What should an Incident Responder do to mitigate a false positive?
Add to Whitelist
Run an indicators of compromise (IOC) search
Submit to VirusTotal
Submit to Cynic
Submit