The majority of AROs are automatically released as soon as Field Effect MDR detects something suspicious, malicious, or otherwise warranting the release of an ARO. These scenarios are representative of high-priority priority alerts, (ex: malware) where the probability of it being a false positive are low.
AROs that pose a risk of being a false positive are flagged and reviewed internally before an ARO is generated. As all events are different, normal activity for one account or organization might be considered anomalous for another. And as such, the time it takes to review these AROs will vary case by case.
With this in mind, we release AROs that we believe should be brought to your attention and provide you with the background and required steps to address underlying issue. If you have any examples of specific AROs that you are seeing consistently being false positives, please use the Difficulty with option to flag them to our team who will then adapt to your needs.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article