Bias Analysis
Detected Bias Types
powershell_heavy
windows_tools
windows_examples
missing_linux_example
Summary
The documentation page demonstrates a notable Windows bias, especially in the Process Activity section, where many hunting queries and analytics rules focus on Windows-specific tools (PowerShell, rundll32.exe, certutil, etc.) and attack patterns. There is a lack of Linux/macOS-specific examples, tools, or queries, and no parity for Linux process, file, or session activity is provided. The registry activity section is inherently Windows-centric, and most examples reference Windows-centric threats and utilities. No Linux-specific content, such as bash scripts, Linux process monitoring, or Linux-specific threat detection, is present.
Recommendations
- Add Linux/macOS-specific analytics rules and hunting queries, e.g., detection of suspicious bash scripts, cron jobs, or Linux persistence techniques.
- Include examples for Linux process activity (e.g., monitoring suspicious use of systemd, bash, python, or SSH).
- Provide parity for file activity and session monitoring on Linux/macOS, such as detection of suspicious file changes or network connections.
- Explicitly mention Linux/macOS equivalents for Windows tools (e.g., use of curl/wget instead of PowerShell for downloads, Linux system logs instead of Windows Event Logs).
- Balance examples between Windows and Linux/macOS, or clearly indicate platform applicability for each rule/query.
Create Pull Request