week (and now I don’t have to, yay), and is definitely really interesting if you are into that sort of thing. I’ll finish my work onto top of this new implementation. github.com/VirusTotal/y...
github.com
Release v1.9.0 · VirusTotal/yara-x
Add function for scanning files by path to the C and Go APIs (32bac10). Add version number to the Rust API (bdb53e8, #469). Add osabi field to elf module (afa0960). Avoid verifying patterns when th...
020
Wesley Shields @wxs.bsky.social · 02/11/2025
I’ve been working on something in YARA-X that I think is needed if you have complex sets of rules and dependencies. Should have something to show next week.
120
Wesley Shields @wxs.bsky.social · 20/10/2025
cloud.google.com/blog/topics/... I wrote some more on COLDRIVER - specifically about their recent malware they have been using since at least May. If you’re on the COLDRIVER target list keep an eye out for this stuff. They have been more active with it than previous malware.
cloud.google.com
To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER | Google Cloud Blog
Russia state-sponsored COLDRIVER started using new malware immediately following a May public disclosure of their activity.
0116
Wesley Shields @wxs.bsky.social · 16/10/2025
Thanks to @xorhex for an interesting discussion that is worth sharing here. I knew I read this somewhere but here's a fun thing you can do in YARA-X: 2 of ($a*, $b*, 3 of ($c*)) This is documented but not widely known: virustotal.github.io/yara-x/docs/...
virustotal.github.io
Differences with YARA
Documents the differences between YARA-X and YARA.
264
Wesley Shields @wxs.bsky.social · 15/10/2025
Is it a good idea to have a modifier that treats ' the same as " in strings. Something like this: $a = "foo('bar')" quotes This would effectively get you that string and foo("bar") but also foo('bar") or any combination of quote usage. Might have to put some thought into this and implement it.
110
Wesley Shields @wxs.bsky.social · 09/10/2025
Smart person says smart things! And it’s not just when walking this structure (though it is great there) it is for any loop that can get out of hand. Use it and be happy. Don’t use it and be sad - as I have seen first hand multiple times.
010