Bias Analysis
Detected Bias Types
Summary
The documentation is largely platform-neutral, focusing on network alerts and OT protocols. However, there are a few alert types and malware references that are specific to Windows environments, such as 'Unauthorized Windows Process', 'Unauthorized Windows Service', and alerts referencing Windows malware (e.g., WannaCry, NotPetya, DoublePulsar, Conficker, Stuxnet, PsExec). These references indicate some Windows bias in terms of threat coverage and terminology, but do not impact the usability of the documentation for Linux/macOS users.
Recommendations
- Where Windows-specific alerts or malware are mentioned, consider adding equivalent examples or references for Linux/macOS threats (e.g., Linux-targeted malware, unauthorized Linux processes/services).
- Clarify that the detection covers cross-platform threats and, where possible, expand coverage to include non-Windows-specific attack vectors.
- If alert types are OS-specific, explicitly state their applicability and provide parity for Linux/macOS where relevant.
Create Pull Request