Signal and noise
When malicious activity is a tiny fraction of all activity, even a very accurate detection produces mostly false alarms.
This is arithmetic rather than a failing of the tool, and it surprises people every time. A test that is 99% accurate, looking at a million events of which ten are malicious, will still bury those ten in thousands of false positives. It is why "we have a detection for that" is not the end of the conversation, and why the volume of events matters as much as the quality of the rule.
Checked against the primary source.
