Bias Analysis
Detected Bias Types
powershell_heavy
windows_tools
windows_first
Summary
The documentation page demonstrates a moderate Windows bias. Several detection scenarios and examples reference Windows-specific tools (such as PowerShell, WMI, and Windows Error Events) and Microsoft Defender for Endpoint, which is primarily a Windows security solution. PowerShell-based attack patterns are highlighted in multiple places, and Windows terminology (e.g., 'Windows Error and Warning Events') is used in example tables. There are no explicit Linux/macOS examples, nor are Linux-specific attack patterns or tools mentioned. The order of presentation and scenario selection tends to favor Windows-centric threats and technologies.
Recommendations
- Add equivalent Linux/macOS detection scenarios, such as suspicious Bash or shell command executions, sudo abuse, or Linux-specific malware.
- Include examples of multistage attacks involving Linux endpoints, such as SSH brute force, rootkit installation, or suspicious cron jobs.
- Reference Linux/macOS security tools and logs (e.g., auditd, syslog, journald) in tables and examples.
- Ensure parity in scenario tables by including Linux/macOS alerts and incident types alongside Windows ones.
- Provide guidance for configuring Fusion to detect threats on non-Windows platforms.
Create Pull Request