How to Triage Findings in MobileAudit: Mark False Positives and Adjust Severity Levels

You triage findings in MobileAudit by updating the status and severity enumerated fields on the Finding model, either through the web interface's bulk-edit form or programmatically via Django ORM calls.

MobileAudit stores every security detection as a Finding record that includes dedicated triage fields. Understanding how to manipulate these fields allows security teams to filter false positives and prioritize real vulnerabilities during the findings triage workflow.

Understanding the Finding Data Model

The triage system relies on two enumeration classes defined in app/models.py.

Severity Levels

The Severity enum defines five risk levels at lines 30–36:

  • CR – Critical
  • HI – High
  • ME – Medium
  • LO – Low
  • NO – None

These values drive the severity dropdown in the UI and the severity field on each finding.

Triage Status Values

The Status enum defines the investigation state at lines 40–46:

  • VF – Verified
  • FP – False Positive
  • TP – True Positive
  • MI – Mitigated
  • UK – Unknown
  • TD – To Do

Setting a finding to FP marks it as a false positive, while TP confirms it as a valid vulnerability.

Web-Based Findings Triage Workflow

The bulk-edit functionality is implemented in the findings view (app/views.py lines 75–84). When you submit the bulk-edit form, the view iterates over selected findings and applies the posted values:

if (edit):
    if (status):
        f.status = status          # ← updates triage status (e.g., "FP")

    if (severity):
        f.severity = severity      # ← updates risk level (e.g., "HI")

    f.save()

The HTML controls reside in app/templates/findings.html (lines 11–21). The template renders two dropdown selectors:

<select name="severity" id="severity">
    <option value="NO">None</option>
    <option value="LO">Low</option>
    <option value="ME">Medium</option>
    <option value="HI">High</option>
    <option value="CR">Critical</option>
</select>

<select name="status" id="status">
    <option value="VF">Verified</option>
    <option value="FP">False Positive</option>
    <option value="TP">True Positive</option>
    <option value="UK">Unknown</option>
    <option value="TD">To Do</option>
</select>

Step-by-Step Triage Process

  1. Open the Findings page for your scan (/findings/ endpoint).
  2. Select findings using the checkboxes in the leftmost column of the table.
  3. Choose a new Severity from the dropdown (e.g., downgrade from High to Low).
  4. Choose a new Status from the dropdown (e.g., mark as False Positive).
  5. Click Edit Findings to submit the bulk-update form.
  6. The view updates each selected record and displays a confirmation message.

Programmatic Findings Triage

For automation or data cleanup, use the Django ORM to update findings directly.

Update a Single Finding

from app.models import Finding, Severity, Status

f = Finding.objects.get(pk=123)
f.status = Status.FP        # Mark as false positive

f.severity = Severity.LO    # Downgrade to Low

f.save()

Bulk Update by Query


# Mark all Critical findings in scan 42 as False Positives

Finding.objects.filter(scan_id=42, severity=Severity.CR).update(status=Status.FP)

# Downgrade all High severity findings to Medium

Finding.objects.filter(severity=Severity.HI).update(severity=Severity.ME)

These operations use the same enumeration values defined in the model, ensuring data consistency with the web interface.

Key Source Files

  • app/models.py – Defines Severity, Status, and the Finding model fields used for triage (lines 30–46).
  • app/views.py – Processes POST requests from the bulk-edit form; contains the triage update logic (lines 75–84).
  • app/templates/findings.html – Renders the findings table and bulk-edit UI controls (lines 11–21).
  • app/forms.py – Supplies FindingForm for individual finding edits (optional for non-bulk updates).

Summary

  • MobileAudit uses two enum fields—severity (CR/HI/ME/LO/NO) and status (VF/FP/TP/UK/TD)—to track triage state.
  • The bulk-edit workflow in app/views.py applies status and severity changes to multiple findings simultaneously.
  • You can mark false positives by setting status = Status.FP and adjust risk levels by updating the severity field.
  • Programmatic triage is supported via standard Django ORM filter().update() operations.

Frequently Asked Questions

What status code marks a finding as a false positive in MobileAudit?

The FP status code represents "False Positive". This value is defined in the Status enum in app/models.py at line 42. When assigned to a finding's status field, the record is filtered out of active vulnerability reports.

Can I bulk-update severity levels for multiple findings at once?

Yes. In the web interface, select multiple findings using the checkboxes, choose a new severity from the dropdown in app/templates/findings.html, and click Edit Findings. The findings view in app/views.py (lines 75–84) iterates through selections and applies the change to all checked records.

How do I programmatically triage findings using the Django shell?

Import the models and enums, then use ORM queries to update fields. For example: Finding.objects.filter(scan_id=7).update(status=Status.FP, severity=Severity.LO). This executes an efficient SQL UPDATE without loading records into memory.

What is the difference between "Verified" and "True Positive" statuses?

Verified (VF) indicates an analyst has reviewed the finding but not yet confirmed it as a genuine vulnerability. True Positive (TP) explicitly marks the finding as a confirmed, valid security issue. Use VF during investigation and TP once validation is complete.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →