Sleep Obfuscation: How Beacons Vanish in Memory and Where the Artifacts Survive

Article banner for Sleep Obfuscation: red-team encrypted beacon memory and timer callback chains on the left, blue-team memory scanning, entropy detection and ETW-TI VirtualProtect monitoring on the right

AuthorAdrián DíazRead time14 minPublishedApr 23, 2026TopicsWindows InternalsEDR Evasion Table of Contents The previous post covered call stack spoofing: how an implant makes its call stack look legitimate at the moment an EDR inspects it. But that solves only half the problem. A memory scanner does not wait for the implant to call an API. It […]