SLEEPWALKER dpapi.dll side-load into ERAAgent.exe
Detects instances where 'ERAAgent.exe', part of the ESET Remote Administrator agent, loads the 'dpapi.dll' library from a location outside of standard Windows System directories (System32 or SysWOW64). Furthermore, the rule flags this behavior if the loaded 'dpapi.dll' file is either unsigned or contains an untrusted digital signature, which may indicate a malicious DLL side-loading or masquerading attempt to access protected system credentials.
Microsoft Sentinel (KQL)

