771
Total Pages
720
Linux-Friendly Pages
51
Pages with Bias
6.6%
Bias Rate

Bias Trend Over Time

Pages with Bias Issues

90 issues found
Showing 26-50 of 90 flagged pages
Sentinel This file is auto-generated . Do not edit manually. Changes will be overwritten. ...in/articles/sentinel/includes/deprecated-connectors.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Powershell Heavy Missing Linux Example
Summary
The documentation page demonstrates a notable Windows bias. Several connectors (e.g., Exchange Logs, Security Events) are described as working only with Windows agents or Windows machines, with explicit references to Windows tools and patterns (e.g., PowerShell, Windows agent). Windows-centric connectors and instructions are presented before Linux equivalents, and Linux-specific guidance is limited to a single Syslog section. There are no Linux/macOS examples or parity in agent installation instructions, and prerequisites for Linux are not discussed in detail.
Recommendations
  • Add equivalent Linux/macOS examples and instructions for each connector where possible.
  • Ensure agent installation and configuration steps are provided for Linux/macOS alongside Windows (not just for Syslog).
  • Present Linux and Windows options in parallel, rather than Windows-first.
  • Clarify which connectors are cross-platform and which are Windows-only, and provide alternatives for Linux/macOS users.
  • Include references to Linux tools and commands (e.g., Bash, systemd, CLI) where relevant.
Sentinel The Advanced Security Information Model (ASIM) Application Entity reference .../articles/sentinel/normalization-entity-application.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Missing Linux Example
Summary
The documentation page shows a Windows bias in several ways: process examples use Windows-style paths (e.g., C:\Windows\explorer.exe), and all sample process names are Windows executables. There are no Linux/macOS examples (e.g., /usr/bin/bash), and Windows terminology and file paths are used exclusively. Although there is a note acknowledging Linux, it does not provide Linux-specific examples or guidance.
Recommendations
  • Add Linux/macOS process examples alongside Windows ones (e.g., /usr/bin/sshd, /bin/bash).
  • Include Linux-style file paths and process names in the 'ProcessName' and 'Process' fields.
  • Provide explicit guidance or examples for Linux/macOS users in relevant notes and descriptions.
  • Ensure parity in terminology by mentioning Linux/macOS equivalents where Windows-specific terms are used.
Sentinel Advanced multistage attack detection in Microsoft Sentinel ...tDocs/azure-docs/blob/main/articles/sentinel/fusion.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Windows First
Summary
The documentation page demonstrates a moderate Windows bias. Several detection scenarios and examples reference Windows-specific tools (such as PowerShell, WMI, and Windows Error Events) and Microsoft Defender for Endpoint, which is primarily a Windows security solution. PowerShell-based attack patterns are highlighted in multiple places, and Windows terminology (e.g., 'Windows Error and Warning Events') is used in example tables. There are no explicit Linux/macOS examples, nor are Linux-specific attack patterns or tools mentioned. The order of presentation and scenario selection tends to favor Windows-centric threats and technologies.
Recommendations
  • Add equivalent Linux/macOS detection scenarios, such as suspicious Bash or shell command executions, sudo abuse, or Linux-specific malware.
  • Include examples of multistage attacks involving Linux endpoints, such as SSH brute force, rootkit installation, or suspicious cron jobs.
  • Reference Linux/macOS security tools and logs (e.g., auditd, syslog, journald) in tables and examples.
  • Ensure parity in scenario tables by including Linux/macOS alerts and incident types alongside Windows ones.
  • Provide guidance for configuring Fusion to detect threats on non-Windows platforms.
Sentinel SAP agentless data connector prerequisites checker ...icles/sentinel/includes/sap-agentless-prerequisites.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy Missing Linux Example Windows First
Summary
The documentation provides only a PowerShell script example for triggering the SAP prerequisites checker, with no equivalent example for Linux/macOS users (e.g., Bash, curl, or Python). This creates friction for non-Windows users, who must adapt the instructions themselves. The example is Windows-centric and appears first, with no mention of alternatives.
Recommendations
  • Add equivalent examples using Bash/curl and/or Python for Linux/macOS users.
