@pmelson @r0wdy_ @pmelson The "what do you do about?" using the above states means that, if we're getting too many
Not a Threat - Improve suppression criteria, or our suppression logic. Investigative action.
False Positive - Improve the analytic(s). Detection Engineering action.
12/3/2020, 6:20:28 AM