771
Total Pages
720
Linux-Friendly Pages
51
Pages with Bias
6.6%
Bias Rate

Bias Trend Over Time

Pages with Bias Issues

90 issues found
Showing 76-90 of 90 flagged pages
Sentinel Connect your SAP system to Microsoft Sentinel | Microsoft Sentinel .../sentinel/sap/deploy-data-connector-agent-container.md
Low Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First Missing Linux Example
Summary
The documentation page demonstrates a mild Windows bias by presenting Azure portal and CLI examples and instructions that are platform-agnostic but implicitly assume Windows/Azure environments. Linux is referenced (e.g., Ubuntu VM creation), but there are no explicit Linux/macOS-specific examples or troubleshooting steps. The use of Azure CLI and portal is cross-platform, but the order of presentation and lack of Linux/macOS parity in examples may create minor friction for non-Windows users.
Recommendations
  • Add explicit Linux/macOS terminal examples for agent installation and troubleshooting.
  • Include notes or sections on deploying and managing the connector agent on Linux and macOS systems, including common issues and solutions.
  • Provide parity in screenshots and walkthroughs for Linux/macOS environments, not just Azure portal.
  • Clarify that Azure CLI commands work on Linux/macOS and provide links to installation instructions for those platforms.
  • Mention alternative container runtimes or management tools for Linux/macOS if relevant.
Sentinel Common Event Format (CEF) key and CommonSecurityLog field mapping ...e-docs/blob/main/articles/sentinel/cef-name-mapping.md
Low Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows Terms Windows Examples Windows Fields
Summary
The documentation page is largely platform-neutral, focusing on mapping CEF keys to Microsoft Sentinel's CommonSecurityLog fields. However, there are several instances of Windows bias: (1) Windows-specific terms such as 'deviceNtDomain', 'DestinationNTDomain', and 'SourceNTDomain' are present, (2) file path examples show Windows paths (e.g., 'C:\ProgramFiles\WindowsNT\Accessories\wordpad.exe') before Linux equivalents, and (3) some field descriptions reference Windows domains without mentioning Linux alternatives. No PowerShell or Windows-only tools are referenced, and Linux/UNIX is mentioned in some places (e.g., process names), but Windows terminology and examples are slightly prioritized.
Recommendations
  • Ensure file path examples always show both Windows and Linux formats, alternating which comes first.
  • For fields referencing Windows domains (e.g., NTDomain), clarify Linux/UNIX equivalents or note when not applicable.
  • Add explicit notes where a field is Windows-specific and suggest Linux/UNIX alternatives if relevant.
  • Review all examples and descriptions to ensure Linux/UNIX is equally represented alongside Windows.
Sentinel Create a codeless connector for Microsoft Sentinel ...ob/main/articles/sentinel/create-codeless-connector.md
Low Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First Powershell Heavy
Summary
The documentation page exhibits mild Windows bias in its API testing tool recommendations, listing PowerShell and Visual Studio Code before Linux-native tools like curl and Bruno. PowerShell is specifically called out as an example, and Visual Studio Code is referenced with a Marketplace extension, which is more common on Windows. No Linux-specific shell (e.g., bash) or Linux-centric tools (e.g., httpie) are mentioned. However, curl is included, and most instructions are platform-neutral, focusing on ARM templates and REST APIs.
Recommendations
  • List Linux/macOS tools (e.g., curl, httpie, bash scripts) before or alongside Windows tools in API testing recommendations.
  • Include explicit Linux/macOS command-line examples for API calls (e.g., using curl or httpie).
  • Mention Linux-native editors (e.g., Vim, nano) or cross-platform editors (e.g., VS Code, Sublime Text) rather than only Visual Studio Code.
  • Clarify that all steps can be performed on Linux/macOS and Windows, and provide troubleshooting notes for common platform differences.
  • Add a note that PowerShell is available cross-platform, but also provide bash/zsh alternatives.
Sentinel Create scheduled analytics rules in Microsoft Sentinel | Microsoft Docs .../blob/main/articles/sentinel/create-analytics-rules.md
Low Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
🔧 Windows Tools Powershell Heavy Windows First
Summary
The documentation page demonstrates mild Windows bias, primarily in the 'Next steps' section, where PowerShell is mentioned as a primary automation method for enabling rules, with no equivalent Linux/macOS CLI (such as Azure CLI or Bash) examples or references. The documentation refers to Microsoft portals (Defender, Azure), which are web-based and cross-platform, but when discussing automation, it only references PowerShell and omits Linux-native tools. Additionally, PowerShell is mentioned before API, reinforcing Windows-first patterns. No explicit Linux/macOS examples or tools are provided for automation or scripting.
