Signal Confidence Levels

The Confidence Score is a dynamic metric assigned to each signal generated by detection workbooks. This score helps analysts assess the reliability of a signal at a glance and prioritize investigations more effectively.

  • The confidence score ranges from 1 (lowest) to 5 (highest).
  • The initial confidence score is set to 5 when a signal is first raised from a workbook.
  • The score is automatically updated based on analyst feedback and triage actions.

How the Score Updates

False Positive Tagging
  • When a signal is marked as a false positive, the associated confidence score gradually decreases over time.
  • This helps prevent the system from assigning high confidence to signals that are consistently identified as incorrect.

False Positive Tag Removed
  • If the false positive tag is later removed on further investigation , the confidence score will gradually increase, trending back toward the original score.

Example: If the score dropped from 5 to 4.8 because of a false positive tag, and the tag is later removed, the score will slowly go back up, depending on how many false positives were untagged.

Note: The confidence score is rounded off to 1 decimal place and hence initially, unless 3-4 signals are tagged as “false positive”, the score will not reflect a value < 5 on the signals listing page

The following screen helps you to view the confidence level of a raised signal: