A false negative occurs when a control, detection rule, model, or analyst concludes that malicious or policy-violating activity is benign or absent. Causes include coverage gaps, evasion, stale signatures, mis-scoped rules, encrypted traffic, log loss, and thresholds tuned to reduce noise.
Key points
Miss-rate estimationUse purple-team testing, breach and attack simulation, retrospective hunts, and incident review to estimate miss rates that dashboards do not show.
Deliberate tuningEvery threshold change trades false positives for false negatives; record who accepted that trade and why.
Important limitationAbsence of alerts is not evidence of absence. Detection coverage can be estimated and tested but never proven complete.