Recommendations
  • Include Azure CLI examples alongside PowerShell for automation tasks, especially for enabling rules or exporting/importing them.
  • Mention Bash scripting or other cross-platform approaches for rule management.
  • Clarify that PowerShell Core is available cross-platform, but also provide direct Linux/macOS instructions where possible.
  • Add links or references to Linux/macOS compatible tools for Sentinel automation.
  • When listing automation options, present API and CLI methods before or alongside PowerShell to avoid Windows-first ordering.
Sentinel Data connector definitions reference for the Codeless Connector Framework ...es/sentinel/data-connector-ui-definitions-reference.md
Low Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
🔧 Windows Tools Windows First
Summary
The documentation page is generally cross-platform, but there is mild Windows bias in the references and examples. The only explicit connector example linked is for Windows DNS, and the 'InstallAgent' section lists Windows agent installation link types before Linux equivalents. No Linux/macOS-specific examples or references are provided, and the sample code and walkthroughs are platform-neutral but do not demonstrate Linux parity.
Recommendations
  • Include explicit Linux/macOS connector examples, such as links to Linux data connector templates or walkthroughs.
  • Alternate the order of Windows and Linux references in lists and examples to avoid implicit prioritization.
  • Provide sample JSON and screenshots for Linux-based connectors alongside Windows examples.
  • Reference Linux/macOS agent installation documentation and tools equally, and provide links to their respective GitHub templates.
Sentinel Microsoft Sentinel entity types reference | Microsoft Docs ...docs/blob/main/articles/sentinel/entities-reference.md
Low Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
🔧 Windows Tools Windows First
Summary
The documentation page exhibits mild Windows bias through the use of Windows-specific terminology and concepts, such as NTDomain, NetBiosName, SID, and registry keys/values, which are all Windows-centric constructs. These identifiers and schema fields are described and listed before their Linux/macOS equivalents (if any), and there is little to no mention of Linux/macOS-specific patterns or identifiers. The examples and explanations focus on Windows attributes, with Linux/macOS only referenced in the OSFamily enumeration and OSVersion field, without further detail or parity in examples.
Recommendations
  • Add explicit examples and explanations for Linux and macOS entity attributes, such as user/group identifiers, host naming conventions, and file system constructs.
  • Include Linux/macOS-specific fields or mapping guidance where applicable (e.g., UID/GID for accounts, /etc/passwd for user accounts, hostname conventions, file attributes).
  • Balance the order and prominence of Windows and non-Windows identifiers in tables and schema descriptions.
  • Provide cross-platform mapping tables or notes for fields that are Windows-only, indicating Linux/macOS equivalents or how to handle them in those environments.
Sentinel The Advanced Security Information Model (ASIM) Audit Events normalization schema reference | Microsoft Docs ...b/main/articles/sentinel/normalization-schema-audit.md
Low Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows Examples Windows Terms Windows Domain Format
Summary
The documentation is largely platform-neutral, focusing on schema definitions and KQL usage. However, there are subtle Windows biases: examples of hostnames use Windows-style names (e.g., 'DESKTOP-1282V4D'), domain formats are described as 'Windows domain\hostname', and username types include 'Windows' as an example. Application paths use Windows-style (e.g., 'C:\Windows\System32\svchost.exe'). No Linux/macOS-specific examples or terminology are provided, and Linux-style hostnames, usernames, or application paths are absent.
Recommendations
  • Add Linux/macOS examples alongside Windows ones (e.g., show hostnames like 'ubuntu-server', application paths like '/usr/bin/sshd', and usernames like 'alice').
  • Explicitly mention that fields support Linux/macOS formats where relevant (e.g., FQDN, username types, application paths).
  • Include Linux/macOS-specific values in enumerated fields (e.g., 'Linux', 'macOS' for ActorUsernameType).
  • Clarify that the schema is OS-agnostic and provide guidance for mapping Linux/macOS audit events.
Sentinel The Advanced Security Information Model (ASIM) DNS normalization schema reference | Microsoft Docs ...lob/main/articles/sentinel/normalization-schema-dns.md
Low Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Windows Heavy Examples
Summary
The documentation demonstrates a mild Windows bias, primarily through the use of Windows-centric terminology, examples, and field values. Windows domain formats (domain\hostname), Windows-specific field values (e.g., 'Windows' for domain type, SIDs for user IDs), and Windows process paths (C:\Windows\explorer.exe) are shown first or exclusively in examples. Linux equivalents are mentioned only briefly or as afterthoughts, and examples are not provided for Linux/macOS formats. There is no explicit Powershell or Windows-only tooling, but the schema and examples are clearly oriented toward Windows environments.
