391
Total Pages
285
Linux-Friendly Pages
106
Pages with Bias
27.1%
Bias Rate

Bias Trend Over Time

Pages with Bias Issues

488 issues found
Showing 451-475 of 488 flagged pages
Sentinel Common Event Format (CEF) key and CommonSecurityLog field mapping ...e-docs/blob/main/articles/sentinel/cef-name-mapping.md
Low Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 1 bias type
Detected Bias Types
Windows First
Summary
The documentation provides mappings between CEF keys and CommonSecurityLog fields in Microsoft Sentinel. While the content is generally platform-neutral, some field descriptions (e.g., filePath, oldFilePath) list Windows-style paths before Linux-style paths, and several fields reference Windows domains (e.g., deviceNtDomain, dntdom, sntdom) without equivalent mention of Linux/macOS concepts. However, the overall mapping is relevant to both Windows and Linux environments, and examples for both are present in some cases.
Recommendations
  • When providing example file paths, alternate the order or give Linux/macOS examples first in some cases.
  • Where fields reference Windows-specific concepts (e.g., NTDomain), clarify if/how these fields are used for Linux/macOS sources, or mention that they may be empty or not applicable.
  • Add more Linux/macOS-centric examples where possible, especially for fields like process names, file paths, and domain concepts.
  • Ensure that descriptions do not imply Windows is the default or primary platform unless the feature is Windows-only.
Sentinel Create scheduled analytics rules in Microsoft Sentinel | Microsoft Docs .../blob/main/articles/sentinel/create-analytics-rules.md
Low Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
🔧 Windows Tools Powershell Heavy Windows First
Summary
The documentation is generally cross-platform and focused on the Azure and Defender portals, which are web-based and accessible from any OS. However, in the 'Next steps' section, PowerShell is mentioned explicitly as a method for automating rule enablement, with no mention of Linux/macOS equivalents (such as Azure CLI or Bash scripting). Additionally, PowerShell is referenced before the REST API, and no Linux-specific automation examples are provided. There is a minor bias toward Windows tooling for automation, but the core workflow (creating and managing rules) is portal-based and OS-agnostic.
Recommendations
  • Include Azure CLI examples for rule automation and management alongside PowerShell.
  • Mention Bash scripting or other cross-platform automation methods where appropriate.
  • Clarify that PowerShell Core is available on Linux/macOS, or provide links to cross-platform PowerShell installation.
  • Provide parity in automation instructions by listing REST API, Azure CLI, and PowerShell together, not prioritizing Windows tools.
Sentinel Create a codeless connector for Microsoft Sentinel ...ob/main/articles/sentinel/create-codeless-connector.md
Low Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
🔧 Windows Tools Windows First Powershell Heavy
Summary
The documentation page provides a cross-platform overview of creating codeless connectors for Microsoft Sentinel, but there is mild Windows bias in the API testing tools section. PowerShell (Invoke-RestMethod) and Visual Studio Code are listed before Linux-native tools like curl and Bruno. PowerShell is called out specifically, and Microsoft Edge's Network Console is mentioned, which is Windows-centric. No Linux/macOS-specific examples or shell commands are given, and Windows tools are referenced first in the list.
Recommendations
  • List cross-platform tools (curl, Bruno) before Windows-centric tools in the API testing section.
  • Explicitly mention Linux/macOS compatibility for all steps, especially for API testing and ARM template editing.
  • Provide example commands for Linux/macOS shells (e.g., curl, jq) alongside PowerShell examples.
  • Clarify that Visual Studio Code and Bruno are available on Linux/macOS, and link to their respective downloads for all platforms.
  • Consider including a note that all ARM template deployment steps can be performed via Azure CLI on Linux/macOS, not just via the Azure portal.
Sentinel This file is auto-generated . Do not edit manually. Changes will be overwritten. ...in/articles/sentinel/includes/deprecated-connectors.md
Low Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First 🔧 Windows Tools
Summary
The documentation lists deprecated Microsoft Sentinel data connectors, with several sections focused on Windows-specific tools and patterns (e.g., Windows agent, Windows machines, Windows event logs) and these are presented before Linux equivalents. While there is a dedicated section for Syslog (Linux), Windows connectors and terminology appear first and are described in more detail, potentially creating a perception of Windows preference.
Recommendations
  • Ensure Linux/macOS connectors (e.g., Syslog, custom log ingestion) are presented with equal prominence and detail as Windows connectors.
