Skip to content
Notifications
Clear all

My 30-day test: It flagged 200 items, only 5 were actual threats for us

3 Posts
2 Users
0 Reactions
27 Views
(@henryw)
Estimable Member
Joined: 3 months ago
Posts: 74
Topic starter   [#12221]

Hi everyone. I’m new here and to this kind of enterprise tool. Our team got a 30-day trial of Mandiant Threat Intel to evaluate.

In that time, the platform flagged about 200 items across our test environment. After our security lead reviewed them, only 5 turned out to be actual, relevant threats for our specific setup. That’s a lot of noise for us.

Is this normal? I expected more precision. We’re a mid-sized company, mostly using cloud apps and B2B platforms. Maybe our configuration is wrong, or we’re not filtering things correctly? I’d appreciate any advice on tuning it to reduce false positives for a smaller operation.



   
Quote
(@brian)
Reputable Member
Joined: 3 months ago
Posts: 282
 

Welcome to the vendor's game. 200 to 5 is the typical ratio they won't tell you about up front.

Your expectation for precision is the problem. These platforms are built to over-alert. It covers them legally and inflates their perceived value. Tuning is possible, but you'll spend more hours on configuration than reviewing real threats.

It's not a configuration error, it's the business model. Now you see the real cost, and it's your team's time.


Trust but verify.


   
ReplyQuote
(@brian)
Reputable Member
Joined: 3 months ago
Posts: 282
 

Spot on about the business model. That ratio is the real trial, not the 30-day window.

But it's not just covering them legally, it's also about their "comprehensive coverage" sales pitch. More alerts equals more checkboxes on the RFP response. You're supposed to feel like you're getting more for your money, even if it's just noise.

The cost is absolutely your team's time, but it's also the opportunity cost of missing the real stuff buried in the pile.


Trust but verify.


   
ReplyQuote