Environment
- App Control Console: All Supported Versions
- Microsoft Windows: All Supported Versions
Symptoms
When using the <CmdLineAnyArgument:X> macro with multiple arguments in a custom rule process, the rule does not tag the matching events correctly.
Cause
<CmdLineAnyArgument:X> macro is being applied to each token in cmdline and it will try to match against two tokens due to the space between multiple arguments
Resolution
Use the <CmdLine:X> macro, it is able to support multiple arguments in the same command line value
Additional Notes
Related Content