Bias Analysis
Detected Bias Types
powershell_heavy
windows_tools
windows_first
Summary
The documentation page demonstrates a moderate Windows bias, particularly in the 'Malicious execution with legitimate process' section, which focuses on Windows-specific tools and technologies such as PowerShell and WMI. These attack scenarios are described exclusively in terms of Windows tooling and behaviors, with no mention of Linux/macOS equivalents (e.g., Bash, SSH, systemd, cron, etc.). Additionally, the only credential theft tool mentioned by name is Mimikatz, which is primarily a Windows tool. Throughout the page, examples and scenarios are described using Windows-centric terminology and tools, with little to no reference to Linux/macOS environments or their attack surfaces.
Recommendations
- Add equivalent scenarios and detection descriptions for Linux/macOS environments, such as suspicious Bash or Python command execution, SSH abuse, or use of Linux credential dumping tools (e.g., 'LaZagne', 'gsecdump').
- Where PowerShell or WMI is referenced, include parallel examples for Linux/macOS (e.g., suspicious shell commands, remote execution via SSH, or abuse of system management tools like systemd or cron).
- Mention cross-platform attack frameworks and techniques, and clarify which scenarios apply to non-Windows environments.
- When referencing credential theft tools, include Linux/macOS tools and techniques.
- Ensure that detection logic and data connector sources are described for Linux/macOS endpoints where supported.
Create Pull Request