Bias Analysis
Detected Bias Types
windows_first
missing_linux_example
Summary
The documentation page demonstrates a Windows bias by providing a security analytics rule example and query that specifically targets Windows server sign-in failures, with no equivalent example for Linux systems. The only concrete scenario described is for Windows, and there are no Linux-specific queries, event types, or guidance. The documentation does mention 'Operating system' as a field when adding servers, but does not provide any Linux-focused instructions, examples, or queries. This may lead Linux users to feel unsupported or unclear about how to implement similar monitoring for their systems.
Recommendations
- Add equivalent Linux-focused examples, such as a scheduled query rule for failed SSH login attempts or other common Linux authentication events.
- Include sample KQL queries for Linux security events (e.g., parsing Syslog or auditd events) alongside the Windows example.
- Explicitly mention support for Linux VMs in the integration steps, and provide any Linux-specific prerequisites or considerations.
- Wherever possible, present both Windows and Linux examples in parallel to ensure parity and inclusivity.
- Clarify in the 'Create rules to identify security threats' section that similar rules can be created for Linux, and link to relevant documentation or provide sample queries.
Create Pull Request