771
Total Pages
720
Linux-Friendly Pages
51
Pages with Bias
6.6%
Bias Rate

Bias Trend Over Time

Pages with Bias Issues

90 issues found
Showing 1-25 of 90 flagged pages
Sentinel Stream and filter Windows DNS logs with the AMA connector ...re-docs/blob/main/articles/sentinel/connect-dns-ama.md
High Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First Missing Linux Example 🔧 Windows Tools
Summary
The documentation is heavily focused on Windows DNS servers, with all examples, prerequisites, and instructions tailored exclusively to Windows environments. There is no mention of Linux or macOS DNS servers, nor any guidance for users operating non-Windows platforms. The tools and patterns described (such as enabling Windows DNS analytical logs and using the Windows DNS Events via AMA connector) are Windows-specific, and Linux alternatives are absent.
Recommendations
  • Add explicit statements clarifying platform support, including whether Linux/macOS DNS servers are supported or not.
  • If Linux DNS log ingestion is possible (e.g., via AMA or other connectors), provide equivalent setup instructions and examples for Linux-based DNS servers (such as BIND, Unbound, etc.).
  • Include Linux-specific prerequisites, configuration steps, and filtering examples where applicable.
  • If Linux is not supported, clearly state this limitation at the beginning of the documentation to set user expectations.
Sentinel Microsoft Sentinel DNS over AMA connector reference - available fields and normalization schema ...ure-docs/blob/main/articles/sentinel/dns-ama-fields.md
High Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First Missing Linux Example 🔧 Windows Tools
Summary
The documentation is heavily focused on Windows DNS servers and the Windows DNS Events via AMA connector. All examples, field mappings, and instructions are specific to Windows environments, with no mention of Linux or cross-platform DNS log sources. The tools and connectors referenced are Windows-specific, and there is no guidance for Linux users or parity in examples.
Recommendations
  • Include information about collecting and normalizing DNS logs from Linux-based DNS servers (e.g., BIND, Unbound, dnsmasq) using Microsoft Sentinel.
  • Provide equivalent connector or ingestion instructions for Linux environments, or clarify if such support is unavailable.
  • Add normalization schema mappings for common Linux DNS log formats.
  • Explicitly state platform limitations and suggest alternative approaches for non-Windows users.
Sentinel The Advanced Security Information Model (ASIM) Registry Event normalization schema reference | Microsoft Docs ...ticles/sentinel/normalization-schema-registry-event.md
High Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Missing Linux Example
Summary
The documentation is heavily Windows-centric, focusing exclusively on Windows Registry events, terminology, and examples. All field descriptions, examples, and references are specific to Windows (e.g., HKEY_LOCAL_MACHINE, C:\Windows paths, SIDs, Windows process names). There are no Linux or macOS equivalents, nor any mention of how (or if) similar normalization applies to non-Windows platforms. Windows tools and documentation are referenced exclusively, and Linux is only mentioned in passing regarding process IDs.
Recommendations
  • Explicitly state that the schema is Windows-only, or clarify if/how non-Windows platforms are supported.
  • If Linux/macOS registry-like event normalization is possible, provide equivalent examples, field mappings, and references.
  • Add a section comparing Windows registry events to Linux/macOS configuration or system events, if relevant.
  • Where process-related fields are discussed, provide Linux/macOS examples (e.g., /usr/bin/bash, UID/GID formats) alongside Windows ones.
  • Reference Linux/macOS documentation or tools if cross-platform normalization is supported.
Sentinel Stream and filter Windows DNS logs with the AMA connector ...re-docs/blob/main/articles/sentinel/connect-dns-ama.md
High Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First Missing Linux Example 🔧 Windows Tools
Summary
The documentation is exclusively focused on Windows DNS servers, with all instructions, examples, and prerequisites tailored to Windows Server environments. No mention is made of Linux or cross-platform DNS logging, and all tooling and configuration steps are specific to Windows (e.g., Windows DNS Events via AMA, Windows event logs, Windows Server roles). This creates a strong Windows bias, making the documentation irrelevant for Linux/macOS users who wish to stream and filter DNS logs.
Recommendations
  • Explicitly state in the introduction and prerequisites that the connector is Windows-only, and provide guidance or links for Linux-based DNS logging solutions.
  • Add a section comparing Windows and Linux DNS logging approaches, including references to Linux DNS servers (e.g., BIND, Unbound, dnsmasq) and how their logs can be ingested into Microsoft Sentinel.
  • Provide examples or alternative connectors for ingesting Linux DNS logs, or document how to use AMA or other agents to collect DNS logs from Linux servers.
  • If Linux support is planned, include a roadmap or note about future parity.
  • Ensure that related content and normalization schema documentation mention Linux DNS sources and how to achieve similar normalization.
Sentinel Microsoft Sentinel DNS over AMA connector reference - available fields and normalization schema ...ure-docs/blob/main/articles/sentinel/dns-ama-fields.md
High Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First Missing Linux Example 🔧 Windows Tools
Summary
The documentation is heavily focused on Windows DNS servers and the Windows DNS Events via AMA connector. All examples, field mappings, and instructions are specific to Windows environments, with no mention of Linux or cross-platform DNS sources. The tools and connectors referenced are Windows-specific, and there is no guidance for Linux or macOS users who may want to ingest or normalize DNS logs from non-Windows sources.
Recommendations
  • Add equivalent instructions and schema mappings for ingesting DNS logs from Linux-based DNS servers (e.g., BIND, Unbound, dnsmasq) using AMA or other connectors.
  • Provide examples and field normalization for Linux DNS log formats.
  • Clarify whether the AMA connector supports Linux DNS sources, and if not, suggest alternative ingestion methods for Linux/macOS users.
  • Include cross-platform guidance in introductory and summary sections to make clear the scope and applicability.
Sentinel Manage custom content with repository connections ...cs/blob/main/articles/sentinel/ci-cd-custom-content.md
Medium Priority View Details →
Scanned: 2026-01-16 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy Windows First Missing Linux Example
Summary
The documentation page for managing custom content with repository connections in Microsoft Sentinel demonstrates a notable Windows/PowerShell bias. Many conversion and export tasks reference PowerShell scripts as the primary or only method, with Linux/macOS alternatives (such as Bash or Azure CLI) either missing or mentioned secondarily. In several content types (e.g., Analytic rules, Automation rules, Playbooks), only PowerShell scripts are linked for conversion/export, and Linux-friendly approaches are not provided. The workflow customization section also refers to PowerShell deployment scripts without mentioning cross-platform alternatives.
Recommendations
  • Provide equivalent Azure CLI or Bash script examples for all tasks currently covered only by PowerShell scripts, especially for conversion and export operations.
  • Explicitly state when PowerShell scripts are cross-platform (PowerShell Core), or provide instructions for running them on Linux/macOS.
  • Where possible, link to or create Linux/macOS-friendly tools for template conversion and deployment.
  • In tables and examples, present Azure CLI or Bash approaches alongside PowerShell, or at least clarify platform compatibility.
  • Clarify if any referenced scripts or tools require Windows-only PowerShell, and suggest alternatives for non-Windows users.
Sentinel Anomalies detected by the Microsoft Sentinel machine learning engine ...ocs/blob/main/articles/sentinel/anomalies-reference.md
Medium Priority View Details →
Scanned: 2026-01-13 06:17
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Missing Linux Example Powershell Heavy
Summary
The documentation page exhibits a notable Windows bias. Many anomaly detection rules and examples reference Windows-specific data sources (such as Windows Security logs and event IDs), and PowerShell is explicitly mentioned as a sub-technique. There is a lack of parity for Linux/macOS: no equivalent examples, log sources, or event IDs are provided for non-Windows platforms. The documentation does not mention Linux audit logs, syslog, or macOS equivalents, nor does it provide guidance for anomaly detection on those platforms.
Recommendations
  • Add equivalent anomaly detection examples for Linux (e.g., using auditd, syslog, journald) and macOS (e.g., Unified Logs, Apple System Logger).
  • Reference Linux/macOS event types and IDs where applicable, such as login failures, account creation, and code execution.
  • Include Linux/macOS-specific MITRE ATT&CK sub-techniques (e.g., Bash, Zsh, Python) alongside PowerShell.
  • Document how to onboard Linux/macOS logs into Sentinel for anomaly detection.
  • Provide sample queries or detection rules for Linux/macOS environments.
  • Avoid listing Windows examples first or exclusively when describing cross-platform features.