  • Explicitly mention that any REST client can be used, and provide cross-platform sample commands.
  • Clarify any platform-specific requirements or limitations for running the prerequisites checker.
Sentinel List of Microsoft Sentinel Advanced Security Information Model (ASIM) parsers | Microsoft Docs ...b/main/articles/sentinel/normalization-parsers-list.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Windows Heavy
Summary
The documentation lists ASIM parsers for a wide variety of sources, but Windows-centric sources (e.g., Windows Events, Sysmon for Windows, Microsoft Defender XDR, Windows Security Events, IIS) are consistently present and often described in detail. Windows event types and connectors are frequently mentioned, sometimes with specific event IDs and collection agents. Linux sources are present (e.g., Sysmon for Linux, sshd, su, sudo, authpriv, Apache HTTP Server), but Windows examples and tools appear more frequently and are often listed before Linux equivalents in each section.
Recommendations
  • Ensure Linux and macOS sources are given equal prominence in each parser category, listing them alongside or before Windows sources where appropriate.
  • Expand notes for Linux/macOS sources to match the detail given for Windows (e.g., specify event types, collection methods, and supported connectors).
  • Add examples or references for Linux/macOS collection agents and connectors (e.g., mention NXlog for Linux, syslog collection details, or other open-source agents).
  • Where Windows event IDs and collection methods are described, provide equivalent details for Linux/macOS (e.g., syslog facility, event types, log file locations).
  • Consider including macOS-specific sources if supported, or clarify platform support for each parser.
Sentinel The Advanced Security Information Model (ASIM) Process Event normalization schema reference | Microsoft Docs ...rticles/sentinel/normalization-schema-process-event.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Windows Examples Windows Terms
Summary
The documentation page demonstrates a moderate Windows bias. Many example values for process names, paths, and command lines use Windows-style conventions (e.g., C:\Windows\explorer.exe, rundll32.exe). Integrity level explanations and references are Windows-centric, with links to Microsoft documentation and terminology (e.g., UAC, Mandatory Integrity Control). Linux is mentioned only in passing for PID conversion, and there are no Linux/macOS-specific examples, fields, or references. The documentation assumes Windows as the default context for process activity, file paths, and user/session identifiers.
Recommendations
  • Add Linux/macOS-specific examples for process names, paths, and command lines (e.g., /usr/bin/bash, /usr/local/bin/python3).
  • Include explanations of process integrity and privilege concepts for Linux/macOS (e.g., SELinux context, capabilities, sudo elevation).
  • Reference Linux/macOS documentation where appropriate, not only Windows resources.
  • Clarify field usage for non-Windows systems, especially where Windows-specific terms (e.g., UAC, integrity level) are used.
  • Ensure examples and field descriptions alternate or balance Windows and Linux/macOS contexts.
Sentinel Create Summary Rules for Microsoft Sentinel Solutions ...n/articles/sentinel/sentinel-summary-rules-creation.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
🔧 Windows Tools Windows First Missing Linux Example
Summary
The documentation page displays Windows bias in the 'ID' section, where PowerShell's New-GUID cmdlet is mentioned as the example tool for generating GUIDs, with no mention of Linux/macOS alternatives. The Windows tool is referenced first and exclusively, and there are no examples or suggestions for Linux/macOS users (such as uuidgen or Python). Other sections do not show platform bias, but the omission in a required step creates friction for non-Windows users.
Recommendations
  • Include Linux/macOS alternatives for GUID generation, such as 'uuidgen' (Linux/macOS CLI) or 'python -c "import uuid; print(uuid.uuid4())"'.
  • Present cross-platform options together, or mention platform-neutral online generators before platform-specific tools.
  • Add a note clarifying that any tool capable of generating a GUID is acceptable, and provide links to popular Linux/macOS methods.
Sentinel Import threat intelligence with the upload API ...e-docs/blob/main/articles/sentinel/stix-objects-api.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy Missing Linux Example 🔧 Windows Tools
Summary
The documentation provides a detailed PowerShell example for interacting with the API, relying on the MSAL.PS module and Windows certificate store. There are no equivalent examples for Linux/macOS environments, nor are cross-platform tools (such as curl, Python, or OpenSSL) mentioned. This creates friction for non-Windows users, who must adapt the instructions without guidance.
