ERAAgent.exe loads LZMA/7-zip decompression library then executes payload
Detects the loading of compression libraries (such as lzma.dll or 7z.dll) by ERAAgent.exe followed by suspicious process or thread activity (e.g., remote thread creation, memory allocation). This pattern is often associated with the staging and execution of malicious payloads in memory.
Microsoft Sentinel (KQL)

