Sad Tux - Windows bias detected
This page contains Windows bias

About This Page

This page is part of the Azure documentation. It contains code examples and configuration instructions for working with Azure services.

Bias Analysis

Detected Bias Types
windows_first
windows_tools
missing_linux_example
powershell_heavy
Summary
The documentation page exhibits a notable Windows bias. Many anomaly detections and examples reference Windows-specific data sources (e.g., Windows Security logs, Event IDs 4624/4625, PowerShell), with no equivalent coverage or examples for Linux or macOS systems. Anomaly types such as brute force detection, local account creation, and login volume are exclusively described in the context of Windows logs and events. There is no mention of Linux audit logs, syslog, or macOS security events, nor are Linux command interpreters (e.g., Bash, Python) referenced in code execution anomalies. This creates friction for users monitoring non-Windows endpoints.
Recommendations
  • Add equivalent anomaly detection descriptions and examples for Linux and macOS endpoints, referencing syslog, auditd, or other relevant logs.
  • Include Linux/macOS event IDs or log patterns for brute force, account creation, and login anomalies.
  • Expand 'Anomalous Code Execution' to mention Linux/macOS interpreters (e.g., Bash, Python, Perl) and their detection.
  • Provide parity in documentation structure, listing Linux/macOS sources and detection rules alongside Windows.
  • Where PowerShell is referenced, also mention Bash or other Linux shells.
  • Clarify which anomaly detections are Windows-only and which are cross-platform.
GitHub Create Pull Request

Scan History

Date Scan Status Result
2026-01-13 06:17 #107 completed Biased Biased
2026-01-12 00:00 #99 completed Biased Biased
2026-01-11 06:20 #98 completed Biased Biased
2026-01-10 00:00 #92 completed Clean Clean
2026-01-06 22:28 #78 completed Clean Clean
2025-12-15 00:00 #7 completed Clean Clean
2025-12-14 05:05 #6 completed Clean Clean