Recommendations
  • Add sample requests using cross-platform tools such as curl or Python (requests, msal).
  • Document how to acquire and use certificates on Linux/macOS (e.g., using OpenSSL, storing as PEM files).
  • Provide guidance for authenticating and sending requests from Linux/macOS, including environment-specific notes.
  • List PowerShell as one option, but present cross-platform alternatives first or alongside.
  • Clarify that the API is platform-agnostic and can be accessed from any OS with HTTP tooling.
Sentinel Create Hunting Queries for Microsoft Sentinel Solutions ...n/articles/sentinel/sentinel-hunting-rules-creation.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
🔧 Windows Tools Powershell Heavy Windows First
Summary
The documentation displays Windows bias in the 'ID' section, where PowerShell's New-GUID cmdlet is explicitly mentioned as a way to generate GUIDs, with no mention of Linux/macOS alternatives. The only tool example given for GUID generation is Windows-centric, and PowerShell is referenced before more platform-neutral or Linux/macOS methods. No Linux/macOS command-line tools (e.g., uuidgen) or guidance are provided, which may cause friction for non-Windows users.
Recommendations
  • Add Linux/macOS equivalents for GUID generation, such as mentioning the uuidgen command.
  • Present platform-neutral or cross-platform online GUID generators before platform-specific tools.
  • Ensure all tool references include both Windows and Linux/macOS options, or use generic language (e.g., 'any development tool, such as PowerShell's New-GUID or Linux's uuidgen').
Sentinel Create Playbooks for Microsoft Sentinel Solutions ...b/main/articles/sentinel/sentinel-playbook-creation.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Missing Linux Example Windows First
Summary
The documentation demonstrates a notable Windows bias in the playbook ARM template generation steps. It exclusively references a PowerShell script for sanitizing ARM templates, instructs users to use Windows PowerShell, PowerShell Core, or Visual Studio Code, and provides only Windows-centric instructions (including Set-ExecutionPolicy). There are no equivalent instructions or examples for Linux/macOS users, such as using Azure CLI, Bash, or cross-platform scripting alternatives. This may create friction for non-Windows users attempting to follow the guide.
Recommendations
  • Provide Linux/macOS instructions for running the PowerShell script, including prerequisites (e.g., installing PowerShell Core on Linux/macOS).
  • Offer alternative methods for ARM template sanitization, such as using Azure CLI, Bash scripts, or cross-platform tools.
  • Explicitly mention how to run the script on Linux/macOS, including any required changes (e.g., file permissions, execution policy).
  • Include examples or screenshots from Linux/macOS environments where applicable.
  • List any dependencies or limitations for non-Windows platforms up front.
Sentinel Microsoft Sentinel User and Entity Behavior Analytics (UEBA) reference ...ure-docs/blob/main/articles/sentinel/ueba-reference.md
Medium Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
🔧 Windows Tools Windows First Missing Linux Example
Summary
The documentation demonstrates a moderate Windows bias. Windows-specific event sources (e.g., Windows Security Events, Windows Forwarded Events) are listed explicitly, and device-related enrichments and examples predominantly reference Windows (e.g., DeviceFamily: Windows, OperatingSystem: Windows 10). There is little mention of Linux or macOS equivalents, and no examples or guidance are provided for non-Windows endpoints or logs. The documentation assumes a Windows-centric environment for device and security event analysis, which may create friction for organizations with significant Linux/macOS infrastructure.
Recommendations
  • Explicitly mention support for Linux/macOS endpoints and their log sources, if available.
  • Add examples and enrichment fields relevant to Linux/macOS devices (e.g., DeviceFamily: Linux, OperatingSystem: Ubuntu, macOS).
  • Clarify whether UEBA supports Linux/macOS security events and how to onboard these sources.
  • Provide parity in documentation tables and sample values for non-Windows operating systems.
  • If Linux/macOS support is limited, clearly state the limitations and provide guidance for mixed environments.
