771
Total Pages
720
Linux-Friendly Pages
51
Pages with Bias
6.6%
Bias Rate

Bias Trend Over Time

Pages with Bias Issues

90 issues found
Showing 51-75 of 90 flagged pages
Sentinel This file is auto-generated . Do not edit manually. Changes will be overwritten. ...in/articles/sentinel/includes/deprecated-connectors.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Missing Linux Example
Summary
The documentation page shows a notable Windows bias: Windows agents and tools are mentioned first and more frequently, especially for Exchange and Security Events connectors. Windows-specific patterns (e.g., 'Windows agent', 'Windows machines') are described in detail, while Linux equivalents are only briefly referenced or omitted. Only the Syslog connector section directly addresses Linux, and there are no Linux-specific examples or instructions for other connectors.
Recommendations
  • For each connector, explicitly mention Linux/macOS support status and provide equivalent instructions or examples where possible.
  • Add Linux/macOS agent installation and configuration steps alongside Windows instructions.
  • Where Windows tools (e.g., PowerShell, Windows agent) are referenced, include Linux alternatives (e.g., Bash, Linux agent) and clarify cross-platform compatibility.
  • Ensure connector prerequisites and troubleshooting steps cover both Windows and Linux environments.
  • Reorder sections or examples so that Linux and Windows are presented with equal prominence.
Sentinel SAP agentless data connector prerequisites checker ...icles/sentinel/includes/sap-agentless-prerequisites.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy Missing Linux Example Windows First
Summary
The documentation provides only a PowerShell script as the example for triggering the SAP prerequisites checker, with no equivalent Linux/macOS example (e.g., Bash, curl, or Python). This creates friction for users on non-Windows platforms, as PowerShell is not natively available and the instructions implicitly prioritize Windows usage.
Recommendations
  • Add a Linux/macOS example using curl or Python to demonstrate how to trigger the iflow from a REST client.
  • Explicitly mention that any REST client can be used, and provide platform-agnostic instructions.
  • Reorder or parallelize examples so that Windows and Linux/macOS instructions are presented together, not Windows-first.
Sentinel Advanced Security Information Model (ASIM) security content | Microsoft Docs ...s/blob/main/articles/sentinel/normalization-content.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
🔧 Windows Tools Powershell Heavy Windows First
Summary
The documentation page exhibits a moderate Windows bias. Many examples and hunting queries focus on Windows-specific tools (e.g., rundll32.exe, PowerShell, certutil, Exchange PowerShell Snapin, Windows System Shutdown/Reboot), and several analytics rules and queries reference Windows-centric attack patterns or binaries. There is little to no mention of Linux/macOS equivalents, and Windows tools are often referenced first or exclusively in process activity and registry sections.
Recommendations
  • Add Linux/macOS-specific examples and hunting queries, such as those involving bash, systemd, cron, or common Linux persistence/attack techniques.
  • Include detection rules for Linux/macOS threats (e.g., SSH brute force, sudo abuse, Linux malware, MacOS launch agents).
  • Balance references to Windows tools (PowerShell, rundll32, certutil) with Linux/macOS tools (bash scripts, curl/wget, system utilities).
  • Explicitly state cross-platform applicability or limitations for each rule/query.
  • Provide parity in documentation structure by listing Linux/macOS examples alongside Windows ones, not just as an afterthought.
Sentinel Develop Microsoft Sentinel Advanced Security Information Model (ASIM) parsers | Microsoft Docs ...ain/articles/sentinel/normalization-develop-parsers.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Powershell Heavy
Summary
The documentation demonstrates a moderate Windows bias, primarily in deployment and management sections. Windows-centric tools (PowerShell, Azure portal) are mentioned first and sometimes exclusively for tasks such as deleting functions and deploying ARM templates. There is a lack of explicit Linux/macOS alternatives or parity in deployment and management instructions, and no mention of cross-platform command-line tools (e.g., Azure CLI, Bash). However, the core parser development and testing instructions are platform-neutral, focusing on KQL and Azure services.
Recommendations
  • Include explicit instructions and examples for Linux/macOS users, such as using Azure CLI or Bash scripts for deployment and management tasks.