Sentinel Stream data from Microsoft Defender XDR to Microsoft Sentinel in the Azure portal ...in/articles/sentinel/connect-microsoft-365-defender.md
Medium Priority View Details →
Scanned: 2026-01-13 06:17
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
🔧 Windows Tools Windows First Missing Linux Example
Summary
The documentation page demonstrates a moderate Windows bias. It references Windows-specific technologies (Active Directory, Defender for Identity sensors, Windows Defender Antivirus) and focuses on integration patterns that are most relevant to Windows environments. There are no explicit Linux/macOS examples, nor is there guidance for non-Windows endpoints or identity sources. The event tables and configuration steps assume the reader is operating in a Microsoft-centric, Windows-heavy infrastructure, with no mention of Linux/macOS equivalents or how to handle non-Windows data sources.
Recommendations
  • Add guidance for integrating Linux/macOS endpoints with Microsoft Sentinel, including how to stream security events from those platforms.
  • Include examples or references for collecting identity and authentication data from non-Active Directory sources (e.g., LDAP, Azure AD-only, or Linux PAM logs).
  • Clarify whether the connector supports ingestion of security events from Linux/macOS endpoints and, if so, provide configuration steps.
  • If advanced hunting tables or features are Windows-only, explicitly state this and suggest alternative approaches for Linux/macOS data.
  • Provide parity in examples, such as showing KQL queries for Linux event tables if available.
Sentinel This file is auto-generated . Do not edit manually. Changes will be overwritten. ...in/articles/sentinel/includes/deprecated-connectors.md
Medium Priority View Details →
Scanned: 2026-01-13 06:17
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Missing Linux Example
Summary
The documentation page demonstrates a notable Windows bias. Several deprecated connectors and data collection instructions focus on Windows agents, Windows machines, and Windows-specific event types (e.g., SecurityEvent, IIS logs). Windows examples and prerequisites are presented before or instead of Linux equivalents. While there is a section for Syslog (Linux), most other connectors lack explicit Linux instructions or parity, and Windows tooling (agents, event types) is referenced more frequently and prominently.
Recommendations
  • For each connector, explicitly document Linux/macOS support, including prerequisites and installation steps for non-Windows platforms.
  • Where Windows agents or event types are referenced, provide equivalent Linux/macOS agent instructions (e.g., AMA on Linux, syslog, auditd, etc.) and event types.
  • Present Linux/macOS examples and tools alongside or before Windows examples to ensure parity.
  • Clarify which connectors are Windows-only and which support cross-platform ingestion, and provide migration guidance for Linux users where relevant.
  • Add links to Linux/macOS agent installation guides and troubleshooting resources.
Sentinel Microsoft Sentinel User and Entity Behavior Analytics (UEBA) reference ...ure-docs/blob/main/articles/sentinel/ueba-reference.md
Medium Priority View Details →
Scanned: 2026-01-13 06:17
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
🔧 Windows Tools Windows First Missing Linux Example
Summary
The documentation page demonstrates a moderate Windows bias, primarily through its focus on Windows-centric data sources (e.g., Windows Security Events, Windows Forwarded Events, Microsoft Defender XDR, Active Directory) and terminology. Device and OS examples are exclusively Windows (e.g., 'Device family: Windows', 'Operating system: Windows 10'), with no mention of Linux or macOS equivalents in enrichment fields or sample values. There are no examples or guidance for Linux/macOS endpoints, log sources, or device enrichments, and Windows tools and patterns are referenced before any cross-platform or Linux alternatives.
Recommendations
  • Add explicit examples and documentation for Linux and macOS endpoints, including how their logon/authentication events can be ingested and analyzed by UEBA.
  • Include Linux/macOS device families and operating systems in enrichment field sample values and descriptions.
  • Document supported Linux/macOS log sources and connectors (e.g., syslog, auditd, OSQuery) in the data sources table.
  • Clarify whether non-Windows devices are supported for device insights and how their data is mapped.
  • Provide parity in device-related enrichments and sample values for Linux/macOS.
  • If Windows-only, clearly state limitations and recommend alternatives for non-Windows environments.