Sentinel Create scheduled analytics rules from templates in Microsoft Sentinel | Microsoft Docs ...ticles/sentinel/create-analytics-rule-from-template.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Missing Linux Example
Summary
The documentation mentions PowerShell as a method for pushing rules to Microsoft Sentinel, but does not provide equivalent examples or guidance for Linux/macOS users (e.g., Bash, Azure CLI). The only automation tool referenced is PowerShell, which is Windows-centric. No Linux/macOS-specific tools or examples are provided, and the API mention is generic without platform guidance.
Recommendations
  • Add examples for Linux/macOS users, such as using Azure CLI or Bash scripts to push rules via the API.
  • Explicitly mention cross-platform alternatives to PowerShell, and provide sample commands for those environments.
  • Clarify whether the API can be used from any OS and provide guidance or links for Linux/macOS usage.
  • Ensure automation and scripting sections include parity for Linux/macOS users, not just PowerShell.
Sentinel Microsoft Sentinel User and Entity Behavior Analytics (UEBA) reference ...ure-docs/blob/main/articles/sentinel/ueba-reference.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
🔧 Windows Tools Windows First Missing Linux Example
Summary
The documentation demonstrates a moderate Windows bias, primarily in the data sources and enrichment fields. Windows-specific event sources (e.g., Windows Security Events, Windows Forwarded Events) are listed explicitly, and device-related enrichments focus on Windows as the primary operating system and device family. There is little mention of Linux or macOS equivalents, and no examples or guidance are provided for non-Windows endpoints or logs. This may create friction for organizations with heterogeneous environments, as Linux/macOS users may not see their platforms represented or supported in the same detail.
Recommendations
  • Add explicit references to Linux/macOS log sources and connectors (e.g., Syslog, Linux audit logs) in the data sources table.
  • Include enrichment examples and schema fields for Linux/macOS devices (e.g., device family: Linux, macOS; operating system: Ubuntu, Red Hat, macOS Ventura, etc.).
  • Clarify whether UEBA supports non-Windows endpoints and how to onboard them, including any limitations or required connectors.
  • Provide parity in documentation for Linux/macOS event types, device attributes, and investigation workflows.
  • If Linux/macOS support is limited, state this clearly and provide guidance for mixed environments.
Sentinel Best practices for data collection in Microsoft Sentinel ...ocs/blob/main/articles/sentinel/best-practices-data.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Powershell Heavy Missing Linux Example
Summary
The documentation page demonstrates a moderate Windows bias. Windows-specific tools and patterns (e.g., Windows Event Forwarding, PowerShell, .NET) are mentioned frequently and sometimes before Linux equivalents. Windows examples and terminology are often presented first, and some sections (such as endpoint solutions and custom log collection) focus on Windows methods without equivalent Linux examples or details. Linux solutions are present but less detailed and sometimes referenced as requiring developer knowledge, which may create friction for Linux/macOS users.
Recommendations
  • Ensure Linux examples are provided for every Windows example, especially for custom log collection and endpoint solutions.
  • Present Windows and Linux solutions in parallel, rather than listing Windows methods first.
  • Include Linux/macOS-specific tools and scripts (e.g., Bash, Python) alongside PowerShell/.NET recommendations.
  • Expand details for Linux solutions to match the depth given to Windows solutions, including troubleshooting and configuration guidance.
  • Clarify agent support for various Linux distributions and provide links to relevant documentation.
Sentinel Use Azure Functions to connect Microsoft Sentinel to your data source | Microsoft Docs .../articles/sentinel/connect-azure-functions-template.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy Windows First Missing Linux Example
Summary
The documentation provides three deployment options: ARM template, manual deployment with PowerShell, and manual deployment with Python. The PowerShell manual deployment instructions are detailed and presented before the Python instructions, which require Visual Studio Code. There are no examples or instructions for deploying with Bash, CLI, or Linux-native tools. The PowerShell section assumes use of PowerShell Core, which is cross-platform, but the workflow and terminology are more familiar to Windows users. The Python workflow is tied to Visual Studio Code, which is available on Linux/macOS but may not be the preferred tool for all users. There is no mention of Linux shell, Azure CLI, or other Linux/macOS-specific deployment patterns.
