Detected Bias Types
Windows First
🔧
Windows Tools
Windows Examples
Summary
The documentation exhibits mild Windows bias, primarily through the use of Windows-centric terminology, examples, and field values. Windows is mentioned first and most frequently when discussing authentication event sources, device naming conventions, and example values (e.g., 'C:\Windows\System32\svchost.exe', 'DESKTOP-1282V4D', 'Contoso\DESKTOP-1282V4D', 'SID'). Protocol examples such as NTLM are Windows-specific, and username types like 'Windows' are highlighted. Linux/macOS equivalents, such as PAM authentication, UIDs, or typical Linux hostnames, are not provided as examples, nor are Linux/macOS-specific authentication protocols or patterns discussed.
Recommendations
- Include Linux/macOS authentication event examples (e.g., PAM, SSH, Kerberos, SSSD).
- Provide sample values for fields using Linux/macOS conventions (e.g., '/usr/bin/sshd', 'ubuntu-server', UIDs, FQDNs in Linux format).
- Mention Linux/macOS authentication protocols and logon types alongside Windows-specific ones.
- Clarify that the schema supports non-Windows systems and explicitly list common Linux/macOS sources.
- Balance example values and terminology to reflect cross-platform environments.