# How to Triage Findings in MobileAudit: Mark False Positives and Adjust Severity Levels

> Learn to triage findings in MobileAudit by marking false positives and adjusting severity levels. Use the web interface or Django ORM for efficient management.

- Repository: [Mónica Pastor/mobileaudit](https://github.com/mpast/mobileaudit)
- Tags: how-to-guide
- Published: 2026-03-07

---

**You triage findings in MobileAudit by updating the `status` and `severity` enumerated fields on the `Finding` model, either through the web interface's bulk-edit form or programmatically via Django ORM calls.**

MobileAudit stores every security detection as a `Finding` record that includes dedicated triage fields. Understanding how to manipulate these fields allows security teams to filter false positives and prioritize real vulnerabilities during the findings triage workflow.

## Understanding the Finding Data Model

The triage system relies on two enumeration classes defined in [`app/models.py`](https://github.com/mpast/mobileaudit/blob/main/app/models.py).

### Severity Levels

The `Severity` enum defines five risk levels at lines 30–36:

- **CR** – Critical
- **HI** – High  
- **ME** – Medium
- **LO** – Low
- **NO** – None

These values drive the severity dropdown in the UI and the `severity` field on each finding.

### Triage Status Values

The `Status` enum defines the investigation state at lines 40–46:

- **VF** – Verified
- **FP** – False Positive
- **TP** – True Positive
- **MI** – Mitigated
- **UK** – Unknown
- **TD** – To Do

Setting a finding to `FP` marks it as a false positive, while `TP` confirms it as a valid vulnerability.

## Web-Based Findings Triage Workflow

The bulk-edit functionality is implemented in the `findings` view ([`app/views.py`](https://github.com/mpast/mobileaudit/blob/main/app/views.py) lines 75–84). When you submit the bulk-edit form, the view iterates over selected findings and applies the posted values:

```python
if (edit):
    if (status):
        f.status = status          # ← updates triage status (e.g., "FP")

    if (severity):
        f.severity = severity      # ← updates risk level (e.g., "HI")

    f.save()

```

The HTML controls reside in [`app/templates/findings.html`](https://github.com/mpast/mobileaudit/blob/main/app/templates/findings.html) (lines 11–21). The template renders two dropdown selectors:

```html
<select name="severity" id="severity">
    <option value="NO">None</option>
    <option value="LO">Low</option>
    <option value="ME">Medium</option>
    <option value="HI">High</option>
    <option value="CR">Critical</option>
</select>

<select name="status" id="status">
    <option value="VF">Verified</option>
    <option value="FP">False Positive</option>
    <option value="TP">True Positive</option>
    <option value="UK">Unknown</option>
    <option value="TD">To Do</option>
</select>

```

### Step-by-Step Triage Process

1. **Open the Findings page** for your scan (`/findings/` endpoint).
2. **Select findings** using the checkboxes in the leftmost column of the table.
3. **Choose a new Severity** from the dropdown (e.g., downgrade from *High* to *Low*).
4. **Choose a new Status** from the dropdown (e.g., mark as *False Positive*).
5. Click **Edit Findings** to submit the bulk-update form.
6. The view updates each selected record and displays a confirmation message.

## Programmatic Findings Triage

For automation or data cleanup, use the Django ORM to update findings directly.

### Update a Single Finding

```python
from app.models import Finding, Severity, Status

f = Finding.objects.get(pk=123)
f.status = Status.FP        # Mark as false positive

f.severity = Severity.LO    # Downgrade to Low

f.save()

```

### Bulk Update by Query

```python

# Mark all Critical findings in scan 42 as False Positives

Finding.objects.filter(scan_id=42, severity=Severity.CR).update(status=Status.FP)

# Downgrade all High severity findings to Medium

Finding.objects.filter(severity=Severity.HI).update(severity=Severity.ME)

```

These operations use the same enumeration values defined in the model, ensuring data consistency with the web interface.

## Key Source Files

- **[`app/models.py`](https://github.com/mpast/mobileaudit/blob/main/app/models.py)** – Defines `Severity`, `Status`, and the `Finding` model fields used for triage (lines 30–46).
- **[`app/views.py`](https://github.com/mpast/mobileaudit/blob/main/app/views.py)** – Processes POST requests from the bulk-edit form; contains the triage update logic (lines 75–84).
- **[`app/templates/findings.html`](https://github.com/mpast/mobileaudit/blob/main/app/templates/findings.html)** – Renders the findings table and bulk-edit UI controls (lines 11–21).
- **[`app/forms.py`](https://github.com/mpast/mobileaudit/blob/main/app/forms.py)** – Supplies `FindingForm` for individual finding edits (optional for non-bulk updates).

## Summary

- MobileAudit uses two enum fields—`severity` (CR/HI/ME/LO/NO) and `status` (VF/FP/TP/UK/TD)—to track triage state.
- The bulk-edit workflow in [`app/views.py`](https://github.com/mpast/mobileaudit/blob/main/app/views.py) applies status and severity changes to multiple findings simultaneously.
- You can mark false positives by setting `status = Status.FP` and adjust risk levels by updating the `severity` field.
- Programmatic triage is supported via standard Django ORM `filter().update()` operations.

## Frequently Asked Questions

### What status code marks a finding as a false positive in MobileAudit?

The `FP` status code represents "False Positive". This value is defined in the `Status` enum in [`app/models.py`](https://github.com/mpast/mobileaudit/blob/main/app/models.py) at line 42. When assigned to a finding's `status` field, the record is filtered out of active vulnerability reports.

### Can I bulk-update severity levels for multiple findings at once?

Yes. In the web interface, select multiple findings using the checkboxes, choose a new severity from the dropdown in [`app/templates/findings.html`](https://github.com/mpast/mobileaudit/blob/main/app/templates/findings.html), and click **Edit Findings**. The `findings` view in [`app/views.py`](https://github.com/mpast/mobileaudit/blob/main/app/views.py) (lines 75–84) iterates through selections and applies the change to all checked records.

### How do I programmatically triage findings using the Django shell?

Import the models and enums, then use ORM queries to update fields. For example: `Finding.objects.filter(scan_id=7).update(status=Status.FP, severity=Severity.LO)`. This executes an efficient SQL UPDATE without loading records into memory.

### What is the difference between "Verified" and "True Positive" statuses?

**Verified** (`VF`) indicates an analyst has reviewed the finding but not yet confirmed it as a genuine vulnerability. **True Positive** (`TP`) explicitly marks the finding as a confirmed, valid security issue. Use `VF` during investigation and `TP` once validation is complete.