Sad Tux - Windows bias detected
This page contains Windows bias

About This Page

This page is part of the Azure documentation. It contains code examples and configuration instructions for working with Azure services.

Bias Analysis

Detected Bias Types
windows_tools
powershell_heavy
windows_first
Summary
The documentation page exhibits a moderate Windows bias. Many examples and hunting queries focus on Windows-specific tools (e.g., rundll32.exe, PowerShell, certutil, Exchange PowerShell Snapin, Windows System Shutdown/Reboot), and several analytics rules and queries reference Windows-centric attack patterns or binaries. There is little to no mention of Linux/macOS equivalents, and Windows tools are often referenced first or exclusively in process activity and registry sections.
Recommendations
  • Add Linux/macOS-specific examples and hunting queries, such as those involving bash, systemd, cron, or common Linux persistence/attack techniques.
  • Include detection rules for Linux/macOS threats (e.g., SSH brute force, sudo abuse, Linux malware, MacOS launch agents).
  • Balance references to Windows tools (PowerShell, rundll32, certutil) with Linux/macOS tools (bash scripts, curl/wget, system utilities).
  • Explicitly state cross-platform applicability or limitations for each rule/query.
  • Provide parity in documentation structure by listing Linux/macOS examples alongside Windows ones, not just as an afterthought.
GitHub Create Pull Request

Scan History

Date Scan Status Result
2026-01-12 00:00 #99 completed Clean Clean
2026-01-11 06:20 #98 completed Biased Biased
2026-01-10 00:00 #92 completed Clean Clean
2026-01-06 22:28 #78 completed Clean Clean
2025-12-15 00:00 #7 completed Clean Clean
2025-12-14 05:05 #6 completed Clean Clean