cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who Me Too'd this solution

L5 Sessionator

Hi @reg_naidu , by definition, a True Positive is when a behavior was correctly detected after it was performed.
On the other hand, a False Positive is when a behavior that was not performed was detected.

In this case, as the behavior was benign but was incorrectly categorized as malicious, this would be a False Positive.

Do note that these are low severity Analytics alerts - you will need to take into account if the alert was due to the endpoint leveraging VPN or similar solutions that use different gateways for optimal connectivity etc. That is the reason why the severity is low.
 A low severity alert will not create an incident by itself, but will be stitched to an existing incident which would have medium/high sev alerts. You can also look at the corresponding Analytics alerts here.

View solution in original post

Who Me Too'd this solution