ERAAgent.exe dynamic API resolution of VirtualProtect/SetSecurityDescriptorDacl/
Detects ERAAgent.exe performing suspicious dynamic API resolution for functions commonly used by the SLEEPWALKER malware (VirtualProtect, SetSecurityDescriptorDacl, and CryptGenRandom). By resolving these functions at runtime via GetProcAddress rather than including them in the static import table, the malware attempts to evade detection and analysis.
Microsoft Sentinel (KQL)

