← CYBERNETICSINTERN.COMCYBERNETIC INTERN
Detection EngineeringFOUNDATION

Close reasons are your only feedback

Alert volume tells you a rule is loud. Structured close reasons tell you why, and they are written by the people using it.

A rule fires. An analyst looks, decides it is benign, closes it. Then what?

In most teams, nothing. The alert closes into a status field offering “resolved” and not much else, the reasoning goes into a free-text note nobody aggregates, and the rule keeps firing. The next analyst repeats the work from scratch.

Close reasons are the only structured signal that travels back from the people using a detection to the people writing it. Without them you can measure how many alerts a rule produced, which tells you about volume and nothing about quality. With them you can see that eighty percent of a rule’s alerts close as expected administrative activity, which is a tuning instruction written by your own SOC.

Keep the list short and make the options mutually exclusive. True positive. Benign expected. Benign unexpected. Not enough information to decide. Duplicate of an existing case. Five options a tired analyst picks correctly at three in the morning beat twenty that get picked at random.

The fourth one earns its place. “Not enough information” is not the analyst failing, it is the alert failing, and a rule that collects those repeatedly needs more fields rather than more attention.

Take your noisiest rule and read the last twenty close notes. If you cannot tell why those alerts were closed, that is the finding.

CHECK YOURSELF

One rule accounts for 30 percent of your alert volume, and 90 percent of its alerts close with the reason 'benign expected activity'. What does that most directly tell you?

SHOW THE ANSWER

The rule's scope includes behaviour that is routine in your environment

Why. Close reasons turn raw volume into a diagnosis. Volume alone could only have told you the rule is loud; ninety percent closing the same way is your SOC telling you, in structured form, exactly which kind of loud. Note that a rule can be perfectly accurate at matching what it was written to match and still be wrong here, because the behaviour is normal in this environment. That is a scoping finding, not an accuracy one.

← ALL DETECTION ENGINEERING