  • Where possible, provide parallel examples for both Windows and Linux data collection agents and workflows.
  • Avoid listing Windows connectors before Linux ones unless there is a technical reason; consider grouping by OS or presenting in alphabetical order.
  • Clarify in each connector section which platforms are supported and provide links to Linux/macOS agent installation and troubleshooting guides.
Sentinel This file is auto-generated . Do not edit manually. Changes will be overwritten. ...b/main/articles/sentinel/includes/connector-details.md
Low Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
🔧 Windows Tools Windows First
Summary
The documentation is a comprehensive, auto-generated list of Microsoft Sentinel data connectors. While most connectors are platform-agnostic or cloud-focused, there are several connectors and sections that reference Windows-specific tools (e.g., Windows Event logs, Windows Firewall, IIS Logs, Windows DNS Events) and sometimes present Windows collection methods before Linux equivalents. However, Linux collection methods (such as Syslog via AMA) are also present and described. The bias is minor and mostly a result of the prevalence of Windows in enterprise environments, not an intentional exclusion of Linux/macOS.
Recommendations
  • For each connector that references Windows-specific collection (e.g., Windows Event logs, Windows Firewall, IIS Logs), ensure that equivalent Linux/macOS collection methods (such as Syslog, auditd, or other agents) are referenced where possible.
  • Where both Windows and Linux collection methods exist, present them in parallel or clarify platform applicability, rather than listing Windows first by default.
  • For connectors that are truly Windows-only (e.g., Windows Firewall), clarify this explicitly to avoid confusion.
  • Consider adding more Linux/macOS-specific examples or connectors if available, and ensure parity in documentation structure and detail.
Sentinel Microsoft Purview Information Protection connector reference - audit log record types and activities support in Microsoft Sentinel .../sentinel/microsoft-purview-record-types-activities.md
Low Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 1 bias type
Detected Bias Types
🔧 Windows Tools
Summary
The documentation references the Windows PowerShell cmdlet Unlock-SPOSensitivityLabelEncryptedFile as a method for removing sensitivity labels from files, without mentioning Linux/macOS alternatives or clarifying cross-platform support. No other examples or instructions are platform-specific, and the overall content is focused on audit log types and activities, which are platform-agnostic.
Recommendations
  • Clarify whether the referenced PowerShell cmdlet is available on Linux/macOS (via PowerShell Core) or only on Windows.
  • If the cmdlet is Windows-only, suggest alternative methods for Linux/macOS users, or explicitly state platform limitations.
  • Provide guidance or links for performing equivalent actions on non-Windows platforms, if supported.
Sentinel The Advanced Security Information Model (ASIM) Application Entity reference .../articles/sentinel/normalization-entity-application.md
Low Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First Windows Examples
Summary
The documentation page for the ASIM Application Entity reference displays minor Windows bias. Examples for process-related fields use Windows-style paths (e.g., 'C:\Windows\explorer.exe'), and Windows process conventions are shown first. Linux equivalents (e.g., '/usr/bin/nginx') are not provided, though the text acknowledges Linux compatibility in the ProcessId field note.
Recommendations
  • Provide Linux/macOS examples alongside Windows examples for fields like ProcessName and Process.
  • Include sample process paths using Linux conventions (e.g., '/usr/bin/nginx') in the examples.
  • Clarify that field values are platform-agnostic and provide guidance for Linux/macOS users where relevant.
Sentinel The Advanced Security Information Model (ASIM) Alert Events normalization schema reference | Microsoft Docs ...b/main/articles/sentinel/normalization-schema-alert.md
Low Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First 🔧 Windows Tools
Summary
The documentation page is generally platform-neutral, focusing on schema definitions and concepts relevant to Microsoft Sentinel and ASIM. However, there is a mild Windows bias in example values and field descriptions, such as file paths (e.g., C:\Windows\explorer.exe), registry keys (e.g., HKEY_LOCAL_MACHINE), and process names, which are all Windows-centric. No Linux/macOS-specific examples or references are provided, and Windows patterns/tools are used as the default illustration.
Recommendations
  • Include Linux/macOS examples alongside Windows ones for fields like file paths (e.g., /usr/bin/bash), process names, and registry equivalents (if applicable).
  • Add sample values for fields that reflect Linux/macOS environments, such as Linux process paths, Linux user formats, or macOS file locations.
