Classification vs Status
Before diving into classifications, it’s important to understand the difference between Status and Classification:Status
Work state of the investigation
- New — Not yet reviewed
- Active — Under investigation
- Closed — Investigation complete
Classification
Outcome of the investigation
- True Positive
- False Positive
- Benign Positive
- Undetermined
Status tracks where you are in the investigation process. Classification documents what you found when the investigation is complete.
Classification Types
True Positive
True Positive
The incident represents an actual security threat that required response.
- Confirmed malicious activity was detected
- A real attack or compromise occurred
- Threat actor activity was identified
- Malware, phishing, or unauthorized access was verified
- User credentials were actually compromised
- Malware was confirmed running on an endpoint
- Data exfiltration attempt was verified
- Unauthorized access to sensitive resources occurred
Benign Positive
Benign Positive
The detection was technically correct, but the activity was legitimate and authorized.
- Suspicious-looking activity was actually authorized
- A user performed unusual but legitimate actions
- IT/Admin activities triggered security alerts
- Penetration testing or security assessments caused alerts
- Admin legitimately accessed multiple systems during maintenance
- User traveled and logged in from an unusual location
- Authorized penetration test triggered alerts
- New software deployment caused unusual process behavior
False Positive
False Positive
The incident was incorrectly triggered due to flawed detection logic or bad data.
- Detection rule logic is flawed or too broad
- Inaccurate or corrupted data triggered the alert
- Misconfiguration caused incorrect detection
- The alert has no basis in actual activity

| Reason | Description |
|---|---|
| Inaccurate data | The data used to generate the alert was incorrect, incomplete, or corrupted |
| Incorrect alert logic | The detection rule itself is flawed and needs to be modified or disabled |
- Alert triggered on a non-existent user due to log parsing error
- Detection rule matches normal business activity too broadly
- Time zone misconfiguration caused false temporal correlation
- Deprecated system generated alerts for decommissioned resources
Undetermined
Undetermined
The investigation was inconclusive—the cause or outcome couldn’t be determined.
- Insufficient evidence to reach a conclusion
- Logs or data needed for investigation are unavailable
- The incident doesn’t fit other classification categories
- Investigation was abandoned due to resource constraints
- Relevant logs expired before investigation completed
- Activity was suspicious but couldn’t be verified either way
- Source system was decommissioned, preventing further analysis
- Alert context was insufficient for determination
Quick Reference
| Classification | Meaning | Action |
|---|---|---|
| True Positive | Real threat confirmed | Document threat details, validate response actions |
| Benign Positive | Correct detection, authorized activity | Consider tuning or adding exceptions |
| False Positive | Incorrect detection | Report for rule improvement |
| Undetermined | Inconclusive investigation | Document findings in comments |
Classification Decision Tree
Use this flow to determine the correct classification:Best Practices
Always add comments
Always add comments
Document your investigation findings regardless of classification. This creates an audit trail and helps with future investigations of similar incidents.
Be consistent
Be consistent
Work with your team to establish classification guidelines. Consistent classification improves metrics accuracy and detection tuning.
Review patterns
Review patterns
Regularly review classification trends. High False Positive rates indicate detection rules that need tuning. High Benign Positive rates suggest exception lists need updating.
Don't default to Undetermined
Don't default to Undetermined
Use Undetermined only when you genuinely cannot determine the outcome. Overuse of Undetermined reduces the value of your classification data.
Related Guides
Incident Management Guide
Complete workflow for managing incidents
Security Workbench
Investigate incidents with the Security Workbench
Questions about classifications? Contact us at [email protected].