Fortinet black logo

User Guide

Resolving detections

Resolving detections

You can resolve a detection to change its state from Active and remove it from the default view.

FortiGuard Labs curates detection rule logic over time. When the resolution ratio shows a high rate of False Positives, FortiGuard Labs will take steps to determine what changes are necessary in order to increase rule performance.

Tooltip

Detection resolutions are your direct feedback line to FortiGuard Labs. We recommend resolving detections to improve the quality of the rules you see.

To resolve a detection:
  1. Click the Detections tab and open a rule in the list.
  2. In the Impacted Devices tab, select the detection you want to resolve.
  3. Click the Actions menu at the right side of the page and select Resolve Detection. The Resolve <IP address> dialog opens.
  4. From the Resolution drop down, select one of the following options.
    Resolution StateDescriptionExample
    True Positive: MitigatedThe threat was investigated and resolved, contained, or removed.Malware was discovered on a host.
    True Positive: No ActionThe threat has been acknowledged, however no action was taken to resolve it.An analyst ran a post-exploit tool for testing purposes.
    False PositiveThe matched events don't represent the reported activity.A signature for malware C2 instead flagged web browser traffic to a common site.
    UnknownThe status or veracity of the detection is unknown.You have no idea what you're even looking at, nor what to do with it.
  5. (Optional) In the Comments field, enter brief description of the resolution.

  6. Click Resolve detection.

  7. (Optional) To unresolve a detection, select Unresolve Detection from the action menu.

Note

Resolving a detection does not delete the detection, it is simply removes it from the default view. Detections remain in your account in perpetuity and can be viewed or pulled via the API at any time.

To view resolved deflections, click the Filter button in the Impacted Devices tab on the Rule page and select Resolved Detections.

To bulk resolve detections:
  1. Click the Detections tab and open a rule in the list.
  2. In the Impacted Devices tab, click the select all box in the first column of the table. The Bulk Resolve icon is displayed.
  3. Click Bulk Resolve Detections.

  4. In the Impacted Devices tab, click Bulk Resolve Detections. the Resolve X Detections dialog opens.
  5. From the Resolution drop down, select one of the following options.
    Resolution StateDescriptionExample
    True Positive: MitigatedThe threat was investigated and resolved, contained, or removed.Malware was discovered on a host.
    True Positive: No ActionThe threat has been acknowledged, however no action was taken to resolve it.An analyst ran a post-exploit tool for testing purposes.
    False PositiveThe matched events don't represent the reported activity.A signature for malware C2 instead flagged web browser traffic to a common site.
    UnknownThe status or veracity of the detection is unknown.You have no idea what you're even looking at, nor what to do with it.
  6. (Optional) In the Comments field, enter brief description of the resolution.

  7. Click Resolve detections.

Resolving detections

You can resolve a detection to change its state from Active and remove it from the default view.

FortiGuard Labs curates detection rule logic over time. When the resolution ratio shows a high rate of False Positives, FortiGuard Labs will take steps to determine what changes are necessary in order to increase rule performance.

Tooltip

Detection resolutions are your direct feedback line to FortiGuard Labs. We recommend resolving detections to improve the quality of the rules you see.

To resolve a detection:
  1. Click the Detections tab and open a rule in the list.
  2. In the Impacted Devices tab, select the detection you want to resolve.
  3. Click the Actions menu at the right side of the page and select Resolve Detection. The Resolve <IP address> dialog opens.
  4. From the Resolution drop down, select one of the following options.
    Resolution StateDescriptionExample
    True Positive: MitigatedThe threat was investigated and resolved, contained, or removed.Malware was discovered on a host.
    True Positive: No ActionThe threat has been acknowledged, however no action was taken to resolve it.An analyst ran a post-exploit tool for testing purposes.
    False PositiveThe matched events don't represent the reported activity.A signature for malware C2 instead flagged web browser traffic to a common site.
    UnknownThe status or veracity of the detection is unknown.You have no idea what you're even looking at, nor what to do with it.
  5. (Optional) In the Comments field, enter brief description of the resolution.

  6. Click Resolve detection.

  7. (Optional) To unresolve a detection, select Unresolve Detection from the action menu.

Note

Resolving a detection does not delete the detection, it is simply removes it from the default view. Detections remain in your account in perpetuity and can be viewed or pulled via the API at any time.

To view resolved deflections, click the Filter button in the Impacted Devices tab on the Rule page and select Resolved Detections.

To bulk resolve detections:
  1. Click the Detections tab and open a rule in the list.
  2. In the Impacted Devices tab, click the select all box in the first column of the table. The Bulk Resolve icon is displayed.
  3. Click Bulk Resolve Detections.

  4. In the Impacted Devices tab, click Bulk Resolve Detections. the Resolve X Detections dialog opens.
  5. From the Resolution drop down, select one of the following options.
    Resolution StateDescriptionExample
    True Positive: MitigatedThe threat was investigated and resolved, contained, or removed.Malware was discovered on a host.
    True Positive: No ActionThe threat has been acknowledged, however no action was taken to resolve it.An analyst ran a post-exploit tool for testing purposes.
    False PositiveThe matched events don't represent the reported activity.A signature for malware C2 instead flagged web browser traffic to a common site.
    UnknownThe status or veracity of the detection is unknown.You have no idea what you're even looking at, nor what to do with it.
  6. (Optional) In the Comments field, enter brief description of the resolution.

  7. Click Resolve detections.