Sentinel Use matching analytics to detect threats ...s/sentinel/use-matching-analytics-to-detect-threats.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First 🔧 Windows Tools
Summary
The documentation page demonstrates a moderate Windows bias. Windows-specific data sources (Windows DNS, Windows Firewall) are listed before Linux equivalents, and Windows tools are referenced more frequently. While syslog and CEF (cross-platform) are mentioned, Windows-centric solutions and connectors are given prominence, and Linux-specific examples or instructions are missing.
Recommendations
  • Add explicit Linux-focused examples, such as configuring syslog or CEF connectors on popular Linux distributions.
  • Include troubleshooting steps or connector installation guidance for Linux environments.
  • Balance the order of data source listings to avoid putting Windows tools first.
  • Provide screenshots or walkthroughs from Linux-based Sentinel deployments, if applicable.
  • Clarify that syslog and CEF connectors are cross-platform and provide links to Linux documentation.
Sentinel Deploy Microsoft Sentinel solution for SAP BTP .../main/articles/sentinel/sap/deploy-sap-btp-solution.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Missing Linux Example
Summary
The documentation provides a PowerShell-only script for rotating BTP client secrets and references Azure PowerShell modules and tools, with no equivalent Bash, Linux CLI, or cross-platform example. There is a notable reliance on Windows-centric tooling and scripting, and no guidance is given for Linux/macOS users who may need to perform the same tasks.
Recommendations
  • Provide equivalent Bash or Azure CLI scripts for secret rotation and connector updates, ensuring Linux/macOS users can follow along.
  • Explicitly mention cross-platform compatibility for all automation steps, and note any OS-specific requirements or limitations.
  • Reference both PowerShell and Bash/CLI approaches in mass onboarding and automation sections.
  • Add guidance for installing and using Azure CLI on Linux/macOS, and clarify which steps are OS-agnostic.
Sentinel Onboard your Azure Stack Hub virtual machines to Microsoft Sentinel | Microsoft Docs ...ocs/blob/main/articles/sentinel/connect-azure-stack.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First Missing Linux Example
Summary
The documentation page provides links for both Windows and Linux VM creation, but when discussing agent installation and troubleshooting, it references Windows guidance first and only provides a troubleshooting link for Linux, not installation/configuration. There are no Linux-specific examples or step-by-step instructions for installing/configuring the agent, while Windows users are directed to a dedicated installation guide.
Recommendations
  • Add a direct link to the Linux agent installation/configuration documentation, not just troubleshooting.
  • Include step-by-step instructions or examples for Linux agent installation, mirroring the detail provided for Windows.
  • Present Windows and Linux guidance in parallel or in a combined section to avoid Windows-first ordering.
  • Ensure screenshots and UI references are applicable to both Windows and Linux VMs, or clarify differences.
Sentinel Anomalies detected by the Microsoft Sentinel machine learning engine ...ocs/blob/main/articles/sentinel/anomalies-reference.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Missing Linux Example Powershell Heavy
Summary
The documentation page exhibits a notable Windows bias. Many anomaly detections and machine learning models are described exclusively in terms of Windows Security logs (e.g., event IDs 4624, 4625), with no mention of equivalent Linux/macOS audit logs or syslog formats. PowerShell is referenced as a sub-technique for code execution, but no Bash or Linux shell equivalents are discussed. There are no examples or guidance for Linux/macOS environments, and Windows-specific terminology and tools are used throughout, especially in the machine learning-based anomaly section.
Recommendations
  • Add equivalent examples and descriptions for Linux/macOS audit logs (e.g., /var/log/auth.log, /var/log/secure, syslog, auditd) alongside Windows Security logs.
  • Include Linux/macOS command and scripting interpreter techniques (e.g., Bash, sh, Python) in the anomaly descriptions, not just PowerShell.
  • Reference Linux/macOS authentication events and their identifiers (e.g., PAM, SSH login failures) where login anomalies are discussed.
  • Provide parity in anomaly detection coverage for Linux/macOS endpoints, including local account creation, brute force, and privilege escalation.
  • Avoid listing Windows tools and event IDs first or exclusively; present cross-platform information in parallel or in separate sections.
