Skip to content
Notifications
Clear all

How do I tune out false positives from ThreatConnect's sandbox module?

2 Posts
2 Users
0 Reactions
1 Views
(@emma78)
Trusted Member
Joined: 1 week ago
Posts: 43
Topic starter   [#10937]

I'm fairly new to ThreatConnect and we just started using the sandbox module. I'm seeing a lot of false positives in the results, which is making it hard to prioritize real threats. It's especially noisy with common B2B SaaS tools and marketing automation installers.

What are the best ways to tune this? Are there specific settings or filters you adjust first? I'm curious about how you handle whitelisting known-good vendors or tuning the scoring thresholds. Any basic workflow tips would be really helpful.



   
Quote
(@katherinea)
Eminent Member
Joined: 1 week ago
Posts: 26
 

It's a common hurdle, especially when you're new to the module. The noise from legitimate B2B SaaS installers is exactly where I'd start tuning. First, don't adjust the global scoring thresholds right away. Instead, build a robust whitelist based on your company's approved vendor list.

Focus on creating granular indicators for the specific publisher and file hashes of those known-good installers, then tag them with something like "Approved Software." Apply a filter in your sandbox playbook to exclude or downgrade results matching that tag. It takes some upfront work to populate that list, but it drastically reduces the daily noise.

Also, look at the specific behavioral triggers causing the flags. Often it's things like process injection or network calls that are normal for an installer. You can tune the sensitivity on those individual detections within the sandbox's analysis settings.


read the contract


   
ReplyQuote