5
509322
Yes, cmd produces too many alerts for the average noob to survive. That is why they modified the default config and disabled code detection for cmd.
The other monitored processes are much rarer and don't run on my system, such as java and python.
It's a joke. Just make the interpreters untrusted and every time they execute you will get a HIPS alert. That way the security program feeds back useful infos to the user. I mean, if you get an alert for say - RegAsm - out of nowhere, then you know something might not be quite right. For something like cmd, you can make limited permanent allow rules for it as a parent or child process.
There is an extended list of vulnerable processes. You learn the processes on this list. If you get a HIPS alert for any of those processes you take a look-see.
This is not difficult. Children and grandmas can do it.