Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is a false negative?

A false negative occurs when relevant or malicious activity is present but the detection system does not alert. The absence of an alert is meaningful only in relation to expected coverage and sensitivity.

Detection always has boundaries

Required logs may be absent, collection or parsing may fail, a rule may not cover the technique, or exclusions and suppression may apply. Valid credentials and trusted tools can also make hostile activity resemble normal use.

Missed activity often becomes visible only through source-log searches, forensic examination, provider evidence or another platform's detection.

Test whether an alert should have existed

Identify the data sources, rules, versions and configuration active at the relevant time. Determine whether the alleged behaviour would normally generate the necessary telemetry and satisfy a rule. Search underlying authentication, endpoint, network, application or cloud records rather than relying on the alert list.

Say that no alert was located in the available system. Claiming the activity did not occur requires much stronger evidence that the system had complete, reliable capability to detect it.

The point to remember

No alert is not proof of no activity unless the system was reliably expected to detect that activity.

Reference: LOG-110Logs, Records & Provider Evidence