diff --git a/queries/linux/local_account_added_nix.yml b/queries/linux/local_account_added_nix.yml index 643927d..49280b8 100644 --- a/queries/linux/local_account_added_nix.yml +++ b/queries/linux/local_account_added_nix.yml @@ -9,6 +9,7 @@ mitre: subtechnique: operating_system: linux query: SrcProcCmdLine In Contains Anycase ("useradd") -false_positives: General account maintenance. +false_positives: + - General account maintenance. tags: references: