391
Total Pages
285
Linux-Friendly Pages
106
Pages with Bias
27.1%
Bias Rate

Bias Trend Over Time

Pages with Bias Issues

488 issues found
Showing 301-325 of 488 flagged pages
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/sentinel-playbook-creation.md ...b/main/articles/sentinel/sentinel-playbook-creation.md
High Priority View Details →
Scanned: 2025-07-12 23:44
Reviewed by: Unknown
Issues: 4 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Missing Linux Example Windows First
Summary
The documentation demonstrates a Windows bias by exclusively providing instructions and tooling based on PowerShell scripts, referencing Windows PowerShell and Visual Studio Code as editors, and instructing users to run commands such as Set-ExecutionPolicy that are specific to Windows environments. There is no mention of Linux or cross-platform alternatives for script execution, nor are there examples or guidance for users on Linux or macOS. All automation and scripting guidance assumes a Windows-centric workflow.
Recommendations
  • Provide explicit instructions for running the PowerShell script on Linux and macOS, including prerequisites (such as installing PowerShell Core and setting execution policy equivalents).
  • Mention and demonstrate the use of cross-platform editors (e.g., VS Code on Linux/macOS, nano, vim) for editing scripts.
  • Include alternative shell commands or instructions for users who prefer Bash or other shells, or clarify that the script is compatible with PowerShell Core on all platforms.
  • Add notes or examples for Linux/macOS users, such as how to download and run the script, and how to handle permissions.
  • Avoid referencing only Windows-specific tools (e.g., 'Windows PowerShell') and instead use neutral or cross-platform terminology (e.g., 'PowerShell Core').
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/top-workbooks.md ...zure-docs/blob/main/articles/sentinel/top-workbooks.md
High Priority View Details →
Scanned: 2025-07-12 23:44
Reviewed by: Unknown
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Missing Linux Example
Summary
The documentation page exhibits a Windows-first bias, with several workbooks and descriptions focused specifically on Windows technologies (e.g., Windows Event Log analysis, Windows Security Events, Microsoft products). There is a lack of explicit mention or examples for Linux or non-Windows environments, and no Linux-specific workbooks or equivalent monitoring scenarios are highlighted. The language and examples assume a Microsoft/Windows-centric environment, and Linux or cross-platform considerations are missing.
Recommendations
  • Add examples or descriptions of workbooks that specifically address Linux log sources (e.g., syslog, auditd, Linux authentication logs) and their monitoring in Microsoft Sentinel.
  • Include Linux-focused or cross-platform workbooks in the table, or clarify which existing workbooks are applicable to Linux data sources.
  • Where Windows-specific tools or logs are mentioned (such as Windows Event Log), provide equivalent Linux log types and describe how they can be monitored using Sentinel workbooks.
  • Explicitly mention support for non-Windows environments and provide guidance or links for users managing Linux or hybrid infrastructures.
  • Balance the documentation by ensuring that both Windows and Linux (and other platforms, where relevant) are represented in examples, terminology, and recommended practices.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/ueba-reference.md ...ure-docs/blob/main/articles/sentinel/ueba-reference.md
High Priority View Details →
Scanned: 2025-07-12 23:44
Reviewed by: Unknown
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Missing Linux Example
Summary
The documentation displays a Windows bias by focusing on Windows Security events as the only explicit OS event source, referencing Windows-specific event IDs, and listing 'Windows' as the only device family and OS in enrichment examples. There are no examples or mentions of Linux or macOS event sources, device types, or OSes, and no guidance for integrating non-Windows data. This may lead readers to believe that UEBA is primarily or exclusively for Windows environments.
Recommendations
  • Add explicit mention of Linux and macOS as potential data sources for UEBA, if supported.
  • Provide examples of Linux (e.g., syslog, auditd) and macOS event sources and how to onboard them to Microsoft Sentinel.
  • Include Linux/macOS device types and operating systems in enrichment sample values and tables.
  • Clarify whether non-Windows events are supported or not, and provide guidance for customers with heterogeneous environments.
  • If Linux/macOS are not supported, state this explicitly to set expectations.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/stix-objects-api.md ...e-docs/blob/main/articles/sentinel/stix-objects-api.md
High Priority View Details →
Scanned: 2025-07-12 23:44
Reviewed by: Unknown
Issues: 3 bias types
Detected Bias Types
Powershell Heavy Missing Linux Example 🔧 Windows Tools
Summary
The documentation provides a detailed PowerShell function as the only example for programmatically calling the upload API, relying on the MSAL.PS PowerShell module and Windows certificate store paths. There are no equivalent examples for Linux or cross-platform scripting environments such as Bash/cURL or Python. This focus on PowerShell and Windows-specific tooling may hinder Linux users or those working in non-Windows environments.
Recommendations
  • Add equivalent example(s) for Linux environments, such as using Bash with cURL or Python scripts leveraging the MSAL or requests libraries.
  • Demonstrate how to handle authentication and certificate management in a cross-platform way (e.g., using PEM files instead of Windows certificate store).
  • Explicitly mention that the API can be accessed from any platform and provide at least one non-Windows example before or alongside the PowerShell example.
  • Reference cross-platform tools (e.g., OpenSSL, cURL, Python) where appropriate, not just Windows/PowerShell modules.
  • Clarify any platform-specific requirements or differences in the authentication/token acquisition process.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/use-matching-analytics-to-detect-threats.md ...s/sentinel/use-matching-analytics-to-detect-threats.md
High Priority View Details →
Scanned: 2025-07-12 23:44
Reviewed by: Unknown
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Missing Linux Example
Summary
The documentation page demonstrates a Windows bias by listing Windows-specific solutions (e.g., Windows DNS, Windows Firewall) before or more prominently than their Linux equivalents, and by referencing Windows tools and patterns (such as Windows DNS logs and Windows Firewall) without providing equivalent Linux examples or guidance. While Syslog and CEF are mentioned (which are cross-platform), there is a lack of parity in examples or detailed steps for Linux environments, and no Linux-specific tools (such as iptables, nftables, or Linux DNS logs) are referenced.
Recommendations
  • Add explicit Linux-focused examples, such as how to ingest and match Linux DNS logs (e.g., from BIND or systemd-resolved) and Linux firewall logs (e.g., iptables, nftables) into Sentinel.
  • Provide parity in the solution and connector tables by including Linux-specific sources and connectors alongside Windows ones.
  • When listing data sources or connectors, avoid always listing Windows sources first; alternate or group by platform.
  • Include screenshots or walkthroughs that show Linux log ingestion and matching analytics, not just Windows-centric examples.
  • Reference Linux-native tools and patterns where appropriate, and provide guidance for both Windows and Linux environments.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/unified-connector-custom-device.md ...n/articles/sentinel/unified-connector-custom-device.md
High Priority View Details →
Scanned: 2025-07-12 23:44
Reviewed by: Unknown
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Missing Linux Example
Summary
The documentation generally provides both Windows and Linux examples for log file locations where applicable, but there is a consistent pattern of listing Windows file paths before Linux equivalents (windows_first). In some cases, such as NGINX HTTP Server and SecurityBridge Threat Detection for SAP, only Linux examples are provided, but there are no cases where only Windows examples are given. There is no evidence of PowerShell-heavy or Windows-only tooling; the syslog configuration and command-line instructions are Linux-centric. However, the documentation sometimes refers to Windows tools or patterns first, and in a few cases, Linux-only applications are not mirrored with Windows examples (missing_linux_example).
Recommendations
  • Alternate the order of Windows and Linux examples throughout the documentation to avoid always listing Windows first.
  • Where possible, provide both Windows and Linux examples for all applications, or explicitly state when an application is only available on one platform.
  • Ensure parity in detail and clarity between Windows and Linux instructions, including configuration file names and example paths.
  • Consider adding PowerShell or Windows command-line equivalents for syslog configuration steps if relevant for Windows-based syslog servers.
  • Add a summary table at the top of the document indicating platform support for each application, clarifying which are Linux-only or Windows-only.
Sentinel Anomalies detected by the Microsoft Sentinel machine learning engine ...ocs/blob/main/articles/sentinel/anomalies-reference.md
Medium Priority View Details →
Scanned: 2026-01-22 01:38
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First Missing Linux Example 🔧 Windows Tools
Summary
The documentation page describes anomaly detection features in Microsoft Sentinel, referencing a variety of data sources including Azure, AWS, GCP, Okta, and Office logs. However, there is a notable bias toward Windows environments: many anomaly types and detection algorithms are based exclusively on Windows Security logs (e.g., event IDs 4624 and 4625), with no mention of equivalent Linux/macOS log sources or examples. The documentation does not provide guidance or parity for Linux/macOS systems, nor does it mention how to enable similar anomaly detection for non-Windows hosts. Windows-specific tools and event patterns are referenced without Linux alternatives.
Recommendations
  • Add sections or notes describing how Linux/macOS systems can be monitored for similar anomalies (e.g., using syslog, auditd, or other Linux-native logging sources).
  • Provide equivalent Linux/macOS log event IDs or patterns for account creation, deletion, logon, and brute-force attempts.
  • Clarify whether Sentinel supports anomaly detection for Linux/macOS hosts and, if so, document the required data connectors and log formats.
  • Where Windows Security logs are referenced, add Linux/macOS examples or mention their absence if not supported.
  • Consider including cross-platform examples or a table mapping Windows events to Linux/macOS equivalents.
Sentinel The Advanced Security Information Model (ASIM) Process Event normalization schema reference | Microsoft Docs ...rticles/sentinel/normalization-schema-process-event.md
Medium Priority View Details →
Scanned: 2026-01-22 01:38
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First Windows Examples Windows Terms
Summary
The documentation for the ASIM Process Event normalization schema is designed to be cross-platform and references support for both Windows and Linux systems. However, there is a noticeable Windows bias in the examples and terminology: most example process names and paths use Windows conventions (e.g., C:\Windows\explorer.exe), integrity levels are described only in terms of Windows, and links to further reading about process integrity reference Windows-specific documentation. Linux is mentioned as supported in some field notes, but Linux-specific examples, terminology, or links are absent.
Recommendations
  • Add Linux/macOS process examples alongside Windows ones (e.g., /usr/bin/bash, /usr/bin/sshd).
  • Describe process integrity and privilege concepts for Linux/macOS (e.g., user/group IDs, capabilities, SELinux contexts) or clarify that some fields are Windows-only.
  • Include Linux/macOS-specific notes or links where relevant (e.g., for process creation, integrity, or privilege elevation).
  • Balance example paths and process names between Windows and Linux/macOS.
  • Clarify in field descriptions which concepts are OS-specific and provide cross-platform guidance.
Sentinel Manage custom content with repository connections ...cs/blob/main/articles/sentinel/ci-cd-custom-content.md
Medium Priority View Details →
Scanned: 2026-01-16 00:00
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Windows First Missing Linux Example
Summary
The documentation page for managing custom content with repository connections in Microsoft Sentinel demonstrates a notable Windows bias. PowerShell scripts and utilities are referenced as the primary or sole tooling for converting and exporting content types (analytic rules, automation rules, playbooks, etc.), with minimal or no mention of Linux/macOS equivalents. In several cases, PowerShell is listed before Azure CLI, and some content types lack any non-Windows export/conversion guidance. There are no Bash, shell, or cross-platform examples provided, and the workflow customization section refers to PowerShell deployment scripts without alternatives.
Recommendations
  • Provide equivalent Azure CLI, Bash, or cross-platform examples for all major tasks, especially for exporting and converting content.
  • When referencing scripts or utilities, indicate platform compatibility and offer alternatives for Linux/macOS users.
  • List Azure CLI or other cross-platform tools before PowerShell when both are supported.
  • Expand documentation to include instructions for Linux/macOS environments, such as using shell scripts or Docker containers for automation.
  • Clarify which steps are Windows-specific and which are platform-agnostic.
Sentinel Anomalies detected by the Microsoft Sentinel machine learning engine ...ocs/blob/main/articles/sentinel/anomalies-reference.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First Missing Linux Example 🔧 Windows Tools
Summary
The documentation page for 'Anomalies detected by the Microsoft Sentinel machine learning engine' exhibits moderate Windows bias. Many anomaly detection rules and examples reference Windows Security logs (e.g., Event IDs 4624, 4625) and local account creation on Windows systems, with no equivalent examples or guidance for Linux or macOS systems. There are no Linux audit log or syslog-based anomaly rules, and the documentation does not mention Linux-specific data sources or detection patterns. Windows-centric terminology and event IDs are used exclusively in several sections, and Linux/macOS users are left without clear instructions on how to achieve parity.
Recommendations
  • Add examples and descriptions for anomaly detection using Linux audit logs (e.g., /var/log/auth.log, /var/log/secure, auditd) and macOS system logs.
  • Include Linux/macOS equivalents for local account creation, login events, and brute force detection (e.g., using PAM logs, SSH logs, or syslog).
  • Document how to onboard Linux/macOS logs into Sentinel and how anomaly detection rules can be applied to these data sources.
  • Where Windows event IDs are referenced, provide Linux/macOS log line examples or mapping tables.
  • Clarify which anomaly rules are Windows-only and which can be extended to other platforms.
Sentinel Best practices for data collection in Microsoft Sentinel ...ocs/blob/main/articles/sentinel/best-practices-data.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Powershell Heavy
Summary
The documentation provides both Windows and Linux guidance for data collection in Microsoft Sentinel, but Windows-specific tools and patterns (such as Windows Event Forwarding, PowerShell, and Windows-centric agent configuration) are frequently mentioned first or exclusively in several sections. Some examples and solutions for Windows (e.g., PowerShell, Windows Event Forwarding) are more detailed or appear before Linux equivalents, and endpoint log collection mentions Windows Event Forwarding but omits Linux endpoint examples. However, Linux solutions are present and described in parallel tables, and most tasks are achievable on both platforms.
Recommendations
  • Ensure that Linux examples and solutions are presented with equal prominence and detail as Windows ones, especially in endpoint log collection and custom log ingestion sections.
  • Add Linux-specific endpoint log collection examples (e.g., using auditd, Sysmon for Linux, or EDR connectors for Linux endpoints).
  • When listing solutions, alternate the order or group by platform to avoid Windows-first presentation.
  • Provide PowerShell alternatives for Linux/macOS (e.g., Bash, Python scripts) where PowerShell is suggested for custom log collection.
Sentinel Reduce costs for Microsoft Sentinel ...cs/blob/main/articles/sentinel/billing-reduce-costs.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
🔧 Windows Tools Windows First
Summary
The documentation is generally cross-platform and focuses on cost optimization for Microsoft Sentinel, which is an Azure service accessible from any OS. However, the only OS-specific section is 'Use data collection rules for your Windows Security Events,' which exclusively discusses Windows Server and the Windows Security Events connector. No equivalent Linux/macOS data collection example or mention is provided, and Windows is the only platform called out explicitly in this context.
Recommendations
  • Add a section or note describing how Linux and macOS security events can be collected and cost-optimized in Microsoft Sentinel, if supported.
  • Provide parity by mentioning or linking to documentation for Linux data connectors (e.g., syslog, CEF, AMA for Linux) and how data collection rules or filtering can be used to reduce ingestion costs for non-Windows platforms.
  • Clarify whether the cost optimization strategies for Windows Security Events also apply to Linux/macOS, or provide alternative strategies if they differ.
Sentinel Manage custom content with repository connections ...cs/blob/main/articles/sentinel/ci-cd-custom-content.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Missing Linux Example
Summary
The documentation references a 'PowerShell deployment script' as the mechanism for deploying content from workflows or pipelines, but does not mention Linux/macOS alternatives or clarify cross-platform compatibility. No Bash, Azure CLI, or platform-neutral examples are provided. The use of PowerShell as the only referenced deployment tool may create friction for Linux/macOS users, especially since PowerShell Core is cross-platform but not always assumed or installed by default.
Recommendations
  • Explicitly state whether the PowerShell deployment script is compatible with PowerShell Core on Linux/macOS.
  • Provide equivalent Bash or Azure CLI examples for deployment, or clarify if only PowerShell is supported.
  • Add guidance for Linux/macOS users on installing and using PowerShell Core if it is required.
  • Where possible, offer platform-neutral instructions or scripts.
  • Clarify any OS-specific prerequisites for running deployment scripts.
Sentinel Connect Microsoft Sentinel to Amazon Web Services to ingest AWS service log data .../azure-docs/blob/main/articles/sentinel/connect-aws.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy Windows First Missing Linux Example
Summary
The documentation for connecting Microsoft Sentinel to AWS log data exhibits a Windows bias in several areas. The automatic setup process is centered around a PowerShell script, with explicit instructions to install PowerShell and run commands from a PowerShell command line. There are no equivalent instructions or scripts for Linux/macOS users, nor is there guidance for running the automation on those platforms. The prerequisites and step-by-step instructions assume a Windows environment, and PowerShell is mentioned before the AWS CLI, reinforcing the Windows-first approach.
Recommendations
  • Provide clear instructions for running the automatic setup script on Linux and macOS, including any necessary dependencies (e.g., bash, Python).
  • Offer a bash or Python version of the setup script, or document how to run the PowerShell script using PowerShell Core on Linux/macOS.
  • Include example commands and screenshots for Linux/macOS terminals alongside Windows/PowerShell examples.
  • Clarify whether the PowerShell script is compatible with PowerShell Core on non-Windows platforms, and provide troubleshooting tips for cross-platform use.
  • List prerequisites for Linux/macOS users (e.g., package managers, installation commands for PowerShell Core and AWS CLI).
Sentinel Use Azure Functions to connect Microsoft Sentinel to your data source | Microsoft Docs .../articles/sentinel/connect-azure-functions-template.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy Windows First Missing Linux Example
Summary
The documentation provides three deployment options: ARM template (platform-agnostic), manual deployment with PowerShell, and manual deployment with Python. The PowerShell manual deployment steps are detailed and use the Azure portal, which is cross-platform, but the PowerShell example is presented before the Python example. The PowerShell section does not clarify whether it is Windows-only or if it can be run on Linux/macOS (PowerShell Core is cross-platform, but this is not stated). The Python manual deployment requires Visual Studio Code, which is also cross-platform, but there are no explicit Linux/macOS shell or CLI examples. There is a slight bias in presenting PowerShell (traditionally associated with Windows) first and in more detail, with no explicit mention of Linux/macOS alternatives or clarifications.
Recommendations
  • Clarify that PowerShell Core is cross-platform and can be used on Linux/macOS, not just Windows.
  • Add explicit notes or examples for Linux/macOS users, especially regarding prerequisites and any OS-specific steps.
  • Consider alternating the order of PowerShell and Python examples, or present them in parallel, to avoid the impression of Windows-first bias.
  • If possible, provide Azure CLI or Bash script examples for manual deployment, or at least mention their availability or limitations.
  • Add a brief section or note confirming that all steps can be performed from Linux/macOS, and highlight any exceptions.
Sentinel Onboard your Azure Stack Hub virtual machines to Microsoft Sentinel | Microsoft Docs ...ocs/blob/main/articles/sentinel/connect-azure-stack.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First Missing Linux Example
Summary
The documentation provides links for both Windows and Linux VM creation, but when it comes to agent installation and troubleshooting, it references Windows instructions first and only provides a troubleshooting link for Linux, not a full installation guide. There are no explicit Linux installation steps or screenshots, and the main flow seems to assume a Windows-centric approach.
Recommendations
  • Include explicit instructions and screenshots for installing the extension and agent on Linux VMs, not just Windows.
  • Provide direct links to both Windows and Linux agent installation guides in the relevant section, not just troubleshooting for Linux.
  • Ensure that examples and references to VM creation, extension management, and agent configuration are presented in parallel for both Windows and Linux, or clarify any differences.
  • If there are Linux-specific considerations or UI differences in the Azure Stack Hub portal, document them.
Sentinel Create scheduled analytics rules from templates in Microsoft Sentinel | Microsoft Docs ...ticles/sentinel/create-analytics-rule-from-template.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Missing Linux Example
Summary
The documentation mentions PowerShell as a method to push rules to Microsoft Sentinel, but does not provide equivalent Linux/macOS CLI examples (such as Bash, Azure CLI, or REST API via curl). The only automation tool highlighted is PowerShell, which is primarily a Windows tool, and there is no guidance for Linux/macOS users on how to perform the same task using their native tools.
Recommendations
  • Add examples for pushing rules via Azure CLI and/or Bash scripts, in addition to PowerShell.
  • Explicitly mention how Linux/macOS users can use REST API (e.g., with curl or Postman) to automate rule creation.
  • Clarify that PowerShell is cross-platform, but provide installation and usage notes for Linux/macOS if recommending it.
  • Where automation is discussed, present Windows and Linux/macOS options side-by-side or in tabs.
Sentinel Audit log for Microsoft Sentinel data lake and graph in Microsoft Purview portal ...articles/sentinel/datalake/auditing-lake-activities.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy Windows First Missing Linux Example
Summary
The documentation provides a PowerShell script as the only programmatic example for searching the audit log, with no equivalent example for Linux/macOS users (e.g., Bash, curl, Python). PowerShell is a Windows-centric tool, and its use is presented without alternatives or parity for other platforms. Additionally, the script is shown before any mention of cross-platform or API-based approaches.
Recommendations
  • Provide equivalent examples using Bash/curl or Python for querying the Office 365 Management API, suitable for Linux/macOS users.
  • Explicitly mention that PowerShell Core is available cross-platform, and clarify any limitations or requirements for using it on Linux/macOS.
  • Add links or references to official Microsoft documentation on accessing the audit log via REST API, with sample requests.
  • Where possible, present cross-platform solutions before or alongside Windows-specific ones.
Sentinel Scenarios detected by the Microsoft Sentinel Fusion engine ...ob/main/articles/sentinel/fusion-scenario-reference.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools
Summary
The documentation is generally platform-neutral, focusing on cloud-based detection scenarios in Microsoft Sentinel. However, several sections reference Windows-specific tools and technologies, such as PowerShell and Windows Management Instrumentation (WMI), as examples of suspicious activity. These references are not accompanied by Linux/macOS equivalents or examples, which may create friction for organizations with non-Windows endpoints.
Recommendations
  • Where PowerShell or WMI are mentioned as examples of suspicious activity, add notes or examples for Linux/macOS equivalents (e.g., suspicious Bash scripts, Python execution, or use of Linux-native credential dumping tools like 'gsecdump' or 'LaZagne').
  • Clarify whether the detection scenarios apply to non-Windows endpoints and, if so, provide guidance or references for how similar malicious behaviors would be detected on Linux/macOS.
  • In sections referencing Windows-specific attack techniques, briefly mention common cross-platform alternatives or note Sentinel's coverage for those platforms.
Sentinel Microsoft Sentinel entity types reference | Microsoft Docs ...docs/blob/main/articles/sentinel/entities-reference.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First 🔧 Windows Tools
Summary
The documentation references several Windows-specific concepts and tools (e.g., NTDomain, NetBiosName, AlternateDataStreamName, WindowsSecurityZoneType, registry keys/values) and often lists Windows attributes first or as primary examples. While Linux/macOS equivalents are sometimes acknowledged (e.g., OSFamily includes Linux, Mac, etc.), the documentation structure and examples are noticeably Windows-centric, with limited explicit Linux/macOS guidance.
Recommendations
  • Add explicit examples and descriptions for Linux/macOS attributes where relevant (e.g., Linux user/group/domain concepts, file attributes, process identifiers).
  • Clarify which entity fields are applicable to non-Windows hosts and provide parity in schema documentation (e.g., for Host, Account, File, Registry).
  • Where Windows-specific fields are present (e.g., NTDomain, NetBiosName, AlternateDataStreamName, registry keys), add notes about their absence or equivalents on Linux/macOS.
  • Consider reordering lists or tables to avoid always listing Windows attributes first, or group by OS context.
  • Provide sample entity mappings for Linux/macOS hosts and accounts.
Sentinel Advanced multistage attack detection in Microsoft Sentinel ...tDocs/azure-docs/blob/main/articles/sentinel/fusion.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools
Summary
The documentation references PowerShell and Windows-specific alerts (such as 'Windows Error and Warning Events', 'Suspicious PowerShell command line', and 'PowerShell made a suspicious network connection') as examples of malicious activity and detection scenarios. These examples and references may create a perception that multistage attack detection in Microsoft Sentinel is primarily focused on Windows environments and tooling, with little mention of Linux/macOS equivalents or examples.
Recommendations
  • Include examples of multistage attack scenarios involving Linux/macOS hosts, such as suspicious Bash commands, Linux-specific malware, or SSH brute-force attempts.
  • Reference Linux/macOS system events and logs (e.g., syslog, auditd, systemd journal) as possible sources for detection, alongside Windows events.
  • Add detection scenarios that highlight attacks leveraging Linux/macOS tools (e.g., suspicious use of curl/wget, cron jobs, or sudo activity).
  • Clarify that Fusion can correlate signals from non-Windows sources and provide guidance or examples for integrating Linux/macOS data connectors.
Sentinel SAP agentless data connector prerequisites checker ...icles/sentinel/includes/sap-agentless-prerequisites.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy Missing Linux Example Windows First
Summary
The documentation provides only a PowerShell example for triggering the SAP agentless prerequisites checker via REST, with no equivalent example for Linux/macOS users (e.g., Bash/cURL). This creates friction for non-Windows users and implies a Windows-first approach.
Recommendations
  • Add a Bash/cURL example for triggering the iflow from Linux/macOS environments.
  • Explicitly state that any REST client can be used, and provide cross-platform guidance.
  • Consider mentioning platform-agnostic tools (e.g., Python requests, Postman) as alternatives.
Sentinel Microsoft Sentinel migration: Select a data ingestion tool | Microsoft Docs ...lob/main/articles/sentinel/migration-ingestion-tool.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy Windows First 🔧 Windows Tools
Summary
The documentation page exhibits moderate Windows bias, particularly in its emphasis on PowerShell scripts for ingestion and the SIEM data migration accelerator, which deploys a Windows VM as the migration host. While some tools (AzCopy, Logstash) are cross-platform and this is acknowledged, Windows-centric approaches (PowerShell, Windows VM) are presented first or as defaults, with limited guidance for Linux/macOS users. Some ingestion methods reference PowerShell scripts without providing equivalent Bash or Linux-native examples.
Recommendations
  • Provide Linux/macOS shell script examples alongside PowerShell for ingestion tasks.
  • Clarify when tools (like AzCopy, Logstash) are cross-platform and offer example commands for Linux/macOS.
  • Offer guidance for running migration tasks from Linux/macOS hosts, not just Windows VMs.
  • If SIEM data migration accelerator is Windows-only, explicitly state this and suggest manual alternatives for Linux/macOS users.
  • Where PowerShell is referenced as the default, mention alternative scripting languages or CLI tools usable on Linux/macOS.
Sentinel Advanced Security Information Model (ASIM) security content | Microsoft Docs ...s/blob/main/articles/sentinel/normalization-content.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Windows First
Summary
The documentation page for ASIM security content in Microsoft Sentinel demonstrates a moderate Windows bias. Many examples and hunting queries focus on Windows-specific tools (e.g., rundll32.exe, PowerShell, Certutil, Exchange PowerShell Snapin, Windows System Shutdown/Reboot), and several analytic rules and queries are tailored to Windows attack techniques and binaries. There is little to no mention of Linux/macOS equivalents, and Windows-centric examples are presented first or exclusively in several sections.
Recommendations
  • Add Linux/macOS-specific examples and hunting queries where relevant, such as detection rules for common Linux attack tools (e.g., bash scripts, cron jobs, SSH brute force, Linux-specific malware).
  • Include analytic rules and queries for Linux/macOS process and file activity, such as suspicious sudo usage, modifications to /etc/passwd, or use of common Linux persistence techniques.
  • Balance the presentation order by alternating Windows and Linux/macOS examples, or clearly label which examples apply to which platforms.
  • Where Windows-specific tools are mentioned (e.g., PowerShell, rundll32.exe), provide Linux/macOS analogs (e.g., bash, python, systemd) if applicable.
  • Explicitly state platform applicability for each rule/query to help users understand coverage.
Sentinel The Advanced Security Information Model (ASIM) Authentication normalization schema reference | Microsoft Docs ...ticles/sentinel/normalization-schema-authentication.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First 🔧 Windows Tools
Summary
The documentation references Windows as an example OS in several places (e.g., 'Windows sends several authentication events'), and field examples often use Windows-centric formats (such as domain\hostname, SIDs, and Windows process paths). Windows terminology (NTLM, SID, svchost.exe, domain\hostname) is used preferentially or exclusively in examples, with Linux/macOS equivalents not mentioned. However, the schema itself is designed to be cross-platform and references generic concepts (e.g., 'domain controllers', 'VPN gateways', 'firewall'), and does not appear to exclude Linux/macOS systems from use.
Recommendations
  • Add Linux/macOS-specific examples alongside Windows examples (e.g., show Linux usernames, process paths, authentication protocols like Kerberos, SSH, or PAM).
  • When describing fields such as Hostname, Username, or OS, include Linux/macOS formats and values (e.g., /usr/bin/sshd, UID/GID, user@domain, etc.).
  • Clarify that the schema supports authentication events from non-Windows systems and provide explicit guidance or references for integrating Linux/macOS sources.
  • In field descriptions, mention Linux/macOS equivalents for Windows-centric terms (e.g., mention Kerberos alongside NTLM, or Linux UIDs alongside SIDs).