Recommendations
  • Add manual deployment instructions using Azure CLI and Bash for Linux/macOS users.
  • Provide examples for deploying Function Apps using Linux-native tools (e.g., Bash scripts, az CLI).
  • Clarify that PowerShell Core is cross-platform and provide explicit instructions for Linux/macOS environments (e.g., installation, usage).
  • Offer alternative Python deployment instructions that do not require Visual Studio Code, such as using command-line tools.
  • Ensure examples and instructions are presented in a neutral order (not Windows-first).
Sentinel Onboard your Azure Stack Hub virtual machines to Microsoft Sentinel | Microsoft Docs ...ocs/blob/main/articles/sentinel/connect-azure-stack.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First Missing Linux Example
Summary
The documentation page provides a general workflow for onboarding Azure Stack Hub VMs to Microsoft Sentinel, but references Windows-specific guidance before Linux equivalents and omits direct Linux installation/configuration examples. Windows resources are mentioned first and more prominently, while Linux users are only pointed to troubleshooting documentation.
Recommendations
  • Provide explicit Linux onboarding instructions or examples alongside Windows steps.
  • Include direct links to Linux agent installation/configuration guides, not just troubleshooting.
  • Ensure parity in example screenshots and step-by-step guidance for both Windows and Linux VMs.
  • Mention Linux and Windows resources together, rather than prioritizing Windows.
Sentinel Anomalies detected by the Microsoft Sentinel machine learning engine ...ocs/blob/main/articles/sentinel/anomalies-reference.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Missing Linux Example Powershell Heavy
Summary
The documentation page exhibits a notable Windows bias. Many anomaly detections and examples reference Windows-specific data sources (e.g., Windows Security logs, Event IDs 4624/4625, PowerShell), with no equivalent coverage or examples for Linux or macOS systems. Anomaly types such as brute force detection, local account creation, and login volume are exclusively described in the context of Windows logs and events. There is no mention of Linux audit logs, syslog, or macOS security events, nor are Linux command interpreters (e.g., Bash, Python) referenced in code execution anomalies. This creates friction for users monitoring non-Windows endpoints.
Recommendations
  • Add equivalent anomaly detection descriptions and examples for Linux and macOS endpoints, referencing syslog, auditd, or other relevant logs.
  • Include Linux/macOS event IDs or log patterns for brute force, account creation, and login anomalies.
  • Expand 'Anomalous Code Execution' to mention Linux/macOS interpreters (e.g., Bash, Python, Perl) and their detection.
  • Provide parity in documentation structure, listing Linux/macOS sources and detection rules alongside Windows.
  • Where PowerShell is referenced, also mention Bash or other Linux shells.
  • Clarify which anomaly detections are Windows-only and which are cross-platform.
Sentinel Reduce costs for Microsoft Sentinel ...cs/blob/main/articles/sentinel/billing-reduce-costs.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
🔧 Windows Tools Missing Linux Example
Summary
The documentation page generally avoids platform-specific bias except in the section 'Use data collection rules for your Windows Security Events', which exclusively discusses Windows data sources and tools (Windows Security Events connector, Azure Monitor Agent) without mentioning Linux equivalents or how to optimize costs for Linux-based event collection. No PowerShell-heavy or Windows-first ordering is present, but the lack of Linux/macOS event collection guidance is a notable gap.
Recommendations
  • Add a section describing cost optimization for Linux-based event collection, such as using the Linux Syslog connector or other relevant agents.
  • Provide examples or references for configuring data collection rules for Linux servers, including how to filter and reduce ingested data.
  • Clarify whether similar cost-saving strategies (custom filters, agent configuration) are available for Linux/macOS endpoints and link to relevant documentation.
  • Ensure parity in guidance for both Windows and Linux/macOS environments, especially in sections discussing connectors and data collection.
