Bias Analysis
Detected Bias Types
windows_first
windows_tools
missing_linux_example
Summary
The documentation provides a Windows-specific example (with a Windows file path and SYSTEM user) before any Linux example, and does not offer equivalent Linux/macOS examples for process identity rules. Windows tools and patterns (e.g., C:\Windows\OEM\Unattend.wsf.exe, SYSTEM user) are mentioned exclusively in the WireServer schema example, while Linux process identity examples are limited to generic paths and group names. No explicit Linux/macOS-specific guidance or parity is provided for configuring RBAC rules based on Linux process metadata.
Recommendations
- Add Linux/macOS-specific examples for process identity rules, such as using /usr/bin/nginx, user 'root', or group 'www-data'.
- Provide parallel examples for both Windows and Linux in all schema expansions, especially for WireServer.
- Explicitly mention how Linux/macOS users can determine process names, executable paths, and user/group names for rule authoring.
- Avoid presenting Windows examples first or exclusively; alternate or combine with Linux/macOS examples.
- Clarify any platform-specific differences in process metadata handling.
Create Pull Request