Skip to content

WTFIsStalling 0.4.1

Choose a tag to compare

@github-actions github-actions released this 20 Sep 18:35
· 39 commits to main since this release

Why this release exists

Microsoft Defender's cloud service blocked the 0.4.0 download for at least one person as Trojan:Win32/Wacatac.B!ml. The !ml suffix means a machine-learning guess about an unfamiliar file, not a match against known malware; scanning the very same file with Defender on demand finds nothing. New, unsigned tools that ask for administrator rights and read low-level system data get this a lot. 0.4.1 removes what such models dislike and adds ways to check the download yourself.

What changed

  • Drives are never opened for reading or writing. SATA SMART data now comes from a Windows query that needs no access rights to the disk at all, like everything else the tool reads about drives.
  • The executables say what they are: product name, description, version, source link and an icon.
  • Build provenance. GitHub now attests that these exact files were built by this repository's release workflow from the tagged commit. With the GitHub CLI:
    gh attestation verify WTFIsStalling.exe --repo Tyberious/WTFIsStalling
  • Code signing is on its way. The release pipeline is ready for free open-source signing by SignPath Foundation; the application is pending, so these files are still unsigned.

No change to what the tool detects; see 0.4.0 for that.

If your antivirus still objects

Whether Defender's cloud model likes 0.4.1 better cannot be tested in advance. If a download is blocked, please open an issue with the detection name (Windows Security > Protection history) so it can be reported as a false positive.

Download

WTFIsStalling.exe is the app. wtfis-cli.exe is the same engine for the console.

Windows SmartScreen may warn about a new unsigned program: More info -> Run anyway. Checksums are in SHA256SUMS.txt.