Bias Analysis
Detected Bias Types
windows_first
windows_tools
missing_linux_example
powershell_heavy
Summary
The documentation page exhibits a notable Windows bias. Many anomaly detections and machine learning models are described exclusively in terms of Windows Security logs (e.g., event IDs 4624, 4625), with no mention of equivalent Linux/macOS audit logs or syslog formats. PowerShell is referenced as a sub-technique for code execution, but no Bash or Linux shell equivalents are discussed. There are no examples or guidance for Linux/macOS environments, and Windows-specific terminology and tools are used throughout, especially in the machine learning-based anomaly section.
Recommendations
- Add equivalent examples and descriptions for Linux/macOS audit logs (e.g., /var/log/auth.log, /var/log/secure, syslog, auditd) alongside Windows Security logs.
- Include Linux/macOS command and scripting interpreter techniques (e.g., Bash, sh, Python) in the anomaly descriptions, not just PowerShell.
- Reference Linux/macOS authentication events and their identifiers (e.g., PAM, SSH login failures) where login anomalies are discussed.
- Provide parity in anomaly detection coverage for Linux/macOS endpoints, including local account creation, brute force, and privilege escalation.
- Avoid listing Windows tools and event IDs first or exclusively; present cross-platform information in parallel or in separate sections.
Create Pull Request