Files
JLospinoso-gargoyle/docs/references.md
T
Josh Lospinoso 21f6303990 feat(native): complete Gargoyle refresh backlog
Complete the native build/runtime refresh while preserving the Win32 proof-of-concept baseline.

- add the GargoyleX64 sibling prototype with x64 NASM PIC and timer reentry parity

- consolidate Visual C++ and NASM behavior into shared MSBuild props/targets

- expand just recipes and the acceptance harness across x86/x64 Debug/Release builds

- harden native quality gates with MSVC warnings-as-errors, code analysis, and ASan build coverage

- refresh README and MkDocs architecture, validation, responsible-use, references, and future-work docs

Validation:

- just ci

- just native-check

- Debug and Release live acceptance

- Debug x64 smoke run

Closes #2.

Closes #13.

Closes #14.

Closes #15.

Closes #16.

Closes #17.

Closes #18.

Closes #19.
2026-05-14 10:15:43 -10:00

7.1 KiB

Reference Map

This page places Gargoyle in the public research lineage around memory-scanner evasion, process-memory forensics, and later sleep-obfuscation work. It is a curated map, not an endorsement of every linked project or an implementation guide. The repository should remain a small, benign research artifact.

Access dates below use 2026-05-08.

Original Work

  • Gargoyle: A memory scanning evasion technique is the original March 2017 article that explains the waitable-timer, APC, stack-pivot, and protection-flipping proof of concept. It is still the best starting point for understanding what this repository is intended to show. Accessed 2026-05-08.

  • JLospinoso/gargoyle is the original public proof-of-concept repository. The current refresh preserves the Win32 implementation while adding build, validation, and documentation scaffolding around it. Accessed 2026-05-08.

Detection And Forensics

Direct Derivatives And Adjacent Experiments

  • Bypassing Memory Scanners with Cobalt Strike and Gargoyle is an MWR/WithSecure experiment that applied the Gargoyle idea to a larger payload. It is useful here mainly because it made defender-visible artifacts explicit and helped motivate the later detection work. Accessed 2026-05-08.

  • waldo-irc/YouMayPasser describes itself as an x64 Gargoyle implementation and documents several indicators of compromise in its README. Treat it as lineage and design context rather than a target architecture for this repository. Accessed 2026-05-08.

  • mgeeky/ShellcodeFluctuation cites Gargoyle as background for cyclically changing memory protections and optionally encrypting content while dormant. It is part of the broader family of memory-state fluctuation ideas that followed Gargoyle. Accessed 2026-05-08.

Later Sleep-Obfuscation Family

  • Idov31/Cronos is a waitable-timer based sleep-obfuscation proof of concept that draws from the Ekko family and uses repeated protection and encryption state changes during idle periods. It is a useful comparison point because it keeps timers central while moving beyond Gargoyle's tiny Win32 shape. Accessed 2026-05-08.

  • Cronos Sleep Obfuscation is the companion write-up for Cronos and discusses how later sleep obfuscators evolved from simple memory-protection toggling into timer-driven encryption and re-entry strategies. Accessed 2026-05-08.

  • Understanding Sleep Obfuscation gives a defender-oriented comparison of Ekko, Cronos, Foliage, and related approaches. It is especially useful for thinking about detection categories rather than any single implementation. Accessed 2026-05-08.

  • Hunting for timer-queue timers covers detection work for timer-queue based sleep obfuscation and contrasts that family with waitable-timer variants such as Cronos. Accessed 2026-05-08.

Windows API And Tool References

  • VirtualProtectEx is the Win32 API Gargoyle uses to toggle the setup PIC between executable and non-executable protections. Accessed 2026-05-08.

  • SetWaitableTimer documents the waitable timer and completion routine behavior that Gargoyle uses for re-entry. Accessed 2026-05-08.

  • WaitForSingleObjectEx documents alertable waits, which are important because queued APC completion routines only run when the relevant thread enters an alertable state. Accessed 2026-05-08.

  • Using Waitable Timers with an Asynchronous Procedure Call is Microsoft's conceptual example for waitable timers with APC completion routines. Accessed 2026-05-08.

  • VMMap is the Sysinternals process memory viewer used in the original demo instructions and in the refreshed manual validation checklist. Accessed 2026-05-08.

Open Follow-Ups

  • The initial refresh audit mentioned "Mirage" among later related work, but no reliable public source was verified during this docs pass. Keep it as a follow-up research item before adding it as a citation.

  • The x64 lineage deserves an implementation-focused comparison now that Gargoyle has a sibling x64 timer/APC example. This page intentionally records public references without prescribing a broader evasion design.