Bias Analysis
Detected Bias Types
windows_examples
windows_terms
windows_domain_format
Summary
The documentation is largely platform-neutral, focusing on schema definitions and KQL usage. However, there are subtle Windows biases: examples of hostnames use Windows-style names (e.g., 'DESKTOP-1282V4D'), domain formats are described as 'Windows domain\hostname', and username types include 'Windows' as an example. Application paths use Windows-style (e.g., 'C:\Windows\System32\svchost.exe'). No Linux/macOS-specific examples or terminology are provided, and Linux-style hostnames, usernames, or application paths are absent.
Recommendations
- Add Linux/macOS examples alongside Windows ones (e.g., show hostnames like 'ubuntu-server', application paths like '/usr/bin/sshd', and usernames like 'alice').
- Explicitly mention that fields support Linux/macOS formats where relevant (e.g., FQDN, username types, application paths).
- Include Linux/macOS-specific values in enumerated fields (e.g., 'Linux', 'macOS' for ActorUsernameType).
- Clarify that the schema is OS-agnostic and provide guidance for mapping Linux/macOS audit events.
Create Pull Request