> Malware that is more stealth-conscious would just stop running without any indication, instead of interacting with external processes.
I always wondered if we could just use this against the malware. E.g. just run a useless process which is named/looks like a debugger and the malware stops itself. Of course that's nothing to be relied on on its own but maybe as an additional layer of defense?