While scoping an intrusion you find an alert closed as a false positive nine months ago — what do you do?
answer
- evidence before metrics
- your earliest activity just moved backwards
- check retention before planning queries
- the rule fired; the verdict was wrong
- found only because a later case was caught
basics
~20 sTreat it as evidence first: the intrusion starts nine months earlier, so re-scope that window before retention expires. Then correct the verdict — a rule that fired and was misjudged is a triage failure, not a coverage gap.
solid answer
~50 sTwo jobs, in this order. **Evidence:** the case moves your earliest known activity back nine months, so check what still exists for that window — raw logs may have aged out even though the case record, its matched fields and the analyst note survive — and preserve what is left before anything else. Re-scope from the new start date: different accounts, different hosts, possibly a different initial-access story. **Record:** correct the disposition, since downstream counts are computed from it and it currently says `not malicious` about a confirmed intrusion. Be precise about the failing step — the rule fired, so this is a triage failure, not a coverage gap, and it is fixed by enrichment and closure criteria rather than by new rules. Then log one known miss whose discovery channel was the back-timeline of a later case.
code
json · 13 lines{
"caseId": "SOC-4412",
"openedAt": "2025-06-14T02:31:00Z",
"rule": "file-sync client: bulk download from an unseen device",
"actor": "[email protected]",
"app": "corp-file-sync",
"deviceId": "d-9f21…",
"filesDownloaded": 3184,
"disposition": "false_positive",
"closedBy": "analyst2",
"note": "User confirmed over chat they were setting up a new laptop. Closed.",
"rawEventsRetainedUntil": "2025-09-14"
}go deeper
Be ready to say why a closed case from months ago matters during an investigation, and why the first move is to check what evidence from that period still exists.
Explain the difference between a rule that never fired and a rule that fired and was adjudicated wrongly, and why the two lead to completely different fixes.
Demonstrate the sequencing under pressure: preserve and re-scope the older window first, correct the record second, and label the miss with the channel that found it.
Own the culture consequence. Decide how reclassified verdicts are handled so that correcting the record stays cheap and analysts do not respond by refusing to close anything.
## Why this find is worth more than it looks A closed case surfaced during scoping is simultaneously the best evidence in the investigation and the most uncomfortable entry in your metrics. It is the best evidence because it is dated, structured, and describes what the estate looked like at a moment you would otherwise have to reconstruct from raw logs. It is uncomfortable because someone on your team looked at this activity, formed a verdict, and got it wrong. Handle it in that order — evidence, then record — because the evidence is perishable and the record is not. ## Evidence first: the timeline moved The practical consequences of an earliest-activity date moving back nine months are immediate: - **Retention.** Most estates retain hot, queryable logs for far less than nine months. Check, per source, what still exists for the new window before you plan any query. Cloud and SaaS audit trails, endpoint telemetry and network flow records will typically have different windows, and the case record itself usually outlives all of them. - **Scope.** Everything derived from the old start date is now provisional: which accounts were involved first, which host was patient zero, which access path was used. Re-run scoping queries against the extended window rather than assuming the earlier activity is simply `more of the same`. - **Preservation.** Whatever survives in the older window should be preserved now, before an automated lifecycle policy removes it mid-investigation. - **What the old case already gives you.** The matched fields at the time of firing, the analyst's note, the enrichment attached to it and any artefacts collected are often the only surviving record of that period. Read the note carefully: it usually names the reasoning that has to be re-examined. In a slow-drip exfiltration through a sanctioned file-sync client, the note might read that the user confirmed by chat that they were setting up a new laptop. That is a specific claim you can re-test today: was the confirmation from the user or from someone in the user's account; did the device that was set up match the device that kept downloading; did the downloading continue after the stated setup date. ## Then the record: correct it, and be precise about the failure The disposition currently asserts `false positive` about activity now known to be part of an intrusion. Leave it and every count derived from dispositions is wrong — including the per-rule quality numbers that might otherwise get the rule retired for being noisy. Be exact about where the failure was. A rule fired: coverage worked. What failed was the adjudication. That distinction matters because the fixes are disjoint: - a coverage failure is fixed by telemetry or by new detection logic; - an adjudication failure is fixed by enrichment that puts the missing context in front of the analyst, by closure criteria that forbid closing on a user's self-report alone, or by a review step on a class of case where the cost of being wrong is high. Writing `detection gap` in the record when the rule fired sends the remediation effort to the wrong place and, worse, produces new rules that will be closed the same way. ## Handle the analyst carefully, and deliberately Correct the record; do not retro-judge the person. A verdict is judged against the evidence available at the time, and analysts working a queue against a clock will always have less than a full investigation does. The reason this is a professional obligation rather than a kindness is behavioural: teams where a reclassification becomes a performance finding stop closing cases decisively, and the backlog — where genuinely uncounted misses accumulate — grows instead. What is legitimate is asking what would have had to be on screen for the verdict to differ, and whether that is buildable. ## Feeding the miss count Record this as one known miss with its discovery channel: the back-timeline of a later investigation. That label is not bureaucracy — it is the only thing that lets you read the count later. A back-timeline discovery is conditional on your having eventually caught something else, which means the channel is structurally blind to intrusions that never escalated into anything you detected. One find through this channel implies nothing about how many similar cases sit in the closed-case archive with the same wrong verdict. That implication does suggest one concrete follow-up: a targeted review of historically closed cases matching the same rule, actor pattern or closure reason. It is a bounded, cheap sweep and it is the only way to convert a single retro-read into more than one observation.
- The raw logs behind that old alert have aged out of retention. What can you still assert?The case record usually outlives the events: the fields that matched, the analyst note, the enrichment and any attached artefacts. From those you can date the activity and describe what fired, but you cannot re-adjudicate it or pivot on fields nobody preserved. State what the surviving record supports, label the rest unverified, and record that the limit was retention rather than coverage.
- Should the analyst who closed the case be named in the correction?Correct the disposition, because counts depend on it; do not turn it into a performance finding. Judge the verdict against the evidence that was on screen under queue pressure, and ask instead what would have had to be visible for the answer to differ. Teams that punish reclassification get analysts who stop closing anything, which moves the misses into the backlog where nobody counts them.
- What cheap follow-up does this single find justify?A bounded review of historically closed cases sharing the same rule, actor pattern or closure reason — for example everything closed on a user's self-report alone. One retro-read is a single observation of an unknown population; a targeted sweep of the closed-case archive is the only way to turn it into several, and it costs analyst hours rather than new tooling.
saying these in an interview costs you the question
- Fixes the metric before preserving the older evidence
- Assumes raw logs from nine months ago still exist
- Records it as a detection gap although the rule fired
- Blames the analyst for evidence they never had
- Leaves the original case closed as a false positive