Alert tuning is the appropriate response when a security notification is inaccurate. Detection technologies depend on rules, thresholds, signatures, behavioral models, correlation conditions, exclusions, and environmental context. When these settings are too broad or poorly calibrated, the result may be false positives, unnecessary notifications, or detections that do not accurately represent the underlying activity.
Tuning involves examining the detection that generated the notification and modifying its logic so it more accurately distinguishes malicious activity from legitimate behavior. This can include adjusting thresholds, excluding known-benign entities, refining queries, changing correlation windows, or adding contextual conditions. Microsoft Sentinel specifically recommends modifying analytics rules or creating appropriate exceptions to manage false positives, and its current guidance identifies tuning as a method of reducing noise and improving detection quality.
Data enrichment adds additional context but does not inherently correct an inaccurate detection. Dashboard creation changes visualization rather than detection logic. Threat hunting is a proactive investigative activity used to search for threats that may not have generated alerts; it is not the primary technique for correcting inaccurate notifications.
Study Guide Reference: Security Operations → Security Monitoring → Detection Engineering → Rule/Alert Tuning → False Positives and False Negatives → Detection Optimization.