Detected Bias Types
🔧
Windows Tools
Windows First
Missing Linux Example
Summary
The documentation page demonstrates a moderate Windows bias, primarily through its focus on Windows-centric data sources (e.g., Windows Security Events, Windows Forwarded Events, Microsoft Defender XDR, Active Directory) and terminology. Device and OS examples are exclusively Windows (e.g., 'Device family: Windows', 'Operating system: Windows 10'), with no mention of Linux or macOS equivalents in enrichment fields or sample values. There are no examples or guidance for Linux/macOS endpoints, log sources, or device enrichments, and Windows tools and patterns are referenced before any cross-platform or Linux alternatives.
Recommendations
- Add explicit examples and documentation for Linux and macOS endpoints, including how their logon/authentication events can be ingested and analyzed by UEBA.
- Include Linux/macOS device families and operating systems in enrichment field sample values and descriptions.
- Document supported Linux/macOS log sources and connectors (e.g., syslog, auditd, OSQuery) in the data sources table.
- Clarify whether non-Windows devices are supported for device insights and how their data is mapped.
- Provide parity in device-related enrichments and sample values for Linux/macOS.
- If Windows-only, clearly state limitations and recommend alternatives for non-Windows environments.