Detection names should describe behaviour, not certainty

Naming a rule "Ransomware detected" promises something it cannot deliver.

It saw a behaviour consistent with ransomware, which is a different claim, and the overstated name shapes how the analyst approaches it before they have looked. A name describing what was observed, such as "many files renamed rapidly by one process", tells the responder what to check and does not prejudge the answer.

More on Detection engineering