The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling command-line history

Prev Next

Some endpoints may require Microsoft Security Advisory to be installed as described in the Microsoft Knowledge base article KB3004375 (typically only required for versions of Windows prior to Windows 8.1 or server 2012 R2). To enable command-line monitoring, you enable a group of policy setting.

To change the setting:

  1. Launch the local group policy editor (gpedit.msc) and navigate to Computer Configuration > Administrative Templates > System > Audit Process reaction.

  2. From the right pane, click the Policy Setting link for the Include command line in process creation events setting.

  3. In the dialog box, select the Enabled option and then click Apply to apply the changes to the system.

For additional information, see the Microsoft documentation here.