Bias Analysis
Detected Bias Types
windows_first
windows_tools
missing_linux_example
Summary
The documentation provides a Windows-specific example for process identity matching (WinPA) with Windows paths and process names, but does not offer a Linux equivalent. Windows process metadata (exePath, processName, userName) is shown in detail, while Linux examples are limited to a single earlier snippet and not referenced in the main schema expansion. Windows tools and conventions (e.g., C:\Windows paths, SYSTEM user) are mentioned exclusively in the WireServer example, and Windows examples are presented before or instead of Linux ones.
Recommendations
- Add equivalent Linux/macOS examples for process identity matching, such as using /usr/bin/nginx, processName: nginx, userName: root or www-data.
- Ensure schema expansions include both Windows and Linux/macOS scenarios side-by-side.
- Explicitly mention how to obtain process metadata on Linux/macOS (e.g., using ps, /proc, or systemd conventions).
- Avoid using Windows paths and usernames exclusively; provide cross-platform context.
- If Windows-specific tools or patterns are referenced, provide Linux/macOS alternatives.
Create Pull Request