Bias Analysis
Detected Bias Types
windows_tools
powershell_heavy
windows_first
Summary
The documentation page exhibits a moderate Windows bias. Many examples and hunting queries focus on Windows-specific tools (e.g., rundll32.exe, PowerShell, certutil, Exchange PowerShell Snapin, Windows System Shutdown/Reboot), and several analytics rules and queries reference Windows-centric attack patterns or binaries. There is little to no mention of Linux/macOS equivalents, and Windows tools are often referenced first or exclusively in process activity and registry sections.
Recommendations
- Add Linux/macOS-specific examples and hunting queries, such as those involving bash, systemd, cron, or common Linux persistence/attack techniques.
- Include detection rules for Linux/macOS threats (e.g., SSH brute force, sudo abuse, Linux malware, MacOS launch agents).
- Balance references to Windows tools (PowerShell, rundll32, certutil) with Linux/macOS tools (bash scripts, curl/wget, system utilities).
- Explicitly state cross-platform applicability or limitations for each rule/query.
- Provide parity in documentation structure by listing Linux/macOS examples alongside Windows ones, not just as an afterthought.
Create Pull Request