What is a false negative?¶
A false negative is relevant or malicious activity that happened but was not detected by the security control that should have helped identify it.
For an investigator, the key lesson is simple:
no alert does not mean no event.
Detection depends on visibility¶
A product can only alert on activity it can actually observe and recognise.
It may miss activity because:
- the device was unmanaged;
- the sensor was offline;
- logging was disabled;
- the relevant integration was missing;
- traffic was encrypted;
- a rule did not cover the technique;
- thresholds were not reached;
- telemetry had expired;
- a legitimate tool was abused.
Another source may still have seen it¶
Imagine EDR produced no alert, but the identity provider and server both recorded activity:
That is why incident reconstruction should not rely on one detection product.
Work out what the product could have seen¶
Check:
- which devices were covered;
- sensor health;
- available telemetry;
- rule state;
- product version;
- exclusions;
- retention;
- alert suppression/grouping.
Then describe the negative finding narrowly.
For example:
“No alert was generated by rule X on the telemetry retained for FILE-03.”
That is much stronger than:
“No attack occurred.”
The practical point is: interpret silence through the product’s actual coverage and then check independent sources for the event itself.