Working with false positives

April 11, 2024

ID 254720

Kaspersky CyberTrace allows you to mark indicators and the related detections as false positives, as well as to display or hide the statistics of false positives on the Dashboard page.

Marking indicators as false positives

You can mark indicators as false positive in the following ways:

  • On the Indicators page
  • On the page of a certain indicator

To mark indicators as false positives on the Indicators page:

  1. On the Kaspersky CyberTrace web user interface, select the Indicators tab.
  2. In the indicators list table, choose the indicators that you want to mark as false positives by doing one of the following:
    • Select the checkboxes for the indicators located in the left-most column of the table, and then click the Icon for adding false positives (plus sign in a square). button displayed in the bar False positive add and remove bar in CyberTrace. Plus icon is enabled. that appears above the table.
    • Click the Flag disabled icon (white flag). icon in the FP column of the table.
  3. In the dialog box that opens, confirm your action by clicking the Mark button.

    Along with the indicators, you can mark the related detections as false positives by selecting the corresponding checkbox. This checkbox is selected by default.

    Mark indicators as false positives window in CyberTrace.

    Marking indicators as false positives

The indicators marked as false positives are displayed with the Flag enabled icon (grey flag). icon in the FP column of the indicators table.

To mark an indicator as a false positive on the page of a certain indicator:

  1. On the Indicators page, click the indicator that you want to mark as false positive.
  2. On the indicator page that opens, click the Mark as false positive button.
  3. In the dialog box that opens, select the checkbox for the related detections that you to mark as false positive.
  4. Click Save.

    The indicator is now marked as false positive.

Removing indicators from false positives

You can remove indicators from false positives in the following ways:

  • On the Indicators page
  • On the page of a certain indicator

To remove indicators from false positives on the Indicators page:

  1. On the Kaspersky CyberTrace web user interface, select the Indicators tab.
  2. In the indicators list table, choose the indicators that you want to remove from false positives by doing one of the following:
    • Select the checkboxes for the indicators in the left-most column of the table, and then click the Icon for removing false positives (minus sign in a square). button displayed in the bar False positive add and remove bar in CyberTrace. Minus icon is enabled. that appears above the table.
    • Click the Flag enabled icon (grey flag). icon in the FP column of the table.
  3. In the dialog box that opens, confirm your action by clicking the Remove button.

    Along with the indicators, you can remove the related detections from false positives by selecting the corresponding checkbox. This checkbox is selected by default.

    Remove indicators from false positives window in CyberTrace.

    Removing indicators from false positives

The indicators that are not marked as false positives are displayed with the Flag disabled icon (white flag). icon in the FP column of the indicators table.

To remove an indicator from false positives on the page of a certain indicator:

  1. On the Indicators page, click the indicator that you want to remove from false positives.
  2. On the indicator page that opens, click the Remove from false positives button.
  3. In the dialog box that opens, select the checkbox to remove the related detections from false positives if needed.
  4. Click Save.

    The indicator is now not marked as false positive.

Viewing indicators and related detections marked as false positive on the graph

To view on the graph whether the indicator or the related detection is marked or not marked as false positive:

  1. On the Graph page, double-click the node that you are interested in.

    A side panel opens on the right, containing detailed information about the node.

  2. Check the "Is false positive:" line.

    An indicator marked as false positive will have Yes.

    An indicator not marked as false positive will have No.

    Graph in CyberTrace. Information about a false positive indicator.

    False positives info on graph

Graphically, false positive indicators and the related false positive detections are different from ordinary indicators and detections, and are displayed as shown in the figure below:

Graph in CyberTrace. False positive indicators in black circles with diagonal stripes.

False positives graphical view on graph

Filtering false positives on the Indicators page

To filter false positives to be displayed on the Indicators page:

  1. Click the FP column of the table.
  2. In the dialog box that appears, select the checkboxes that you need:
    • Select all
    • False positives
    • Not false positives
  3. Click Apply.

    The indicators you have selected are now displayed on the page.

Filtering false positives on the Detections page

To filter detections to be displayed on the Detections page:

  1. Click the FP column of the table.
  2. In the dialog box that appears, select the checkboxes you need:
    • Select all
    • False positive
    • Not false positives
  3. Click Apply.

    The detections you have selected are now displayed on the page.

Displaying statistics about false positives on the Dashboard page

To display statistics about false positives on the Dashboard page, turn on the Show false positives toggle switch. The statistics on false positives will be displayed in the Statistics overview section, Supplier statistics section and its donut chart, and the Indicator statistics section and its donut chart.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.