If you're willing to share more details about your site such as your tech stack, we can probably give you more specific advice beyond "check your logs for weirdness and hire a consultancy firm that deals with breach detection," though that is good advice.
For what it's worth I went through something similar to this not too long ago, so I know how maddening it is. My client never found any breach (though I did find some PHP library CVE's that could have conceivably been chained together to wreak some havoc), but I ended up rebuilding their prod environment clean and the flag went away on it's own after a couple days, probably because whatever malware was in there had disappeared.