Wesley Shields
@wxs.bsky.social
670 followers 46 following 170 posts
Working at Google TAG. Retired FreeBSD committer. May or may not be a robot.
Posts Media Videos Starter Packs
Pinned
wxs.bsky.social
"The popular definition of 'simple' among programmers has moved from 'few moving parts' to 'short invocation' (easy) and this is a problem."

Not my quote but I stand by it.

Another good one: "Layers of abstraction become boundaries of competence"

That one is Travis Goodspeed I think.
wxs.bsky.social
Smart person says smart things! And it’s not just when walking this structure (though it is great there) it is for any loop that can get out of hand.

Use it and be happy. Don’t use it and be sad - as I have seen first hand multiple times.
xorhex.bsky.social
When walking a zip file's central directory structure using #yara-x, `math.max` and `with` are your friends.
wxs.bsky.social
I won’t be at CYBERWARCON this year so I need someone to give @hultquist.bsky.social a hard time for me. I don’t yet know why he deserves this, but I’m sure a reason will present itself between now and then. The man never disappoints in the shenanigans and tomfoolery department.
wxs.bsky.social
I appreciate it. Happy to help, but credit really goes to Victor for being so responsive to contributors and users!
wxs.bsky.social
And credit to @xorhex.bsky.social for the feature request that inspired me to get off my ass and do something.

github.com/VirusTotal/y...
wxs.bsky.social
Two things:

YARA-X 1.8.0 is out with some nice features if you use the various bindings and a bug fix involving an edge case in PE signatures. Congrats to all involved!

To be more useful I wrote a small PR to display filenames in console.log() output when using yr scan.

github.com/VirusTotal/y...
Release v1.8.0 · VirusTotal/yara-x
Implement block scanning API for Rust and C (#459, 185c2ee). Implement Golang and C APIs for setting global variables of type array and structure (#449). Add iterator for Rules object in Python (#4...
github.com
wxs.bsky.social
I’ve given the new Tanglewood album a few solid listens since the release on Friday. It continues to impress with the uncompromising sound and production quality out of this band. You should listen to the first two albums a few times to really understand this album. Definitely in my rotation list.
wxs.bsky.social
The first album by Lucid Planet was an instant like. A great progressive rock album that is insanely well produced. When the second album came out I liked it but it took a few full listens to really come into its own - I had to really embrace the electronica inspirations but definitely great album.
Lucid Planet
open.spotify.com
wxs.bsky.social
Those are the best. There’s a place near me called Utica Bakery that is run out of a trailer on cinder blocks. Only open a few hours on weekends and you get whatever they happen to post as their menu that day. Always sells out and so damn good.
Blocks.is / Typescript Components for Websites and User Interfaces
Collection of Typescript Components for building Websites and User Interfaces by Bridger Tower.
blocks.is
wxs.bsky.social
I got no problem with that, I’ve basically been encouraging it. I find it hilarious that most people who say it have no idea why people call me a robot.
wxs.bsky.social
The whole “wxs is a robot” meme has officially gone too far. See you in October!
volatilityfoundation.org
#FTSCon Speaker Spotlight: Wesley Shields (@wxs.bsky.social) is presenting “COLDRIVER: NOROBOT/YESROBOT/MAYBEROBOT” in the HUNTER track.

See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
wxs.bsky.social
Spotify algorithm is on some serious drugs. What the deuce is this?
wxs.bsky.social
Thanks! It's been a mixed bag but I'm surviving. You can't keep a good robot down!
wxs.bsky.social
Almost a month ago I had to have emergency surgery to have my gallbladder removed (not fun, do not recommend). It does mean I just got to use the sentence: "unnecessary organs will be removed for efficiency" - and for that I am happy.
wxs.bsky.social
Uh, that’s an every day breakfast item. Don’t know what weird stuff you’re doing up there!
wxs.bsky.social
Somebody to love. Perfect melody and harmonies.
wxs.bsky.social
I’m old enough to remember lil john and the ying yang boys. I won’t be calling them by that name, at least not with a straight face!
a man with dreadlocks wearing a ny hat and glasses says yeaaahhhh
ALT: a man with dreadlocks wearing a ny hat and glasses says yeaaahhhh
media.tenor.com
wxs.bsky.social
Patrick doing good work and with classy emoji usage in the <whatever the equivalent to a tweet is>.
wxs.bsky.social
…shellcode that is written to be benign on one platform but do something malicious on another.

Knowing what the bytes mean in the context in which they are executed is critical to expressing complex signatures.
wxs.bsky.social
I’ve said this and a corollary to this for years. It’s all just bytes but “why is that particular sequence interesting” and “what do those bytes mean in the context of this malware” are the more interesting questions.

Many decades ago I discovered something new to me that illustrates this…
greg-l.bsky.social
the biggest skill jump I took with yara was to think how the bytes within a file relate to one another

Malware isn’t a monolith - it’s a composite of bytes, and those bytes have to work together to do their job.

we can exploit those unique relations to track em
wxs.bsky.social
First question: Will I be fired for only referring to you as Sir Tom of The House of Lancaster?

Seriously though, if you’re looking this is one of the teams I would consider.