  • Mention cross-platform alternatives alongside Windows tools (e.g., provide both PowerShell and Azure CLI commands for deleting functions and deploying templates).
  • Avoid listing Windows tools first; present cross-platform options together or in parallel.
  • Clarify that the Azure portal and KQL are accessible from any OS via browser, and highlight any platform-specific limitations if they exist.
Sentinel The Advanced Security Information Model (ASIM) Application Entity reference .../articles/sentinel/normalization-entity-application.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Missing Linux Example
Summary
The documentation page exhibits Windows bias through the exclusive use of Windows-style file paths in examples (e.g., 'C:\Windows\explorer.exe'), references to Windows-specific process conventions, and the lack of Linux/macOS equivalents or examples. Linux is mentioned only in passing, with no concrete examples or guidance for Linux/macOS users.
Recommendations
  • Provide Linux/macOS examples alongside Windows ones, such as '/usr/bin/firefox' for process names.
  • Clarify process ID conventions for Linux/macOS, including typical formats and conversion needs.
  • Avoid using only Windows-style paths in examples; alternate or dual examples should be shown.
  • Explicitly mention Linux/macOS tools or patterns where relevant.
Sentinel The Advanced Security Information Model (ASIM) DHCP normalization schema reference | Microsoft Docs ...ob/main/articles/sentinel/normalization-schema-dhcp.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
🔧 Windows Tools Windows First Missing Linux Example
Summary
The documentation shows evidence of Windows bias, notably in the DHCP-specific fields and examples. Windows terminology and formats (e.g., domain\hostname, TransactionID mapping, MAC address logging quirks) are referenced explicitly, while Linux or cross-platform equivalents are not mentioned. Examples use Windows-centric values (e.g., DESKTOP-1282V4D, Contoso\DESKTOP-1282V4D), and guidance is tailored to Windows server behavior (such as MAC address formatting). There are no Linux-specific examples, notes, or clarifications for non-Windows DHCP servers.
Recommendations
  • Add examples and notes for Linux and macOS DHCP servers, including field mappings and log formats.
  • Clarify how non-Windows DHCP servers (e.g., ISC DHCP, Kea) should populate fields like DhcpSessionId, SrcHostname, and SrcDomainType.
  • Provide guidance on handling MAC address formats as logged by Linux DHCP servers.
  • Include cross-platform sample values (e.g., Linux hostnames, FQDNs) and domain formats.
  • Explicitly mention Linux/macOS equivalents when referencing Windows-specific behaviors or quirks.
Sentinel The Advanced Security Information Model (ASIM) Process Event normalization schema reference | Microsoft Docs ...rticles/sentinel/normalization-schema-process-event.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Windows Examples Windows Terms
Summary
The documentation page demonstrates a moderate Windows bias. Many field examples use Windows-style paths (e.g., C:\Windows\explorer.exe), and Windows-specific terms (such as integrity levels and UAC) are described in detail, often with links to Microsoft/Win32 documentation. Linux is mentioned only in passing, and there are no Linux/macOS-specific examples, terminology, or links. The schema is intended to be cross-platform, but the documentation and examples are overwhelmingly Windows-centric.
Recommendations
  • Add Linux/macOS-specific examples for process names, paths, and command lines (e.g., /usr/bin/bash, /usr/bin/sshd, etc.).
  • Document Linux/macOS equivalents for fields such as integrity level and privilege elevation, or clarify how these fields should be populated on non-Windows systems.
  • Include links to Linux/macOS documentation for relevant concepts (e.g., process IDs, user sessions, privilege elevation).
  • Balance examples and terminology so that Linux/macOS users see their platforms represented equally.
  • Explicitly state how fields should be handled when the underlying OS does not support a Windows-specific concept (e.g., UAC, integrity level).
