Your question is Rare Threat Detection Under Imbalance. Take a moment with it on the right.
Talk me through your thinking if you like. When you're confident, submit your answer and I'll grade it like a real screen (7/10 or better passes).
You are training a classifier for a supervised learning task where the positive class is extremely rare. Most examples are benign, but missing the rare positives is costly, and a naive model can look good while failing on the cases that matter.
How do you handle extreme class imbalance when training models to detect rare security threats?