Bias Analysis
Detected Bias Types
windows_examples
windows_terms
windows_first
Summary
The documentation is largely platform-neutral, focusing on schema definitions and KQL usage. However, there is a subtle Windows bias: examples of field values (e.g., hostnames like 'DESKTOP-1282V4D', domain formats like 'Contoso\DESKTOP-1282V4D', and application paths like 'C:\Windows\System32\svchost.exe') are Windows-centric. Username types and examples reference 'Windows', and device OS examples use 'Windows 10'. Linux/macOS equivalents are not shown, and Windows formats are mentioned first when describing FQDN/domain formats.
Recommendations
- Add Linux/macOS examples alongside Windows ones for hostnames, domain formats, application paths, and OS fields.
- Clarify that fields such as ActorUsernameType, TargetDvcOs, etc., can represent Linux/macOS values and provide sample values (e.g., '/usr/bin/sshd', 'ubuntu', 'macOS 13').
- When describing formats (e.g., FQDN), mention Linux/macOS conventions and show examples.
- Avoid using only Windows-centric terms (e.g., 'Windows domain\hostname') and instead use cross-platform terminology or provide parity.
Create Pull Request