Sentinel Sample Microsoft Sentinel workspace designs ...lob/main/articles/sentinel/sample-workspace-designs.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First Missing Linux Example
Summary
The documentation page demonstrates a subtle Windows bias by consistently listing Windows Security Events and Windows Events as primary log sources, and by referencing the Azure Monitoring Agent (AMA) specifically for Windows VMs without mentioning Linux VM log collection methods or Linux-specific agent configuration. There are no explicit Linux or macOS examples, nor are Linux collection patterns or tools described, despite the fact that Syslog and CEF are mentioned as data sources. The guidance for log splitting and agent usage is Windows-centric, and Linux parity is not addressed.
Recommendations
  • Include explicit examples and guidance for collecting logs from Linux VMs, such as configuring AMA or legacy agents for Linux, and how to route Linux security and syslog events to workspaces.
  • Mention Linux-specific log types (e.g., auth.log, syslog, auditd) alongside Windows Security Events when listing data sources.
  • Provide parity in agent configuration instructions, showing both Windows and Linux steps for splitting logs between workspaces.
  • Reference Linux diagnostic settings and data collection patterns where relevant, not just Windows.
  • Clarify that Microsoft Sentinel supports both Windows and Linux sources, and link to Linux-specific documentation.
Sentinel Create Playbooks for Microsoft Sentinel Solutions ...b/main/articles/sentinel/sentinel-playbook-creation.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Missing Linux Example Windows First
Summary
The documentation page demonstrates a notable Windows bias in its instructions for generating sanitized ARM templates for playbooks. It exclusively provides a PowerShell script for this purpose, references Windows PowerShell and Visual Studio Code as the editors, and instructs users to run Windows-specific commands (Set-ExecutionPolicy). There is no mention of Linux/macOS equivalents, alternative shell scripts, or cross-platform usage guidance. This creates friction for users on non-Windows platforms, as they may not have PowerShell installed or may encounter issues with script execution policies.
Recommendations
  • Provide explicit instructions for running the PowerShell script on Linux/macOS using PowerShell Core (pwsh), including any necessary prerequisites and differences in script execution policy.
  • Offer a Bash or Python alternative script for ARM template sanitization, or clarify if the provided PowerShell script is cross-platform and how to use it on non-Windows systems.
  • Include notes or examples for Linux/macOS users, such as using VS Code or other editors on those platforms.
  • List platform requirements and compatibility for the provided tooling at the start of the relevant section.
  • Avoid assuming Windows as the default environment; present cross-platform instructions or alternatives side-by-side.
Sentinel Create Summary Rules for Microsoft Sentinel Solutions ...n/articles/sentinel/sentinel-summary-rules-creation.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
🔧 Windows Tools Windows First Missing Linux Example
Summary
The documentation page exhibits Windows bias primarily in the section describing how to generate a GUID for the 'id' attribute. It mentions the PowerShell 'New-GUID' cmdlet as a method for GUID generation, referencing Windows tooling first and exclusively, without providing Linux or macOS alternatives. No Linux or cross-platform command-line examples (such as 'uuidgen') are offered, and the only tool explicitly named is PowerShell, which is native to Windows.
Recommendations
  • Include Linux/macOS alternatives for GUID generation, such as the 'uuidgen' command.
  • Present cross-platform or web-based GUID generation options before or alongside Windows-specific tools.
  • Add explicit examples for Linux and macOS users where platform-specific tooling is mentioned.
  • Review other sections for similar patterns and ensure parity in tooling and examples.
Sentinel Import threat intelligence with the upload API ...e-docs/blob/main/articles/sentinel/stix-objects-api.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy Missing Linux Example 🔧 Windows Tools
Summary
The documentation provides a detailed PowerShell example for interacting with the upload API, relying on the MSAL.PS module and Windows certificate store paths. There are no equivalent examples for Linux/macOS users (e.g., Bash, curl, Python), nor is there guidance for non-Windows authentication workflows or certificate management. This creates friction for users on Linux or macOS platforms.
Recommendations
  • Add sample code for Linux/macOS environments using Bash (curl), Python (requests, msal), or other cross-platform tools.
  • Include instructions for acquiring access tokens and managing certificates on Linux/macOS (e.g., using OpenSSL, storing certificates in files).
  • Document how to invoke the API using curl or Python, including example request and response bodies.
  • Clarify that the PowerShell/MSAL.PS workflow is Windows-centric and provide parity for other platforms.
