Bias Analysis
Detected Bias Types
powershell_heavy
windows_tools
windows_first
Summary
The documentation page exhibits a moderate Windows bias, primarily through repeated references to Windows-specific tools and technologies such as PowerShell and WMI, and by focusing on Microsoft Defender for Endpoint (which is Windows-centric) for detection scenarios. Examples and threat detections involving PowerShell and WMI are described in detail, while Linux/macOS equivalents (e.g., Bash, SSH, systemd, auditd) are not mentioned. The page also references credential theft tools like Mimikatz, which are primarily Windows-based, and does not discuss Linux/macOS credential theft techniques or detection. The ordering and language throughout the page implicitly prioritize Windows environments and tooling.
Recommendations
- Include detection scenarios and examples relevant to Linux/macOS environments, such as suspicious Bash scripts, SSH key usage, or systemd service manipulation.
- Reference Linux/macOS credential theft tools (e.g., LaZagne, gsecdump) and describe how Fusion detects their execution.
- Add coverage for Linux/macOS remote execution techniques (e.g., SSH, cron jobs, sudo abuse) alongside PowerShell and WMI.
- When describing 'living off the land' attacks, mention Linux/macOS equivalents (e.g., abuse of built-in utilities like curl, wget, netcat, etc.).
- Ensure parity in examples and detection patterns for non-Windows endpoints, including integration with Linux/macOS security logs and tools.
- Explicitly state which scenarios are cross-platform and which are Windows-only, to help users understand coverage gaps.
Create Pull Request