Recommendations
  • Include Linux/macOS-specific examples alongside Windows examples for fields like hostnames, process names, and user IDs.
  • Document Linux/macOS domain and username formats (e.g., FQDN, UID, /usr/bin/bash) in the same detail as Windows formats.
  • Provide sample values and scenarios for Linux/macOS in tables and field descriptions.
  • Clarify that the schema is platform-agnostic and explicitly state how Linux/macOS sources should map their data.
  • Add guidance for handling discrepancies or conversions from Linux/macOS systems (e.g., process IDs, file paths, user identifiers).
Sentinel The Advanced Security Information Model (ASIM) File Event normalization schema reference| Microsoft Docs ...n/articles/sentinel/normalization-schema-file-event.md
Low Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Minor Windows Examples
Summary
The documentation provides a cross-platform schema for file event normalization, referencing both Windows and Unix/Linux systems. However, Windows examples and terminology are presented first and more frequently, such as in file path examples, process names, and user/domain formats. Windows-specific tools and patterns (e.g., 'Windows File Explorer', 'C:\Windows\explorer.exe', 'S-1-12', 'Contoso\DESKTOP-1282V4D') are used as primary illustrations, with Linux/Unix equivalents included but less emphasized and usually after Windows references.
Recommendations
  • Alternate Windows and Linux/Unix examples throughout the documentation, especially in tables and illustrative sections.
  • Provide equal emphasis and detail for Linux/Unix file paths, process names, and user/domain formats.
  • Include Linux/Unix-specific tools or patterns (e.g., 'nautilus', '/usr/bin/bash', UID/GID formats) alongside Windows examples.
  • Clarify cross-platform applicability in introductory sections, explicitly stating parity and differences.
  • Ensure that all examples and notes referencing Windows also provide Linux/Unix equivalents where relevant.
Sentinel Jupyter notebooks with Microsoft Sentinel hunting capabilities ...cs/azure-docs/blob/main/articles/sentinel/notebooks.md
Low Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
🔧 Windows Tools Windows First
Summary
The documentation page is generally cross-platform in its discussion of Jupyter notebooks and Python packages, but it shows mild Windows bias by referencing PowerShell as a management option before Linux equivalents and by focusing on Azure portal-based workflows (which are most commonly used on Windows). The mention of PowerShell in the permissions section appears before Azure CLI and REST API, and there is no explicit mention of Linux/macOS-specific tools or considerations. However, the core notebook functionality is inherently cross-platform, and most examples are generic.
Recommendations
  • List Azure CLI before PowerShell when describing management options, or present both equally.
  • Explicitly mention that Jupyter notebooks and MSTICPy work on Linux and macOS, not just in Azure portal.
  • Provide examples or links for managing roles and permissions using Linux/macOS tools (e.g., Bash scripts, Azure CLI on Linux).
  • Add a note clarifying that the described workflows are accessible from any OS with a browser and Python/Jupyter installed.
Sentinel Microsoft Sentinel network normalization schema (Legacy version - Public preview)| Microsoft Docs ...blob/main/articles/sentinel/normalization-schema-v1.md
Low Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
🔧 Windows Tools Windows First
Summary
The documentation page exhibits mild Windows bias, primarily through the use of Windows-centric terminology and examples. Several field examples reference Windows-specific concepts (e.g., 'Ethernet adapter Ethernet 4', 'C:\Malicious\ImNotMalicious.exe', 'WORKGROUP', 'DESKTOP', 'S-12-1445' for SID, and user agent strings referencing 'Windows NT'). Windows-style file paths and device/domain names are used in examples, and Windows terminology appears before or instead of Linux/macOS equivalents. However, the schema itself is generic and not technically limited to Windows, and Linux/macOS-relevant terms (e.g., 'eth0', 'syslogserver1.contoso.com') do appear.
Recommendations
  • Add Linux/macOS equivalent examples alongside Windows examples (e.g., use '/home/malicious/ImNotMalicious.sh' as a file path, 'eth0' or 'enp0s3' for network interfaces, 'ubuntu' or 'macbook.local' for hostnames).
  • Avoid using Windows-specific domain names like 'WORKGROUP' or 'DESKTOP' exclusively; include examples like 'ubuntu', 'local', or 'default'.
  • Where SIDs are referenced, note that these are Windows-specific and provide examples of Linux/macOS user IDs (e.g., UID/GID).
  • Balance user agent strings to include macOS/Linux browsers.