  • Reference cross-platform authentication libraries (e.g., MSAL for Python, Node.js) and show how to use them.
Sentinel Microsoft Sentinel skill-up training ...docs/blob/main/articles/sentinel/skill-up-resources.md
Medium Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Powershell Heavy Missing Linux Example
Summary
The documentation page for Microsoft Sentinel skill-up training demonstrates a moderate Windows bias. Windows terminology, tools, and examples (such as Windows Security Events, Windows DNS, and PowerShell) are mentioned more frequently and often before Linux equivalents. Some features and health monitoring solutions are described as 'Windows only', and PowerShell is highlighted as the main automation interface before alternatives. Linux-specific guidance is present but less prominent, and Linux/macOS users may need to infer or seek additional resources for parity.
Recommendations
  • Ensure that Linux/macOS equivalents are mentioned alongside Windows tools and examples, especially in sections about data collection, log management, and health monitoring.
  • Provide explicit Linux/macOS examples for automation (e.g., Bash, CLI, Python) and clarify cross-platform compatibility for APIs and connectors.
  • Avoid phrases like 'Windows only' without offering Linux alternatives or workarounds.
  • Balance the order of presentation so that Linux/macOS options are not always listed after Windows ones.
  • Add more references to Linux/macOS documentation, especially for agent health, log collection, and transformation.
  • Highlight cross-platform capabilities in introductory and summary sections.
Sentinel The Advanced Security Information Model (ASIM) Network Session normalization schema reference | Microsoft Docs ...main/articles/sentinel/normalization-schema-network.md
Low Priority View Details →
Scanned: 2026-01-13 06:17
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows Examples Windows Terms Windows First
Summary
The documentation page is generally cross-platform and vendor-neutral, but there is a mild Windows bias in examples and terminology. Several example values use Windows-specific paths (e.g., C:\Windows\explorer.exe), hostnames (e.g., DESKTOP-1282V4D), and domain formats (domain\hostname). Windows terms are sometimes mentioned before Linux equivalents, and Windows-style examples are more prevalent than Linux/macOS ones. No critical functionality is locked to Windows, and Linux is referenced in some places (e.g., process ID type guidance), but Linux/macOS users may find the examples less relatable.
Recommendations
  • Add Linux/macOS equivalent examples alongside Windows ones (e.g., /usr/bin/sshd, linux-host1).
  • Clarify that fields like process names, hostnames, and domain formats are platform-agnostic and provide examples for multiple OSes.
  • When describing formats (e.g., FQDN), mention both Windows and Linux conventions equally.
  • Avoid using Windows paths and hostnames exclusively in examples; rotate or pair with Linux/macOS samples.
  • Explicitly state cross-platform applicability where relevant.
Sentinel Microsoft Sentinel skill-up training ...docs/blob/main/articles/sentinel/skill-up-resources.md
Low Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First 🔧 Windows Tools
Summary
The documentation generally maintains cross-platform neutrality, but there are subtle signs of Windows bias. Windows is mentioned first in several places (e.g., 'Windows, Azure, and Office'), and Windows-specific tools or patterns (such as Windows Security Events, Sysmon, WEF, and PowerShell) are referenced more frequently or before their Linux equivalents. However, Linux and macOS are not excluded, and alternatives are referenced (e.g., Syslog, CEF, Heartbeat table for Linux). There are no critical sections that are Windows-only, and Linux users can complete all tasks described.
Recommendations
  • Ensure that Linux/macOS equivalents are mentioned alongside Windows tools, especially in introductory sections.
  • When listing supported platforms or tools, alternate the order or explicitly state cross-platform support.
  • Provide Linux/macOS-specific examples or references where Windows tools (e.g., PowerShell, Windows Events) are mentioned.
  • Highlight cross-platform capabilities in modules discussing APIs, automation, and monitoring.
  • Add explicit references to Linux/macOS onboarding, troubleshooting, and operational guides where relevant.
