Reflects inter-task data chaining via ScratchBuffer, all 84 tasks consuming
work data, new COM/WMI category with 8 tasks, updated anti-detection table,
corrected test counts (185 verified), and added cat-com to feature flags table.
Inter-task chaining: a 256-byte ScratchBuffer flows through all tasks in
a single run() call. Each task reads from it (blend_into) and writes back
results (absorb), creating a data-dependency chain where task N's output
influences task N+1's computation. An analyzer can no longer identify
individual tasks as isolated blocks.
Work data in all tasks: all 84 tasks now actively consume fed work data.
Filesystem tasks derive skip offsets and iteration biases from work data.
Registry tasks bias subkey/value enumeration counts. WinAPI tasks offset
starting indices for window/process/metric enumeration. Network tasks
select starting host indices and blend work data into response buffers.
New COM/WMI category (8 tasks): WQL queries against Win32_Process,
Win32_OperatingSystem, Win32_ComputerSystem, Win32_NetworkAdapterConfiguration,
Win32_LogicalDisk, Win32_Service, Win32_BIOS, and Win32_Processor. All
read-only. Uses COM automation with CoInitializeSecurity for reliable
initialization across apartment models.
84 tasks across 8 categories. All 182 tests pass.
Tasks can now accept arbitrary user variables via .feed() on the builder.
Data is cloned on entry and woven into task control flow (XOR into buffers,
seed derivation for loop bounds, hash inputs, cipher keys), making busywork
blocks indistinguishable from real data processing under data-flow analysis.
31 tasks across COMPUTE, MEMORY, and CRYPTO actively consume fed data.
All originals remain untouched — tasks receive read-only references to clones.
Test suite covers: per-type serialization (52), direct invocation of every
task with 10 work-data shapes x parameter extremes (18), mirror tests proving
data actually changes computation (28), data isolation (15), stress/regression
(23), and integration across all categories, intensities, and edge cases.
Explains the EDR/anti-cheat evasion purpose, why sleep() is a detection
signal, and how each design decision maps to a specific detection
technique it defeats. Includes example trace showing varied syscall
sequences across consecutive calls.
Pattern-breaking sleep replacement that executes real, varied work on
every call. Randomized task selection across 7 categories (compute,
memory, filesystem, registry, winapi, network, crypto) with intensity
levels and jitter. Zero time objects in the library binary.