Classification Types
| Classification | When to Use | Example |
|---|---|---|
| True Positive | Confirmed real security threat that required response | Actual malware execution, credential theft, lateral movement |
| Benign Positive | Real activity that triggered correctly but was expected or authorized | Scheduled penetration test, approved admin tool usage |
| False Positive | Incorrectly triggered due to flawed detection logic or bad data | Legitimate software flagged as malicious, misconfigured rule |
| Informational | Low-risk activity documented for awareness | Failed login attempt from known location, routine scan |
How to Classify an Incident
Add comments (recommended)
Document your reasoning — this helps with future tuning and audit trails.