Sentinel Common Event Format (CEF) key and CommonSecurityLog field mapping ...e-docs/blob/main/articles/sentinel/cef-name-mapping.md
Low Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
🔧 Windows Tools Windows First
Summary
The documentation page exhibits minor Windows bias, primarily through the frequent mention of Windows-specific concepts such as NTDomain and Windows domain fields, and the use of Windows-style file paths (e.g., C:\ProgramFiles\WindowsNT\Accessories\wordpad.exe) before or alongside Linux equivalents. Several field descriptions reference Windows domains or NTDomain, while Linux/UNIX equivalents are less emphasized or only mentioned as examples. However, Linux/UNIX concepts (e.g., process names, file paths like /usr/bin/zip) are present, and the documentation is largely platform-neutral.
Recommendations
  • Ensure Linux/UNIX examples are given equal prominence to Windows examples in field descriptions and sample values.
  • Where Windows-specific fields (e.g., NTDomain) are described, clarify Linux/UNIX equivalents or note when fields are Windows-only.
  • Alternate the order of examples so that Linux/UNIX paths and concepts are sometimes listed first.
  • Add explicit notes on cross-platform applicability for fields that may differ between Windows and Linux/UNIX systems.
Sentinel Create a codeless connector for Microsoft Sentinel ...ob/main/articles/sentinel/create-codeless-connector.md
Low Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First Powershell Heavy
Summary
The documentation page demonstrates mild Windows bias in its API testing tool recommendations, listing PowerShell and Visual Studio Code before Linux-native options like curl. PowerShell is specifically mentioned as an example, and Windows-centric tools (VS Code, Edge Network Console) are listed before curl. However, curl and Bruno (cross-platform) are included, and no critical steps are Windows-only. The ARM template and connector creation instructions are platform-agnostic.
Recommendations
  • List cross-platform tools (e.g., curl, Bruno) before Windows-specific ones in the API testing section.
  • Provide explicit Linux/macOS command examples where PowerShell is mentioned.
  • Mention Linux/macOS equivalents for Visual Studio Code extensions and Edge Network Console, or clarify their cross-platform availability.
  • Add a note that all steps can be completed on Linux/macOS, and highlight any platform-specific caveats if present.
Sentinel Data connector definitions reference for the Codeless Connector Framework ...es/sentinel/data-connector-ui-definitions-reference.md
Low Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
🔧 Windows Tools Windows First
Summary
The documentation is generally platform-neutral, but there is a subtle Windows bias in the 'InstallAgent' section, where Windows agent installation link types are listed before Linux equivalents. Additionally, the only detailed connector example referenced is for Windows DNS, and the link points to a Windows-specific template. However, Linux options are present and mentioned, and no critical steps are Windows-only.
Recommendations
  • Alternate the order of Windows and Linux agent installation link types, or list them alphabetically to avoid implicit prioritization.
  • Provide example links and templates for both Windows and Linux connectors, not just Windows DNS.
  • Include explicit Linux/macOS sample connector references and examples in the documentation.
  • Ensure screenshots and sample code are not Windows-centric unless necessary.
Sentinel Create scheduled analytics rules in Microsoft Sentinel | Microsoft Docs .../blob/main/articles/sentinel/create-analytics-rules.md
Low Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First Powershell Heavy Missing Linux Example
Summary
The documentation page demonstrates mild Windows bias. While the main workflow is portal-based and cross-platform, references to automation and scripting (such as enabling rules via API or PowerShell) mention PowerShell explicitly and provide a PowerShell Gallery link, with no mention of Linux/macOS equivalents (e.g., Azure CLI, Bash, or cross-platform scripting). Additionally, PowerShell is referenced before API, and no Linux-specific tools or examples are provided for automation tasks. There are no explicit Windows-only tools or screenshots, but the scripting/automation guidance is Windows-centric.
Recommendations
  • Include examples using Azure CLI (which is cross-platform) for rule management and automation alongside PowerShell.
  • Explicitly state that PowerShell Core is available on Linux/macOS, or provide Bash/CLI alternatives for common tasks.
  • When mentioning automation, list API and CLI options before or alongside PowerShell, to avoid implying PowerShell is the primary or only method.
  • Add a note or section on cross-platform automation approaches for Sentinel rule management.
