Managing false positive rules

Prev Next

Alerts based on rules that match harmless activity are called false positive alerts. Reviewing false positive alerts can waste valuable Administrator, Senior Analyst, and Investigator time. You can suppress false positive alerts by identifying relevant indicator of compromise (IOC) conditions and specific malware, exploit, or generic alert information. The classification is not permanent and can be removed.