Sentinel Best practices for data collection in Microsoft Sentinel ...ocs/blob/main/articles/sentinel/best-practices-data.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Windows First Powershell Heavy 🔧 Windows Tools Missing Linux Example
Summary
The documentation page demonstrates a moderate Windows bias. Windows-specific tools (e.g., Windows Event Forwarding, PowerShell) are mentioned more frequently, and Windows examples or solutions often appear before Linux equivalents. Some sections, such as endpoint solutions and cloud platform data, reference Windows tools (e.g., Windows Event Forwarding) without providing Linux alternatives or examples. PowerShell is listed as a method for custom log collection, but no Linux shell or scripting alternatives are mentioned. While Linux solutions are present, they are sometimes less detailed or appear after Windows options.
Recommendations
  • Ensure Linux and macOS examples are provided alongside Windows/Powershell examples, especially for custom log collection and endpoint solutions.
  • Mention Linux-native tools (e.g., Bash, shell scripts) as alternatives to PowerShell for custom log collection.
  • When listing solutions, alternate the order or present Windows and Linux options together to avoid implicit prioritization.
  • Expand endpoint solutions to include Linux EDR/log collection tools and methods.
  • Where Windows Event Forwarding is mentioned, add equivalent Linux log forwarding solutions (e.g., syslog-ng, rsyslog) and clarify applicability.
Sentinel Reduce costs for Microsoft Sentinel ...cs/blob/main/articles/sentinel/billing-reduce-costs.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First Missing Linux Example
Summary
The documentation page exhibits mild Windows bias by providing a dedicated section for optimizing data collection specifically for Windows Security Events, with no equivalent guidance or examples for Linux or macOS systems. The only explicit OS mention is Windows, and no Linux/macOS data collection or cost optimization scenarios are discussed.
Recommendations
  • Add a parallel section detailing cost optimization strategies for Linux (and optionally macOS) security event collection, including connectors, data collection rules, and filtering options.
  • Provide examples or references for configuring data collection rules for Linux agents (such as the Azure Monitor Agent on Linux) and how to optimize ingestion and retention costs for Linux-based sources.
  • Ensure that any OS-specific recommendations are balanced, with Windows and Linux/macOS examples presented together or in separate, clearly labeled subsections.
  • Mention any limitations or differences in cost optimization features between Windows and Linux/macOS explicitly, so users can plan accordingly.
Sentinel Manage custom content with repository connections ...cs/blob/main/articles/sentinel/ci-cd-custom-content.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Missing Linux Example
Summary
The documentation page demonstrates a moderate Windows bias. It references PowerShell deployment scripts as the primary method for customizing deployments, without mentioning or providing alternatives for Linux/macOS users (such as Bash or cross-platform CLI). There are no examples or guidance for Linux shell usage, and the documentation assumes familiarity with Windows-centric tools and workflows.
Recommendations
  • Provide equivalent Bash or Azure CLI examples for deployment and workflow customization, especially for Linux/macOS users.
  • Clarify whether the PowerShell deployment scripts are compatible with PowerShell Core on Linux/macOS, and offer installation instructions if so.
  • Explicitly mention cross-platform support in relevant sections, or link to documentation for Linux/macOS users.
  • Include notes or examples for running repository management tasks on Linux/macOS environments.
Sentinel Connect Microsoft Sentinel to Amazon Web Services to ingest AWS service log data .../azure-docs/blob/main/articles/sentinel/connect-aws.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Windows First Missing Linux Example
Summary
The documentation page demonstrates a notable Windows bias, especially in the 'Automatic setup' section. It exclusively recommends using a PowerShell script for automating AWS connector setup, requiring PowerShell and AWS CLI installation. All command-line instructions reference PowerShell, with no mention of Bash, Linux, or macOS alternatives. There are no Linux/macOS-specific examples or guidance for running the automation script outside Windows environments. The manual setup avoids OS-specific tooling, but the recommended path is Windows-centric.
Recommendations
  • Provide Bash/zsh shell script alternatives for Linux/macOS users, or clarify that the PowerShell script works cross-platform (if true).
  • Explicitly document how to run the automation script on Linux/macOS, including installation steps for PowerShell Core on those platforms.
  • Include Linux/macOS-specific command-line examples (e.g., using Bash, terminal commands) alongside PowerShell instructions.
  • List installation instructions for both PowerShell and AWS CLI for Linux/macOS, not just link to Windows-centric guides.
  • Clarify any platform limitations for the automation script, and offer parity in automation tooling for non-Windows users.