Sentinel The Advanced Security Information Model (ASIM) DNS normalization schema reference | Microsoft Docs ...lob/main/articles/sentinel/normalization-schema-dns.md
Low Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First 🔧 Windows Tools
Summary
The documentation demonstrates a mild Windows bias, primarily in the ordering and examples of field values. Windows domain and hostname formats (e.g., 'Contoso\DESKTOP-1282V4D') are shown first and most frequently in examples, and Windows-specific terminology (such as 'Windows' domain type, SIDs, and process paths like 'C:\Windows\explorer.exe') is used throughout. Linux equivalents are mentioned but not exemplified, and no Linux/macOS-specific examples (e.g., process paths, hostnames, domain types) are provided. There is no Powershell or Windows-only tooling, but the schema and examples are clearly oriented toward Windows environments.
Recommendations
  • Add Linux/macOS-specific examples for fields such as process names (e.g., '/usr/bin/bash'), hostnames, and domain types.
  • Provide sample values for fields like SrcDomainType and SrcFQDN using Linux/macOS conventions (e.g., FQDNs like 'host.example.com').
  • Balance the ordering of examples so that Linux/macOS formats are shown alongside or before Windows formats.
  • Clarify that the schema is platform-agnostic and explicitly mention Linux/macOS applicability where relevant.
Sentinel The Advanced Security Information Model (ASIM) Audit Events normalization schema reference | Microsoft Docs ...b/main/articles/sentinel/normalization-schema-audit.md
Low Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows Examples Windows Terms Windows First
Summary
The documentation is largely platform-neutral, focusing on schema definitions and KQL usage. However, there is a subtle Windows bias: examples of field values (e.g., hostnames like 'DESKTOP-1282V4D', domain formats like 'Contoso\DESKTOP-1282V4D', and application paths like 'C:\Windows\System32\svchost.exe') are Windows-centric. Username types and examples reference 'Windows', and device OS examples use 'Windows 10'. Linux/macOS equivalents are not shown, and Windows formats are mentioned first when describing FQDN/domain formats.
Recommendations
  • Add Linux/macOS examples alongside Windows ones for hostnames, domain formats, application paths, and OS fields.
  • Clarify that fields such as ActorUsernameType, TargetDvcOs, etc., can represent Linux/macOS values and provide sample values (e.g., '/usr/bin/sshd', 'ubuntu', 'macOS 13').
  • When describing formats (e.g., FQDN), mention Linux/macOS conventions and show examples.
  • Avoid using only Windows-centric terms (e.g., 'Windows domain\hostname') and instead use cross-platform terminology or provide parity.
Sentinel The Advanced Security Information Model (ASIM) DHCP normalization schema reference | Microsoft Docs ...ob/main/articles/sentinel/normalization-schema-dhcp.md
Low Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
🔧 Windows Tools Windows First Windows Heavy Examples
Summary
The documentation page exhibits mild Windows bias, primarily through references to Windows-specific fields and formats (e.g., Windows DHCP server, domain formats, and MAC address logging quirks). Windows terminology and examples (such as 'Contoso\DESKTOP-1282V4D', 'Windows' domain type, and SIDs) are given before or instead of Linux equivalents. There are no explicit Linux/Powershell-only examples, but the schema and field notes frequently reference Windows conventions and behaviors, with little mention of Linux or other DHCP server implementations.
Recommendations
  • Add explicit examples and notes for Linux and other non-Windows DHCP servers (e.g., ISC DHCP, Kea DHCP), including differences in field formats and logging.
  • Clarify how fields like MAC address, session ID, and domain are handled by Linux DHCP servers.
  • Provide Linux-specific sample values and scenarios alongside Windows examples.
  • Mention Linux domain and hostname conventions where Windows formats are discussed.
  • Include a section on cross-platform compatibility and mapping for key fields.
Sentinel The Advanced Security Information Model (ASIM) Network Session normalization schema reference | Microsoft Docs ...main/articles/sentinel/normalization-schema-network.md
Low Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows Examples Windows Format Reference
Summary
The documentation is largely platform-neutral, focusing on schema definitions and KQL usage. However, there are minor Windows biases: examples of hostnames and process names use Windows formats (e.g., 'C:\Windows\explorer.exe', 'DESKTOP-1282V4D'), and FQDN examples reference Windows domain\hostname format. Linux/macOS equivalents are not shown.
