Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is a false positive?

A false positive is an alert that looked suspicious but, once checked, turned out not to represent malicious activity.

The important point is that the alert may have fired correctly even though the explanation was benign.

The behaviour can be real and still be harmless

Security tools often alert on patterns that attackers also use.

That can include:

  • remote administration;
  • vulnerability scanning;
  • backups;
  • new-location logins;
  • scripting;
  • bulk file access;
  • security testing.

A detection rule may be doing exactly what it was designed to do.

The question is whether the activity was authorised and expected in this environment.

Work from the alert into the context

Suppose an endpoint product alerts on PowerShell activity from an administrator account.

A useful comparison might be:

Alert viewPowerShell used with administrative privilegesPotentially suspicious behaviour detected.
Operational contextApproved software deployment at 02:00Change record, named administrator and matching deployment logs explain it.

That can support a well-founded benign explanation.

Closing the alert still needs evidence

Useful supporting material may include:

  • change tickets;
  • maintenance windows;
  • named operators;
  • deployment records;
  • scheduled task logs;
  • scanner configuration;
  • expected target systems;
  • outcome logs.

Do not close an alert simply because “IT do that”.

Test the explanation against the actual source, time, target and account.

Keep misuse in mind

A legitimate tool or genuine administrator account can still be abused.

So if the command is authorised but the target, timing or sequence is not, the alert may still matter.

The practical point is: a false positive is a supported benign explanation, not a label used to make an alert disappear.

Reference: CIM-020Cyber Incidents & Offender Methods