Sentinel Use Azure Functions to connect Microsoft Sentinel to your data source | Microsoft Docs .../articles/sentinel/connect-azure-functions-template.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy Windows First Missing Linux Example
Summary
The documentation provides detailed manual deployment instructions for PowerShell-based Azure Functions, which are inherently Windows-centric, and lists these instructions before Python-based (cross-platform) deployment. The PowerShell section assumes use of PowerShell Core and does not mention Linux/macOS explicitly, nor does it provide equivalent shell or CLI examples for Linux users. The Python section requires Visual Studio Code but does not discuss alternative editors or command-line deployment options for Linux/macOS users. There is no mention of Linux-specific tools or workflows, and the documentation does not clarify that both PowerShell Core and Python are cross-platform, potentially leading Linux/macOS users to perceive a Windows bias.
Recommendations
  • Explicitly state that PowerShell Core and Python Azure Functions can be developed and deployed from Linux and macOS, not just Windows.
  • Provide Linux/macOS-specific instructions or examples for deploying Azure Functions, such as using Azure CLI or VS Code on Linux.
  • Include alternative deployment methods (e.g., Azure CLI, GitHub Actions) that work across platforms.
  • Clarify in the prerequisites and relevant sections that all steps can be performed on Linux/macOS, and mention any platform-specific considerations.
  • Consider listing Python (cross-platform) instructions before PowerShell, or interleave them, to avoid 'Windows first' perception.
Sentinel Collect logs from text files with the Azure Monitor Agent and ingest to Microsoft Sentinel - AMA ...blob/main/articles/sentinel/connect-custom-logs-ama.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First Powershell Heavy Missing Linux Example
Summary
The documentation is generally cross-platform, but there are subtle Windows biases. Windows and PowerShell examples are referenced first or exclusively in some sections (e.g., agent installation), and Linux-specific instructions are less detailed or appear later. There are no explicit Linux command-line examples for agent installation, and the ARM template placeholders do not clarify Linux path conventions. Linux log forwarder setup is covered, but parity in example depth and ordering is lacking.
Recommendations
  • Provide explicit Linux command-line examples for installing the Azure Monitor Agent (e.g., using Azure CLI or native Linux package managers).
  • Ensure Linux instructions and examples appear alongside or before Windows/PowerShell equivalents, not after.
  • Clarify file path conventions for Linux in ARM template documentation (e.g., /var/log/app.log).
  • Include sample syslog-ng/rsyslog configuration snippets for common Linux distributions.
  • Add troubleshooting and verification steps for Linux environments, matching the detail given for Windows.
Sentinel Create scheduled analytics rules from templates in Microsoft Sentinel | Microsoft Docs ...ticles/sentinel/create-analytics-rule-from-template.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Missing Linux Example
Summary
The documentation mentions PowerShell as a method for pushing rules to Microsoft Sentinel, but does not provide equivalent Linux/macOS CLI examples (such as Azure CLI or Bash scripts). The only automation tool referenced is PowerShell, which is primarily a Windows technology, and there is no mention of Linux-native alternatives or parity. This creates friction for users on Linux or macOS who may prefer or require non-Windows tooling.
Recommendations
  • Include examples using Azure CLI or REST API via curl for rule management, alongside PowerShell.
  • Explicitly mention cross-platform options for automation, such as Bash scripts or Python SDK usage.
  • Clarify which steps/tools are cross-platform and which are Windows-specific.
  • Add a note about PowerShell Core being available on Linux/macOS, if relevant, and provide installation guidance.
Sentinel Microsoft Sentinel entity types reference | Microsoft Docs ...docs/blob/main/articles/sentinel/entities-reference.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
🔧 Windows Tools Windows First
Summary
The documentation page shows a moderate Windows bias in its terminology and examples. Windows-centric concepts such as NTDomain, NetBiosName, SID, and RegistryKey/Hive are prominent in the entity schemas and identifier tables. Windows-specific fields (e.g., AlternateDataStreamName, WindowsSecurityZoneType) are included in the File entity, and references to Active Directory and NETBIOS domains appear before DNS domain equivalents. Linux and macOS equivalents are not mentioned, and examples are generally Windows-oriented.
Recommendations
  • Add explicit references to Linux/macOS concepts where relevant (e.g., user/group identifiers, file attributes, process details).
  • Provide examples for non-Windows environments, such as Linux UIDs/GIDs, domain structures, and file paths.
