True positives are the alerts that matter. Increasing the ratio of true positives to false positives is a core goal for security operations, as it ensures analyst time is focused on real threats. A high true positive rate requires both accurate detection logic and the ability to filter out noise before it reaches analysts.