1. Knowledge Base
  2. Utilizing Unified VRM

Mark False Positive on Vulnerability

In UVRM, you can mark False Positive on a vulnerability instance or on a vulnerability on all assets that it was detected. 

In order to mark False Positive on a single vulnerability instance:

       1) Go to 'Infrastructure Vulns' page and select a vulnerability instance. The View By dropdown menu should show 'Vuln Instance'.

       2) Select the vulnerability instance by clicking the check box in the far left column. You should see 1 vuln instance selected showing above the vulnerability table. 

      3) Click 'Mark False Positive'. 

fp_vuln_instance.png

 

In order to mark False Positive on a vulnerability across all assets it was detected:

       1) Go to 'Infrastructure Vulns' page and select a vulnerability. The View By dropdown menu should show 'Vulnerability'.

       2) Select the vulnerability by clicking the check box in the far left column. You should see the total number of vuln instances selected showing above the vulnerability table.  

      3) Click 'Mark False Positive'. 

fp_vulnerability.png

 

NOTE: The false positive classification occurs on the vulnerability instance level. If a new asset is discovered from the scan that has the same (previously marked false positive) vulnerability detected on it, then you will have to mark the CVE on this new asset as false positive.