  • Clarify which fields are Windows-only and suggest alternatives or note irrelevance for Linux/macOS.
  • Include Linux/macOS-specific entity attributes (e.g., /etc/passwd for accounts, /var/log for logs, process attributes like cgroup or SELinux context).
  • Balance ordering in tables and explanations so that Windows and Linux/macOS concepts are presented equally.
Sentinel Audit log for Microsoft Sentinel data lake and graph in Microsoft Purview portal ...articles/sentinel/datalake/auditing-lake-activities.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Missing Linux Example Windows First
Summary
The documentation page provides a PowerShell-only example for searching the audit log, with no mention of Linux/macOS-compatible alternatives such as Bash, CLI, or REST API usage. The reliance on PowerShell and Exchange Online tools (which are Windows-centric) creates friction for Linux/macOS users, who may not have access to PowerShell or the required modules. The documentation also introduces the Windows/PowerShell method before any cross-platform alternatives, and does not acknowledge or provide guidance for non-Windows environments.
Recommendations
  • Add examples using cross-platform tools such as Microsoft Graph API, Office 365 Management Activity API via REST calls, or Azure CLI.
  • Provide Bash or Python script examples for querying the audit log from Linux/macOS.
  • Explicitly mention platform requirements and alternatives for non-Windows users.
  • Clarify whether PowerShell Core (pwsh) is supported on Linux/macOS for these tasks, and provide installation guidance if so.
Sentinel Notebook examples for querying the Microsoft Sentinel data lake ...b/main/articles/sentinel/datalake/notebook-examples.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Missing Linux Example
Summary
The documentation page demonstrates how to query the Microsoft Sentinel data lake using Jupyter notebooks, but it exhibits a Windows bias by referencing Visual Studio Code and the Microsoft Sentinel extension as prerequisites, without mentioning Linux/macOS alternatives or confirming cross-platform compatibility. There are no explicit instructions or troubleshooting notes for running these notebooks on Linux or macOS, nor are there examples of using other editors or environments. The code samples themselves are platform-neutral Python, but the setup and context are Windows-centric.
Recommendations
  • Explicitly state that Jupyter notebooks and the Microsoft Sentinel extension for Visual Studio Code are supported on Linux and macOS, or provide alternative instructions for those platforms.
  • Include setup instructions or troubleshooting notes for Linux/macOS users (e.g., installation of VS Code, extension compatibility, Spark environment setup).
  • Mention or provide examples for running the notebooks in other environments (e.g., JupyterLab, native Jupyter Notebook, Databricks, Azure Notebooks) that are platform-agnostic.
  • Add a note clarifying that all code samples are platform-neutral and can be run on any OS with the required Python and Spark dependencies.
Sentinel Scenarios detected by the Microsoft Sentinel Fusion engine ...ob/main/articles/sentinel/fusion-scenario-reference.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Windows First
Summary
The documentation page exhibits a moderate Windows bias, primarily through repeated references to Windows-specific tools and technologies such as PowerShell and WMI, and by focusing on Microsoft Defender for Endpoint (which is Windows-centric) for detection scenarios. Examples and threat detections involving PowerShell and WMI are described in detail, while Linux/macOS equivalents (e.g., Bash, SSH, systemd, auditd) are not mentioned. The page also references credential theft tools like Mimikatz, which are primarily Windows-based, and does not discuss Linux/macOS credential theft techniques or detection. The ordering and language throughout the page implicitly prioritize Windows environments and tooling.
Recommendations
  • Include detection scenarios and examples relevant to Linux/macOS environments, such as suspicious Bash scripts, SSH key usage, or systemd service manipulation.
  • Reference Linux/macOS credential theft tools (e.g., LaZagne, gsecdump) and describe how Fusion detects their execution.
  • Add coverage for Linux/macOS remote execution techniques (e.g., SSH, cron jobs, sudo abuse) alongside PowerShell and WMI.
  • When describing 'living off the land' attacks, mention Linux/macOS equivalents (e.g., abuse of built-in utilities like curl, wget, netcat, etc.).
  • Ensure parity in examples and detection patterns for non-Windows endpoints, including integration with Linux/macOS security logs and tools.
  • Explicitly state which scenarios are cross-platform and which are Windows-only, to help users understand coverage gaps.
← Previous Page 1 of 4 Next →