Marking an alert as a false positive

Prev Next

When you click Mark False Positive on an alert, the Mark as False Positive page appears. You can view an alert and mark the alert as a false positive from either of these alert pages:

  • Alerts page—Select Mark as False Positive from the Options menu for an alert. For more information about the Alerts page, see Viewing alerts on the Alerts page.

  • Host Alert Details page—Select an alert and click Mark False Positive in the alert details. For more information, see Host Alert details page.

Note

You can also mark an IOC or XPLT alert as false positive from the Triage Summary page, but this workflow does not open the Mark as False Positive page. For more information, see Defining false positive rules on the Triage Summary page.

Mark as False Positive page

The Mark as False Positive page displays a summary of options for the false positive rule. The false positive rule is applied to all future detection except on exploit (XPLT) alerts. For exploit alerts, the existing alerts in the system are marked as false positive, but future detection will not be affected by the false positive rule.

Important

To enable the false positive rule for all future detection of exploit alerts, you must clear the Exploit Timestamp checkbox. It is selected by default.

In the example below, the Summary shows that 6,472 alerts occurred on a single host, with 7,270 files quarantined.

Alert_MarkFP_mod.png
Prerequisites
  • Administrator, Senior Analyst or Investigator access

False positive criteria

In the Endpoint Security (HX) Web UI, you can mark an alert as false positive based on certain criteria. This information is then applied to other alerts matching the same criteria. The available false positive criteria for each alert type is provided in the table below.

Alert type

False positive criteria

Malware (MAL)

  • Malware Name

  • Path

  • MD5 hash

  • Digital Signature

Exploit (XPLT)

  • Exploit Timestamp

  • Exploit Process Path

  • Exploit Process MD5 hash

Indicator of Compromised (IOC)

Condition—You can mark the specific condition that identifies this alert as a false positive. You cannot mark individual terms within the IOC alert.

Generic alerts

Conditions for generic alerts depend on the parameters provided by the alerting module.

To define a false positive rule:
  1. Select Alerts at the top of the Endpoint Security (HX) Web UI page.

  2. Select the alert you want to mark as a false positive in the alerts table. You can use filtering to narrow your search results.

    The alert details page appears. Details are shown on the right side of the page. The rule or indicator that caused the alert is shown at the top.

    • For MAL, XPLT, and generic alerts, the Mark False Positive button appears to the right of the rule.

    • For IOC alerts, click the Alerted on tab. The Mark False Positive button appears to the right.

  3. Click Mark False Positive.

    The Mark as False Positive page appears for MAL, XPLT, and generic alerts.

  4. Select one or more conditions from the alert that you want to include in the false positive rule.

    Note

    The summary counts on the left of the page show the total number of alerts affected by your selections, the total number of hosts affected by your selections, and the total number of files that will be restored based on your selections after the false positive rule is defined.

  5. (Optional) Select Delete all the affected alerts for these marked false positive condition(s) if you want to delete the affected alerts.

  6. Click Mark False Positive.

  7. Click Export False Positive Alert Details to export the details about the false positive rule to a CSV file.

  8. Optionally, click Export Quarantined File Details to export details about the quarantined files affected by the false positive rule to a CSV file.

  9. Click Confirm on the confirmation page summarizing the false positive rule definition.

    The false positive rule is added to the False Positives tab of the Rules page.