Reporting a False Positive

If you suspect that a threat indicator in the Threat Intelligence database is a false positive, create a support request and explain the reasoning.

Threat Intelligence investigates the request. If the findings are conclusive, Threat Intelligence adjusts the confidence level or removes the threat indicator from the result set.

  1. From the details page of the threat indicator that you searched for, select Report false positive.
  2. Select Create Support Request.
  3. Include the following information in the request:
    • Tenancy OCID.

      To find the tenancy's OCID, select the Profile icon in the Console header, and then select Tenancy: <your_tenancy_name>.

    • Indicator OCID.

      You can find the OCID for the threat indicator on the indicator details page.

    • Summary of the data quality concern.

Was this article helpful?