Sad Tux - Windows bias detected
This page contains Windows bias

About This Page

This page is part of the Azure documentation. It contains code examples and configuration instructions for working with Azure services.

Bias Analysis

Detected Bias Types
windows_first
missing_linux_example
windows_tools
powershell_heavy
Summary
The documentation page demonstrates a significant Windows bias. Most anomaly detection examples and machine learning models are based on Windows Security logs (e.g., Event IDs 4624 and 4625) and Windows-specific account activities. There is frequent mention of Windows tools and patterns (such as PowerShell and Windows Security logs), with no equivalent Linux or Unix log sources (e.g., syslog, auth.log, auditd) or examples. Linux-specific account creation, authentication, or brute force detection scenarios are missing, and there are no references to Linux command interpreters (e.g., Bash, sh) in code execution anomalies. The documentation assumes a Windows-centric environment for local account and authentication anomalies, and does not provide parity for Linux environments.
Recommendations
  • Add equivalent Linux/Unix anomaly detection examples, such as monitoring /var/log/auth.log, /var/log/secure, or auditd logs for account creation, deletion, and authentication anomalies.
  • Include Linux command and script interpreter sub-techniques (e.g., Bash, sh, Python) in code execution anomaly descriptions.
  • Provide details on how Sentinel can ingest and analyze Linux security logs for brute force, privilege escalation, and suspicious login anomalies.
  • Reference Linux-specific MITRE ATT&CK techniques and sub-techniques where applicable.
  • Ensure that examples and descriptions do not prioritize Windows tools and logs over Linux equivalents, and present both platforms equally where possible.
GitHub Create Pull Request

Scan History

Date Scan Status Result
2026-01-22 01:38 #286 completed Biased Biased
2026-01-14 00:00 #250 in_progress Biased Biased
2026-01-13 00:00 #246 completed Biased Biased
2026-01-11 00:00 #240 completed Biased Biased
2026-01-10 00:00 #237 completed Biased Biased
2026-01-09 00:34 #234 completed Biased Biased
2026-01-08 00:53 #231 completed Biased Biased
2026-01-06 18:15 #225 cancelled Clean Clean
2025-09-09 00:00 #106 completed Clean Clean
2025-08-17 00:01 #83 cancelled Clean Clean
2025-07-13 21:37 #48 completed Clean Clean
2025-07-12 23:44 #41 cancelled Clean Clean