Skip to main content
Skip to main content
DFIR
back

FPLENS

False Positive Likelihood Analyzer. Paste a detection rule (Sigma, KQL, SPL, XQL, or just an alert name) plus optional sample hits and environment context. The model returns a structured verdict — FP risk level, plausible FP patterns with signals, TP indicators, suggested exclusions, and tuning guidance.

Powered by Workers AI (Llama 3.3 70B) with Groq fallback · request content is not stored

Detection rule / alert

required

Sample hits / additional logs

optional

Environment context

optional

Paste a detection rule and click Analyze

Output: risk verdict, FP patterns, TP signals, exclusions, tuning steps

edge·
github·portfolio