Sentinel Manage custom content with repository connections ...cs/blob/main/articles/sentinel/ci-cd-custom-content.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Missing Linux Example
Summary
The documentation page demonstrates a moderate Windows bias. PowerShell is referenced as the deployment scripting tool, but there is no mention of Linux/macOS alternatives (such as Bash or cross-platform scripting). All workflow/pipeline customization examples refer to PowerShell scripts, and there are no explicit Linux/macOS instructions or examples. The documentation does not clarify whether the provided scripts and instructions work natively on Linux/macOS, nor does it offer guidance for users on those platforms.
Recommendations
  • Explicitly state whether the PowerShell deployment scripts are compatible with PowerShell Core on Linux/macOS.
  • Provide equivalent Bash or cross-platform scripting examples for deployment customization.
  • Include instructions or troubleshooting tips for Linux/macOS users, especially regarding prerequisites and environment setup.
  • Mention and prioritize cross-platform tools and patterns where possible, rather than assuming Windows-centric workflows.
Sentinel Connect Microsoft Sentinel to Amazon Web Services to ingest AWS service log data .../azure-docs/blob/main/articles/sentinel/connect-aws.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy Windows First Missing Linux Example
Summary
The documentation page demonstrates a notable Windows bias, especially in the 'Automatic setup' section, which exclusively references PowerShell and provides instructions for running scripts via PowerShell. There are no examples or guidance for Linux/macOS users, such as using Bash or other shells. The prerequisite to install PowerShell and AWS CLI is stated, but only PowerShell is used in the walkthrough, and all command-line instructions assume a Windows environment. No Linux or macOS alternatives are mentioned, nor are there any screenshots or examples for those platforms.
Recommendations
  • Provide explicit instructions and example commands for Linux/macOS users, using Bash or compatible shells.
  • Clarify whether the setup script can be run in PowerShell Core on Linux/macOS, or provide a Bash version if not.
  • Include screenshots or terminal output examples for Linux/macOS environments.
  • List prerequisites for Linux/macOS separately, including installation links for PowerShell Core and AWS CLI on those platforms.
  • Reorder examples so that Windows and Linux/macOS instructions are presented with equal prominence, or in parallel tabs/sections.
Sentinel Audit log for Microsoft Sentinel data lake and graph in Microsoft Purview portal ...articles/sentinel/datalake/auditing-lake-activities.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Missing Linux Example Windows First
Summary
The documentation provides only PowerShell-based examples for searching the audit log, which are primarily relevant to Windows environments. There are no CLI or scripting examples for Linux/macOS users (e.g., Bash, curl, or Python), nor are alternative tools or approaches mentioned. The use of PowerShell and Exchange Online roles is presented as the default method, with no parity for Linux/macOS users.
Recommendations
  • Add equivalent examples using cross-platform tools such as Bash, curl, or Python to query the Office 365 Management API.
  • Mention and link to REST API documentation for audit log access, with sample requests that can be run from any OS.
  • Clarify which steps are OS-agnostic (e.g., web portal access) and which require Windows-specific tools.
  • Provide guidance for Linux/macOS users on installing and using Microsoft 365 CLI or other supported SDKs.
  • Explicitly state any OS requirements or limitations for PowerShell-based instructions.
Sentinel Notebook examples for querying the Microsoft Sentinel data lake ...b/main/articles/sentinel/datalake/notebook-examples.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
🔧 Windows Tools Windows First
Summary
The documentation page demonstrates a subtle Windows bias by requiring Visual Studio Code with the Microsoft Sentinel extension as the primary environment for running Jupyter notebooks. This toolchain is most commonly used and best supported on Windows, and the documentation does not mention Linux/macOS alternatives or compatibility. There are no explicit PowerShell examples or Windows-only code, but the environment setup and implicit tool recommendations favor Windows users. All code samples are Python and Spark-based, which are cross-platform, but the lack of guidance for Linux/macOS users creates friction.
Recommendations
  • Explicitly state that the Jupyter notebook examples and the Microsoft Sentinel extension for Visual Studio Code are supported on Linux and macOS, or provide alternative instructions for these platforms.
  • Include setup instructions or links for installing Visual Studio Code and the Sentinel extension on Linux/macOS.
