What is a false negative?¶
A false negative occurs when relevant or malicious activity is present but the detection system does not alert. The absence of an alert is meaningful only in relation to expected coverage and sensitivity.
Detection always has boundaries¶
Required logs may be absent, collection or parsing may fail, a rule may not cover the technique, or exclusions and suppression may apply. Valid credentials and trusted tools can also make hostile activity resemble normal use.
Missed activity often becomes visible only through source-log searches, forensic examination, provider evidence or another platform's detection.
Test whether an alert should have existed¶
Identify the data sources, rules, versions and configuration active at the relevant time. Determine whether the alleged behaviour would normally generate the necessary telemetry and satisfy a rule. Search underlying authentication, endpoint, network, application or cloud records rather than relying on the alert list.
Say that no alert was located in the available system. Claiming the activity did not occur requires much stronger evidence that the system had complete, reliable capability to detect it.
The point to remember
No alert is not proof of no activity unless the system was reliably expected to detect that activity.