NOTE: If the Command Line Column is not available in Reports Events:
Navigate to Settings > Login Accounts > User Roles > relevant Role > View Details (pencil icon)
Add the Permission: View process command lines
Additional Information
It is recommended to start with Rapid Configs in Report mode before changing to Block to allow an opportunity to test changes.
Using a more dynamic Exception to start with is recommended. This makes it easier to verify the Exception is properly formatted.
Further testing should be done to determine how specific to make the Exception while still allowing desired functionality.
Exceptions may need to be adjusted over time depending on changes by 3rd party vendors.
Example: Suspicious Command Line Protection N-Z
By default the Sc Command Lines To Report is:
<cmdline:*create*>sc.exe
This means that anytime the process sc.exe includes create in the command line, the Agent may take action. An example that would trigger this Rapid Config could be: