Detected Bias Types
Windows First
🔧
Windows Tools
Summary
The documentation references Windows as an example OS in several places (e.g., 'Windows sends several authentication events'), and field examples often use Windows-centric formats (such as domain\hostname, SIDs, and Windows process paths). Windows terminology (NTLM, SID, svchost.exe, domain\hostname) is used preferentially or exclusively in examples, with Linux/macOS equivalents not mentioned. However, the schema itself is designed to be cross-platform and references generic concepts (e.g., 'domain controllers', 'VPN gateways', 'firewall'), and does not appear to exclude Linux/macOS systems from use.
Recommendations
- Add Linux/macOS-specific examples alongside Windows examples (e.g., show Linux usernames, process paths, authentication protocols like Kerberos, SSH, or PAM).
- When describing fields such as Hostname, Username, or OS, include Linux/macOS formats and values (e.g., /usr/bin/sshd, UID/GID, user@domain, etc.).
- Clarify that the schema supports authentication events from non-Windows systems and provide explicit guidance or references for integrating Linux/macOS sources.
- In field descriptions, mention Linux/macOS equivalents for Windows-centric terms (e.g., mention Kerberos alongside NTLM, or Linux UIDs alongside SIDs).