Signal and noise

When malicious activity is a tiny fraction of all activity, even a very accurate detection produces mostly false alarms.

This is arithmetic rather than a failing of the tool, and it surprises people every time. A test that is 99% accurate, looking at a million events of which ten are malicious, will still bury those ten in thousands of false positives. It is why "we have a detection for that" is not the end of the conversation, and why the volume of events matters as much as the quality of the rule.

Checked against the primary source.

More on Detection & SOC