Earlier quoted context omitted.
> They were not legitimate software from trusted sources. Infected email attachments, unless they come from a trusted sender, I consider "useless positives" because nobody, with the appropriate training, should be opening them in the first place. Kinda along the same lines of tracking portscans and counting those as "thwarted cyber attacks", like many government agencies tend to boast about, it's nice for padding sta…
> nobody, with the appropriate training, should be opening them in the first place How many users do you administer again?
But yeah, reality is different ...