ERAAgent.exe staged payload assembly with SHA-256 verify-then-execute (SLEEPWALKER)
Detects a suspicious pattern associated with the SLEEPWALKER technique, involving multiple memory write operations followed by a memory protection change within an ERAAgent.exe process. This behavior suggests code injection or dynamic code loading within a process.
Microsoft Sentinel (KQL)

