skip to content

What is the difference between a detection closed as a false positive and one nobody ever opened?

level: juniorimportance: should knowfreq 58%

answer

  1. one row is a conclusion, one is silence
  2. capacity, not maliciousness
  3. unsampled population in your metrics
  4. false positive versus benign true positive
  5. unopened items age towards retention

basics

~20 s

A closed false positive is a verdict somebody reached. An unopened detection is the absence of a verdict: it tells you about the SOC's capacity, not about the estate, and it can never be counted as benign.

solid answer

~50 s

Closing a detection as a false positive is a **claim about the world**: an analyst looked at the supporting telemetry and concluded the rule matched something that was not the behaviour it describes. That closure is evidence — about the rule, about what is normal in this estate, and it feeds the rule's measured precision. An **unopened** detection carries none of that. Nobody looked, so its status says something about queue capacity and nothing at all about whether the activity was malicious. Two practical consequences follow. First, any hit-rate or false-positive-rate you quote is measured over the worked items only; the unopened band is an unsampled population and the number does not describe it. Second, an unopened item still has a clock on it — the telemetry you would need to adjudicate it is ageing towards its retention limit while it sits there.

go deeper

for a junior

Be ready to state the difference in one sentence: a closure is a verdict, an unopened item is the absence of one. Know the three dispositions — false positive, benign true positive, true positive — and never describe an unopened item as any of them.

for a middle

Expect to explain why the distinction corrupts metrics: hit rates and per-rule precision are computed over worked items, and the unopened band is a non-random, unsampled population that those numbers do not describe.

for a senior

Show you manage the consequence: unopened items have an evidence clock, the tail must be counted and reported as unadjudicated rather than folded into a noise figure, and per-rule precision claims must state what they were measured over.

for a principal

Own the reporting line. Decide what the organisation is told the backlog means, insist the unadjudicated count appears next to the false-positive rate, and refuse a metric that lets an unexamined tail read as a clean estate.

## Two rows that look identical in the console In a case queue, a detection closed last Tuesday as a false positive and a detection raised in March that nobody has opened can sit next to each other looking equally *dealt with* — both are out of the way, neither is paging anyone. They are epistemically opposite, and confusing them is the most common junior mistake on an unworked backlog. ## What a closure actually is A closure is a **verdict**: a human (or an automation someone signed for) examined the record that triggered the rule plus whatever else was needed, and concluded something. There are three closure verdicts worth naming, because interviewers probe the distinction: - **False positive** — the rule matched, but the behaviour it claims to describe did not occur. The rule's logic was wrong about this input: it keyed on a filename, a parent process or an API call that also appears in something else entirely. - **Benign true positive** — the rule was *right*. The behaviour really happened exactly as described, and it was authorised or expected: the backup service really did read every object in the bucket; the platform team really did share that snapshot with the partner account, under an approved change. Nothing about the rule needs fixing; the estate simply contains a legitimate instance of the behaviour. - **True positive** — the behaviour happened and it was not authorised. This escalates. All three are information. They tell you the rule's precision in this estate, they tell you what normal looks like here, and they leave a written trail somebody can audit. ## What an unopened item is An unopened detection is the **absence of a verdict**. The only fact it establishes is that the rule fired and that the SOC's throughput did not extend to it. It is not a false positive, it is not benign, and it is equally not a missed intrusion — you do not know, and the record of not-knowing is the entire content of the row. The direction of the claim matters, because both wrong directions are common in interviews. *Optimistic:* 'nothing came of it, so it was noise' — nothing came of it because nobody looked; no consequence was ever going to surface from an unexamined item unless the intrusion announced itself some other way. *Pessimistic:* 'nine thousand unopened detections means nine thousand intrusions' — equally unfounded, and it makes the whole number unusable in a conversation with anyone who can fund a fix. ## Why the distinction bites in practice **Metrics quietly lie.** A SOC that reports a 98% false-positive rate has almost always computed it over *closed* items, because those are the ones with a disposition field filled in. If a third of the arrivals are never opened, that percentage describes the worked sample and says nothing about the tail. The same trap catches per-rule precision: a rule whose alerts nobody has opened has no measured precision at all, and reporting it as 0% true positives is a fabrication. **The tail is a different population.** Items go unopened non-randomly — usually the medium and low bands, usually the noisy accounts, usually whatever arrives while an analyst is deep in something else. So the unopened set is not a random sample of arrivals and you cannot extrapolate the worked set onto it without doing the work of actually drawing a sample. **An unopened item has an expiry date.** The detection record itself may live in the case system for years, but the surrounding telemetry — the control-plane log, the endpoint process history, the sign-in records — lives only as long as the retention window. An item that ages past that becomes permanently unadjudicable: not benign, just unanswerable forever. ## How to say it in an interview The answer they are listening for is one sentence plus one consequence: *a closure is a conclusion, an unopened item is the absence of one, so it can never be counted as benign — and every hit-rate we quote is measured only over what we worked.* If you can add that the unopened band ages out of retention and becomes permanently unanswerable, you are already answering the follow-up.

  • Your manager says the unopened part of the queue is all false positives anyway. How do you respond?
    That is a claim about a population nobody has sampled. The false-positive rate we publish is computed over worked items, and items go unopened non-randomly — mostly the medium band and the noisiest accounts. If we want a number for the tail, the only honest route is to draw a random sample from it and work those to a real verdict, then report the estimate with its uncertainty.
  • Is a benign true positive the same thing as a false positive?
    No. A false positive means the rule was wrong about what happened. A benign true positive means the rule was right — the behaviour occurred exactly as described — but it was authorised or expected, like an approved change or a backup job. The remediation differs: a false positive means fix the logic; a benign true positive means encode the known-good context, and the rule itself is working.
  • Does an unopened detection prove the SOC missed an intrusion?
    No. It proves only that no verdict exists. Treating the tail as an intrusion count is as unfounded as treating it as noise, and it makes the number useless in a budget conversation. The defensible statement is that these items were never adjudicated and, past the retention horizon, can no longer be.

A closed case is a verdict returned. An unopened case is a file that never reached a courtroom — no one may report that as an acquittal.

saying these in an interview costs you the question

  • Calling unopened items false positives because nothing escalated
  • Quoting a false-positive rate computed only over closed alerts
  • Assuming every unopened detection is a missed intrusion
  • Treating a benign true positive as a rule defect to tune away
  • Believing the alert record surviving means the evidence survived

context