pith. sign in

99% false positives: A qualitative study of SOC analysts’ perspectives on security alarms

1 Pith paper cite this work. Polarity classification is still indexing.

1 Pith paper citing it

fields

cs.CR 1

years

2026 1

verdicts

UNVERDICTED 1

representative citing papers

Evolution of Log-Based Detection Rules in Public Repositories

cs.CR · 2026-05-06 · unverdicted · novelty 6.0

Analysis of 6,859 rule histories shows 56% undergo detection logic revisions, with over half both adding and removing clauses and a quarter to a third alternating between coverage expansion and false-positive reduction.

citing papers explorer

Showing 1 of 1 citing paper.

  • Evolution of Log-Based Detection Rules in Public Repositories cs.CR · 2026-05-06 · unverdicted · none · ref 1

    Analysis of 6,859 rule histories shows 56% undergo detection logic revisions, with over half both adding and removing clauses and a quarter to a third alternating between coverage expansion and false-positive reduction.