Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is a false negative?

A false negative is relevant or malicious activity that happened but was not detected by the security control that should have helped identify it.

For an investigator, the key lesson is simple:

no alert does not mean no event.

Detection depends on visibility

A product can only alert on activity it can actually observe and recognise.

It may miss activity because:

  • the device was unmanaged;
  • the sensor was offline;
  • logging was disabled;
  • the relevant integration was missing;
  • traffic was encrypted;
  • a rule did not cover the technique;
  • thresholds were not reached;
  • telemetry had expired;
  • a legitimate tool was abused.

Another source may still have seen it

Imagine EDR produced no alert, but the identity provider and server both recorded activity:

EDRNo alertThe endpoint control did not flag the activity.
IdentitySuccessful session recordedAuthentication evidence still exists.
ServerRemote process executedTarget-side evidence shows what happened.

That is why incident reconstruction should not rely on one detection product.

Work out what the product could have seen

Check:

  • which devices were covered;
  • sensor health;
  • available telemetry;
  • rule state;
  • product version;
  • exclusions;
  • retention;
  • alert suppression/grouping.

Then describe the negative finding narrowly.

For example:

“No alert was generated by rule X on the telemetry retained for FILE-03.”

That is much stronger than:

“No attack occurred.”

The practical point is: interpret silence through the product’s actual coverage and then check independent sources for the event itself.

Reference: CIM-021Cyber Incidents & Offender Methods