logo

Avoiding Memory Scanners

ID: 18cac8b4-18c9-523d-b42b-1c09cbfd8485

STIX ID: report--18cac8b4-18c9-523d-b42b-1c09cbfd8485

Feed Name: Black Hills Infosec Blog

Threat Score
65/100

Date Published: 2022-09-22

Date Updated: 2026-04-27

Author: BHIS

...
...

This research/post describes methods to evade Windows memory scanners and endpoint detection by obfuscating and encrypting in-memory implants. It documents techniques including multi-byte/RC4 encryption via SystemFunction032, secondary-heap encryption, executable masking stubs, ROP and NtContinue-based FOLIAGE context switching, replacing Sleep with WaitForSingleObject, and return-address spoofing, and it introduces AceLdr — an open-source reflective loader implementing these techniques to bypass scanners like YARA, PE-sieve, Moneta, and BeaconHunter.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.