Bias Analysis
Detected Bias Types
windows_first
windows_tools
missing_linux_example
powershell_heavy
Summary
The documentation page exhibits a notable Windows bias. Many anomaly detection rules and examples reference Windows-specific data sources (such as Windows Security logs and event IDs), and PowerShell is explicitly mentioned as a sub-technique. There is a lack of parity for Linux/macOS: no equivalent examples, log sources, or event IDs are provided for non-Windows platforms. The documentation does not mention Linux audit logs, syslog, or macOS equivalents, nor does it provide guidance for anomaly detection on those platforms.
Recommendations
- Add equivalent anomaly detection examples for Linux (e.g., using auditd, syslog, journald) and macOS (e.g., Unified Logs, Apple System Logger).
- Reference Linux/macOS event types and IDs where applicable, such as login failures, account creation, and code execution.
- Include Linux/macOS-specific MITRE ATT&CK sub-techniques (e.g., Bash, Zsh, Python) alongside PowerShell.
- Document how to onboard Linux/macOS logs into Sentinel for anomaly detection.
- Provide sample queries or detection rules for Linux/macOS environments.
- Avoid listing Windows examples first or exclusively when describing cross-platform features.
Create Pull Request