  • Clarify that the schema is OS-agnostic and provide guidance for mapping Linux/macOS concepts to the schema fields.
Sentinel Scheduled analytics rules in Microsoft Sentinel | Microsoft Docs ...lob/main/articles/sentinel/scheduled-rules-overview.md
Low Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First Powershell Heavy Missing Linux Example
Summary
The documentation page for scheduled analytics rules in Microsoft Sentinel exhibits mild Windows bias. In the 'Next steps' section, PowerShell is mentioned as a primary method for automating rule enablement, with no mention of Linux/macOS equivalents (such as Bash, Azure CLI, or cross-platform scripting). PowerShell is referenced before API, and no Linux-specific tools or examples are provided. There are no explicit Windows-only instructions, but the lack of Linux/macOS parity in automation guidance may create friction for non-Windows users.
Recommendations
  • Include examples using Azure CLI for rule automation, which is cross-platform.
  • Mention Bash scripting and provide sample scripts for exporting/importing rules on Linux/macOS.
  • Clarify that PowerShell Core is available cross-platform, or link to instructions for installing and using PowerShell on Linux/macOS.
  • Provide parity in automation instructions by showing both PowerShell and Azure CLI methods side-by-side.
  • Explicitly state that all API operations can be performed from any OS, and link to relevant REST API usage guides.
Sentinel Create Analytics Rules for Microsoft Sentinel Solutions .../articles/sentinel/sentinel-analytic-rules-creation.md
Low Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
🔧 Windows Tools Windows First
Summary
The documentation page demonstrates mild Windows bias by referencing the PowerShell New-GUID cmdlet as a method for generating GUIDs, mentioning it before any Linux or cross-platform alternatives. No Linux-specific tools or examples are provided for this step, and no parity is offered for macOS or Linux users. However, the rest of the documentation is platform-neutral and does not rely on Windows-specific tooling or patterns.
Recommendations
  • When suggesting GUID generation, include platform-neutral options first, such as online GUID generators or cross-platform CLI tools (e.g., 'uuidgen' on Linux/macOS).
  • Explicitly mention Linux/macOS equivalents for tasks like GUID generation (e.g., 'uuidgen' command, Python's uuid module).
  • Avoid referencing Windows tools (such as PowerShell cmdlets) exclusively or before cross-platform alternatives.
  • Provide example commands for Linux/macOS alongside any Windows-specific examples.
Sentinel Discover and deploy Microsoft Sentinel out-of-the-box content from Content hub ...ob/main/articles/sentinel/sentinel-solutions-deploy.md
Low Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First Missing Linux Example
Summary
The documentation page focuses on Microsoft Sentinel's Content hub and provides instructions and examples primarily through the Azure portal and Defender portal interfaces. When mentioning automation or API-based deployments, it references ARM template deployment via REST API, Azure CLI, or PowerShell, but does not provide explicit Linux/macOS CLI examples or clarify parity. There is no mention of Linux-specific tools, nor are Linux/macOS workflows or screenshots included. The order of mention (PowerShell after Azure CLI) is neutral, but the lack of explicit Linux/macOS guidance or examples creates a subtle Windows-first bias.
Recommendations
  • Add explicit Linux/macOS CLI examples for ARM template deployment (e.g., bash scripts, Azure CLI usage on Linux).
  • Clarify that Azure CLI commands work cross-platform and provide sample commands for Linux/macOS environments.
  • Include notes or screenshots showing the experience on Linux/macOS where relevant.
  • Mention any platform-specific considerations for Linux/macOS users when using the API or automation templates.
  • Ensure parity in instructions for automation, not just referencing PowerShell.
Sentinel Use matching analytics to detect threats ...s/sentinel/use-matching-analytics-to-detect-threats.md
Low Priority View Details →
Scanned: 2026-01-11 06:20
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First 🔧 Windows Tools
Summary
The documentation page demonstrates a mild Windows bias: Windows-specific tools (Windows DNS, Windows Firewall) are listed before Linux equivalents, and Windows-centric solutions are more prominent in examples and connector tables. However, Linux-compatible options (Syslog, CEF) are included, and no critical functionality is Windows-only.
Recommendations
  • Present Linux-compatible connectors (Syslog, CEF) before or alongside Windows connectors in lists and tables.
  • Add explicit examples or references for Linux data sources and connectors, such as Linux DNS logs or Linux firewall logs, if supported.
  • Clarify cross-platform compatibility for each connector and solution.
  • Include screenshots or walkthroughs from Linux environments where applicable.
← Previous Page 4 of 4 Next →