Bias Analysis
Detected Bias Types
powershell_heavy
windows_first
windows_tools
missing_linux_example
Summary
The documentation page exhibits a notable Windows bias. Windows-specific tools (PowerShell, .exe utilities) are featured prominently and in greater detail than Linux equivalents. Windows examples and terminology (e.g., PowerShell commands, .exe files, Windows paths) are presented first and in more depth, while Linux instructions are less detailed or absent (e.g., no Bash or shell scripting examples for Linux users, no mention of Linux-native automation tools). The allowlist generator tool is only available as a Windows executable, with no Linux alternative provided. Sample identities and rules are overwhelmingly Windows-centric, with little coverage of Linux processes or users.
Recommendations
- Provide Linux-native examples for all major steps, including shell (Bash) or Python scripts for resource creation and management.
- Offer a cross-platform or Linux-compatible version of the allowlist generator tool, or document manual log parsing methods for Linux.
- Balance sample identities and rules to include Linux processes and users, not just Windows executables.
- Present CLI and ARM template methods before or alongside PowerShell, emphasizing cross-platform parity.
- Explicitly note any limitations or workarounds for Linux users where Windows-only tooling is referenced.
Create Pull Request