Managing alerts, quarantined files, and false positives

Prev Next

Alerts are matches between one or more indicator rule conditions or source alerts and activity that EDRF Client find on their host endpoints. Analysts and Investigators review alerts to determine whether the matches represent harmless or normal activity (false positives) or potential compromise. Not every alert involves malicious activity.

If your review indicates that an endpoint is compromised, you can contain the endpoint so the threat does not spread. See Containment overview.

If an alert reported harmless activity that does not require further review, you can delete the alert and suppress future alerts by deleting related indicator rules and by minimizing false positive conditions.

This section covers the following topics: