Bias Analysis
Detected Bias Types
windows_first
windows_tools
missing_linux_example
powershell_heavy
Summary
The documentation page exhibits a notable Windows bias. Many anomaly detections and examples reference Windows-specific data sources (e.g., Windows Security logs, Event IDs 4624/4625, PowerShell), with no equivalent coverage or examples for Linux or macOS systems. Anomaly types such as brute force detection, local account creation, and login volume are exclusively described in the context of Windows logs and events. There is no mention of Linux audit logs, syslog, or macOS security events, nor are Linux command interpreters (e.g., Bash, Python) referenced in code execution anomalies. This creates friction for users monitoring non-Windows endpoints.
Recommendations
- Add equivalent anomaly detection descriptions and examples for Linux and macOS endpoints, referencing syslog, auditd, or other relevant logs.
- Include Linux/macOS event IDs or log patterns for brute force, account creation, and login anomalies.
- Expand 'Anomalous Code Execution' to mention Linux/macOS interpreters (e.g., Bash, Python, Perl) and their detection.
- Provide parity in documentation structure, listing Linux/macOS sources and detection rules alongside Windows.
- Where PowerShell is referenced, also mention Bash or other Linux shells.
- Clarify which anomaly detections are Windows-only and which are cross-platform.
Create Pull Request