The Core Prevention Defense Evasion rule is blocking the bladerunner.exe process if the parent process is conhost.exe and this is generating a large amount of alert events in the Carbon Black Cloud console.
This should have been working in same way (blocking) for previous sensor versions also and only in 4.1 it is getting highlighted because of new rule for reporting masquerading (which also is tagging the sensor_action).
This is being fixed in a future CBC Rules release to add an exclusion for this type of behavior; however, since this is a cosmetic issue and not creating a meaningful block event the timeline is unknown.