An Introduction to Sleep Obfuscation for Malware (2023)
dtsec.us
dtsec.us
Not sure if you can actually hook/intercept VirtualProtect on the kernel side, probably not due to the performance and safety implications, but there are ETW feeds that emit telemetry for the call now (https://undev.ninja/introduction-to-threat-intelligence-etw/)