To configure Suspicious Connection Service to block/log the C&C IP address:
- On the Apex One web console, go to Agents > Agent Management.
 - Navigate to Settings and click Additional Service Settings.
 - Under Suspicious Connection Service, tick Windows desktops or Windows Server platforms.
	
	
Click the image to enlarge.
 - Go to Settings and click Suspicious Connection Settings.
 - Tick Detect network connections made to addresses in the Global C&C IP list. For Apex One or newer, then select Log only or Block from the dropdown options.
	
	
Click the image to enlarge.
 - Click Save.
 - Test the connection to the C&C IP address. In Block mode, the alert will pop up and the log can be found under Suspicious Connection.
 
		