Sad Tux - Windows bias detected
This page contains Windows bias

About This Page

This page is part of the Azure documentation. It contains code examples and configuration instructions for working with Azure services.

Bias Analysis

Detected Bias Types
windows_tools
windows_first
missing_linux_example
Summary
The documentation demonstrates a moderate Windows bias, primarily in the data sources and enrichment fields. Windows-specific event sources (e.g., Windows Security Events, Windows Forwarded Events) are listed explicitly, and device-related enrichments focus on Windows as the primary operating system and device family. There is little mention of Linux or macOS equivalents, and no examples or guidance are provided for non-Windows endpoints or logs. This may create friction for organizations with heterogeneous environments, as Linux/macOS users may not see their platforms represented or supported in the same detail.
Recommendations
  • Add explicit references to Linux/macOS log sources and connectors (e.g., Syslog, Linux audit logs) in the data sources table.
  • Include enrichment examples and schema fields for Linux/macOS devices (e.g., device family: Linux, macOS; operating system: Ubuntu, Red Hat, macOS Ventura, etc.).
  • Clarify whether UEBA supports non-Windows endpoints and how to onboard them, including any limitations or required connectors.
  • Provide parity in documentation for Linux/macOS event types, device attributes, and investigation workflows.
  • If Linux/macOS support is limited, state this clearly and provide guidance for mixed environments.
GitHub Create Pull Request

Scan History

Date Scan Status Result
2026-01-13 06:17 #107 completed Biased Biased
2026-01-12 00:00 #99 completed Biased Biased
2026-01-11 06:20 #98 completed Biased Biased
2026-01-10 00:00 #92 completed Clean Clean
2026-01-06 22:28 #78 completed Clean Clean
2025-12-15 00:00 #7 completed Clean Clean
2025-12-14 05:05 #6 completed Clean Clean