Detected Bias Types
Windows First
🔧
Windows Tools
Summary
The documentation references Windows Security Events as a primary data source and lists Windows-specific event codes and log tables before mentioning other platforms. Device-related enrichments and examples (e.g., DeviceFamily, OperatingSystem) use Windows as the sample value, with no mention of Linux or macOS equivalents. There are no Linux/macOS-specific log sources, event codes, or enrichment examples provided, and Windows terminology is used in several schema fields (e.g., SID, local admin). However, the documentation does include cloud and third-party sources (AWS, GCP, Okta), which broadens its scope beyond Windows.
Recommendations
- Add examples of Linux/macOS device logon events and how they are ingested/analyzed by UEBA, if supported.
- Include sample enrichment values for non-Windows operating systems (e.g., Linux, macOS) in tables and examples.
- Clarify whether Linux/macOS security events are supported as UEBA data sources and, if so, provide equivalent event codes and log table references.
- If Windows is the only supported OS for certain features, explicitly state this to avoid confusion.
- Consider including a section on cross-platform support and limitations for UEBA data sources and enrichments.