Marking indicators as false positives

On the Indicators page, you can mark indicators as false positives. To access this page, you need to switch to the Data management mode.

Indicators can be marked as false positives in the following ways:

You can also manually add indicators to the list of false positives.

To mark indicators as false positives:

  1. Do either of the following:
    • In the FP column of the table with indicators, click the Flag enabled icon (white flag on a white background). (Click to mark indicator as a false positive) icon for the required indicator.
    • In the table with indicators, select the check boxes next to the required indicators.
    • In the table with indicators, click the value of the required indicator.
  2. Do either of the following:
    • If some of the selected indicators are of several types, do one of the following:
      • Click the False positive button, and then click Mark {{type}} as false positives, where {{type}} is the indicator type that you want to mark as a false positive.
      • Click the False positive button, and then click Mark all as false positives if you want to mark all indicator types as false positives.
    • If none of the selected indicators have several types, click Mark indicators.
  3. In the confirmation window that opens:
    1. If you want to mark as false positives the detections related to the indicators, keep the Mark related detections as false positives check box selected.
    2. Click the Mark button.

    Mark indicator as a false positive window in CyberTrace.

    Confirmation of marking an indicator as a false positive

The selected indicators are marked as false positives. If you selected this option, the related detections are also marked as false positives.

The indicators that are marked as false positives are displayed with the Flag enabled icon (white flag on a blue background). icon in the FP column of the indicators table.

Page top