Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is a false positive?

A false positive is a detection whose suspicious interpretation is not supported because the underlying activity is benign. The events can be genuine and the rule can have worked exactly as configured.

Legitimate behaviour can match attack patterns

Administrator scripts, vulnerability scans, travel and unusual business activity may satisfy valid detection conditions. The alert was useful if it prompted review; its later classification changes the interpretation, not the historical source records.

“False positive” should therefore not be used to mean that nothing happened or that the evidence can be discarded.

Evaluate the basis of the classification

Preserve rule logic, source events, analyst notes, closure reason and later status changes. Establish whether a quick automated closure, an analyst assumption or a full technical examination produced the decision.

A previous benign outcome does not make every future match harmless. Each occurrence has its own sources and context. Report both what genuinely occurred and why the available review supported a benign rather than hostile explanation.

The point to remember

A false positive is a real detection with an unsupported suspicious interpretation, not necessarily a faulty rule or nonexistent event.

Reference: LOG-109Logs, Records & Provider Evidence