Recommendations
  • Include Linux/macOS examples alongside Windows ones for fields like Hostname, FQDN, and ProcessName (e.g., '/usr/bin/sshd', 'ubuntu-server', 'ubuntu.example.com').
  • Clarify that fields support non-Windows formats and provide explicit Linux/macOS sample values.
  • Where Windows-specific formats are referenced (e.g., domain\hostname), mention Linux/macOS conventions (e.g., FQDN, user@host).
Sentinel Microsoft Sentinel user management normalization schema reference | Microsoft Docs ...icles/sentinel/normalization-schema-user-management.md
Low Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First 🔧 Windows Tools
Summary
The documentation demonstrates a mild Windows bias, primarily in the ordering and examples of identifiers and naming conventions. Windows-specific formats (e.g., SID, domain\username) are consistently listed before Linux equivalents (e.g., UID, simple username), and Windows terminology is used as the default in field descriptions and examples. However, Linux and other platforms are referenced and supported throughout, with equivalent fields and normalization guidance provided.
Recommendations
  • Alternate the order of examples and supported formats so that Linux (UID, simple username) is sometimes listed first.
  • Provide explicit Linux/macOS examples alongside Windows ones for all fields (e.g., show both '4578' and 'S-1-5-...' for IDs, 'johndoe' and 'Contoso\johndoe' for usernames).
  • Clarify in field descriptions that Linux/macOS formats are equally supported and not secondary.
  • Add a note or section summarizing cross-platform support and parity, reassuring users that all major OSes are treated equally.
  • Where Windows-specific conversion advice is given (e.g., session ID conversion), provide parallel Linux/macOS guidance if relevant.
Sentinel Create Analytics Rules for Microsoft Sentinel Solutions .../articles/sentinel/sentinel-analytic-rules-creation.md
Low Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
🔧 Windows Tools Windows First
Summary
The documentation page exhibits mild Windows bias in the 'ID' section, where PowerShell's New-GUID cmdlet is mentioned as a way to generate GUIDs, with no mention of Linux/macOS alternatives. Windows tooling is referenced first and exclusively in this context, potentially causing friction for non-Windows users. The rest of the documentation is platform-neutral and does not show further bias.
Recommendations
  • In the 'ID' section, add Linux/macOS alternatives for GUID generation, such as 'uuidgen' (available on most Unix-like systems) or Python's 'uuid' module.
  • Present platform-neutral or cross-platform options first, e.g., 'You can generate a GUID using tools such as uuidgen (Linux/macOS), PowerShell's New-GUID cmdlet (Windows), or online generators.'
  • Wherever platform-specific tools are mentioned, provide equivalent commands or instructions for other major platforms.
Sentinel Scheduled analytics rules in Microsoft Sentinel | Microsoft Docs ...lob/main/articles/sentinel/scheduled-rules-overview.md
Low Priority View Details →
Scanned: 2026-01-12 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
🔧 Windows Tools Windows First Missing Linux Example
Summary
The documentation page for scheduled analytics rules in Microsoft Sentinel demonstrates a mild Windows bias. In the 'Next steps' section, PowerShell is mentioned as a primary automation tool for enabling rules, with no mention of Linux/macOS equivalents (such as Bash, Azure CLI, or cross-platform scripting). Windows tools (PowerShell) are referenced before any cross-platform alternatives, and there are no examples or guidance for Linux/macOS users on how to perform equivalent tasks. The rest of the documentation is generally platform-neutral, focusing on portal UI and Kusto queries, which are cross-platform.
Recommendations
  • Include Azure CLI examples for automation tasks alongside PowerShell, as Azure CLI is cross-platform and works on Linux/macOS.
  • Explicitly mention that PowerShell Core is available on Linux/macOS, or provide Bash scripting examples for exporting/enabling rules.
  • Add a note or section on how Linux/macOS users can automate rule management, referencing relevant tools and commands.
  • Where possible, avoid listing Windows tools first; present cross-platform options together.