Sad Tux - Windows bias detected
This page contains Windows bias

About This Page

This page is part of the Azure documentation. It contains code examples and configuration instructions for working with Azure services.

Bias Analysis

Detected Bias Types
powershell_heavy
windows_tools
Summary
The documentation references PowerShell and Windows-specific alerts (such as 'Windows Error and Warning Events', 'Suspicious PowerShell command line', and 'PowerShell made a suspicious network connection') as examples of malicious activity and detection scenarios. These examples and references may create a perception that multistage attack detection in Microsoft Sentinel is primarily focused on Windows environments and tooling, with little mention of Linux/macOS equivalents or examples.
Recommendations
  • Include examples of multistage attack scenarios involving Linux/macOS hosts, such as suspicious Bash commands, Linux-specific malware, or SSH brute-force attempts.
  • Reference Linux/macOS system events and logs (e.g., syslog, auditd, systemd journal) as possible sources for detection, alongside Windows events.
  • Add detection scenarios that highlight attacks leveraging Linux/macOS tools (e.g., suspicious use of curl/wget, cron jobs, or sudo activity).
  • Clarify that Fusion can correlate signals from non-Windows sources and provide guidance or examples for integrating Linux/macOS data connectors.
GitHub Create Pull Request

Scan History

Date Scan Status Result
2026-01-14 00:00 #250 in_progress Biased Biased
2026-01-13 00:00 #246 completed Biased Biased
2026-01-11 00:00 #240 completed Biased Biased
2026-01-10 00:00 #237 completed Biased Biased
2026-01-09 00:34 #234 completed Biased Biased
2026-01-08 00:53 #231 completed Biased Biased
2026-01-06 18:15 #225 cancelled Clean Clean
2025-08-17 00:01 #83 cancelled Clean Clean
2025-07-13 21:37 #48 completed Biased Biased
2025-07-12 23:44 #41 cancelled Biased Biased