- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-20-2022 07:20 PM
Hi @reg_naidu , by definition, a True Positive is when a behavior was correctly detected after it was performed.
On the other hand, a False Positive is when a behavior that was not performed was detected.
In this case, as the behavior was benign but was incorrectly categorized as malicious, this would be a False Positive.
Do note that these are low severity Analytics alerts - you will need to take into account if the alert was due to the endpoint leveraging VPN or similar solutions that use different gateways for optimal connectivity etc. That is the reason why the severity is low.
A low severity alert will not create an incident by itself, but will be stitched to an existing incident which would have medium/high sev alerts. You can also look at the corresponding Analytics alerts here.