  • Mention that Jupyter notebooks can be run in other environments (e.g., JupyterLab, VS Code on Linux/macOS, Azure Notebooks) if supported.
  • Add troubleshooting notes for common Linux/macOS issues (e.g., Spark setup, extension installation).
  • If any features are Windows-only, clearly mark them and suggest alternatives for other platforms.
Sentinel Microsoft Purview Information Protection connector reference - audit log record types and activities support in Microsoft Sentinel .../sentinel/microsoft-purview-record-types-activities.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 1 bias type
Detected Bias Types
🔧 Windows Tools
Summary
The documentation references the Windows-specific PowerShell cmdlet Unlock-SPOSensitivityLabelEncryptedFile as a method for removing sensitivity labels from files, without mentioning Linux/macOS alternatives or clarifying cross-platform support. No Linux/macOS-specific tools or examples are provided.
Recommendations
  • Clarify whether the Unlock-SPOSensitivityLabelEncryptedFile cmdlet is available on PowerShell Core (cross-platform) or only on Windows.
  • If no Linux/macOS equivalent exists, explicitly state this and suggest alternative methods for non-Windows users.
  • Provide examples or guidance for performing equivalent actions on Linux/macOS, if possible.
  • Consider including a table or section listing platform support for all referenced tools and commands.
Sentinel Scenarios detected by the Microsoft Sentinel Fusion engine ...ob/main/articles/sentinel/fusion-scenario-reference.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Windows First
Summary
The documentation page demonstrates a moderate Windows bias, particularly in the 'Malicious execution with legitimate process' section, which focuses on Windows-specific tools and technologies such as PowerShell and WMI. These attack scenarios are described exclusively in terms of Windows tooling and behaviors, with no mention of Linux/macOS equivalents (e.g., Bash, SSH, systemd, cron, etc.). Additionally, the only credential theft tool mentioned by name is Mimikatz, which is primarily a Windows tool. Throughout the page, examples and scenarios are described using Windows-centric terminology and tools, with little to no reference to Linux/macOS environments or their attack surfaces.
Recommendations
  • Add equivalent scenarios and detection descriptions for Linux/macOS environments, such as suspicious Bash or Python command execution, SSH abuse, or use of Linux credential dumping tools (e.g., 'LaZagne', 'gsecdump').
  • Where PowerShell or WMI is referenced, include parallel examples for Linux/macOS (e.g., suspicious shell commands, remote execution via SSH, or abuse of system management tools like systemd or cron).
  • Mention cross-platform attack frameworks and techniques, and clarify which scenarios apply to non-Windows environments.
  • When referencing credential theft tools, include Linux/macOS tools and techniques.
  • Ensure that detection logic and data connector sources are described for Linux/macOS endpoints where supported.
Sentinel Advanced multistage attack detection in Microsoft Sentinel ...tDocs/azure-docs/blob/main/articles/sentinel/fusion.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Windows First
Summary
The documentation page demonstrates moderate Windows bias. Several detection scenarios and examples reference Windows-specific tools (such as PowerShell, WMI, and Windows event alerts) and Microsoft Defender products that are primarily Windows-centric. PowerShell-based attack patterns are highlighted multiple times, and Windows alerts are used in example tables. Linux/macOS equivalents (such as Bash, SSH, or Linux-specific malware) are not mentioned, and there are no examples or scenarios tailored for non-Windows environments. Additionally, Windows-related examples (e.g., PowerShell, Windows Error Events) are presented before any mention of cross-platform or third-party tools, reinforcing a Windows-first perspective.
Recommendations
  • Add detection scenarios and examples that reference Linux/macOS attack patterns, such as suspicious Bash scripts, SSH brute force, or Linux-specific malware.
  • Include alerts and incident examples from Linux/macOS endpoints, using connectors like Syslog, CEF, or native Linux security tools.
  • Provide parity in documentation by listing Linux/macOS examples alongside Windows ones, rather than focusing on Windows tools first.
  • Reference cross-platform detection capabilities and clarify how Sentinel Fusion works with non-Windows data sources.
  • Highlight integration with third-party and open-source security tools commonly used in Linux/macOS environments.