  • Where possible, clarify that the schema is applicable to alerts from non-Windows systems and provide guidance or references for mapping Linux/macOS-specific data.
Sentinel The Advanced Security Information Model (ASIM) File Event normalization schema reference| Microsoft Docs ...n/articles/sentinel/normalization-schema-file-event.md
Low Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 1 bias type
Detected Bias Types
Windows First
Summary
The documentation provides both Windows and Unix/Linux examples for file paths and process names, but Windows examples are consistently presented first and more frequently. The only concrete user scenario example uses Windows File Explorer, and most field examples use Windows-style paths or process names before Unix equivalents. However, the schema itself is designed to be cross-platform and explicitly supports Unix paths and cloud storage formats.
Recommendations
  • Alternate the order of examples so that Linux/Unix examples are presented first in some cases.
  • Include more Linux/Unix-specific user scenarios (e.g., using 'mv' or 'cp' commands, or referencing common Linux file operations/applications).
  • Ensure that field examples are balanced between Windows and Linux/Unix formats.
  • Add explicit mention of macOS where relevant, or clarify that Unix examples apply to macOS as well.
Sentinel The Advanced Security Information Model (ASIM) Process Event normalization schema reference | Microsoft Docs ...rticles/sentinel/normalization-schema-process-event.md
Low Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First Windows Examples Windows Terms
Summary
The documentation for the ASIM Process Event normalization schema is intended to be cross-platform, but exhibits a mild Windows bias. Most field examples use Windows-style paths (e.g., 'C:\Windows\explorer.exe'), Windows usernames/domains, and Windows-specific terminology (such as integrity levels and UAC). References to process integrity levels and token elevation are described only in terms of Windows, with links to Windows documentation. Linux is mentioned in a few places (e.g., PID conversion), but there are no Linux/macOS-specific examples or terminology, and the examples and explanations default to Windows conventions.
Recommendations
  • Add Linux/macOS-specific examples for fields such as process names, command lines, and directories (e.g., '/usr/bin/bash', '/home/user').
  • Clarify which fields and concepts are Windows-specific (e.g., integrity levels, UAC) and provide equivalent or 'N/A' guidance for Linux/macOS where appropriate.
  • Include notes or examples for Linux/macOS process events, such as typical process paths, user formats, and session IDs.
  • Where possible, link to Linux/macOS documentation for process concepts, not only Windows.
  • Ensure that terminology and examples are balanced between platforms, or explicitly state when a concept is Windows-only.
Sentinel Microsoft Sentinel user management normalization schema reference | Microsoft Docs ...icles/sentinel/normalization-schema-user-management.md
Low Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 1 bias type
Detected Bias Types
Windows First
Summary
The documentation provides normalization schema details for user management activities in Microsoft Sentinel, referencing both Windows and Linux identifiers (e.g., SID and UID) and username/group formats. However, in several places, Windows formats (such as SID, domain\username, and Windows group types) are listed before Linux equivalents, and Windows is often used as the primary example. No PowerShell-specific examples, Windows-only tools, or missing Linux examples are present; Linux is acknowledged but not given equal prominence.
Recommendations
  • Alternate the order of Windows and Linux examples in tables and descriptions to avoid implicit prioritization.
  • Provide Linux examples (e.g., UID, username formats) with equal detail and frequency as Windows examples.
  • Where possible, use neutral examples or explicitly state that both Windows and Linux are supported equally.
  • Clarify that the schema is designed for cross-platform use and provide links to Linux-specific integration guidance if available.
Sentinel Create Analytics Rules for Microsoft Sentinel Solutions .../articles/sentinel/sentinel-analytic-rules-creation.md
Low Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
🔧 Windows Tools Windows First
Summary
The documentation page provides a detailed guide for creating analytics rules for Microsoft Sentinel solutions. The only explicit tooling example given for generating a GUID is the Windows PowerShell 'New-GUID' cmdlet, with no mention of Linux/macOS alternatives. This is a minor Windows bias, as Linux/macOS users may need to search for their own method to generate a GUID. No other examples or instructions are Windows-specific, and the rest of the content is platform-neutral.
Recommendations
  • When mentioning GUID generation, include cross-platform alternatives such as 'uuidgen' (available on Linux/macOS), Python's 'uuid' module, or online generators.
  • Provide examples for both Windows (PowerShell) and Linux/macOS (shell commands) when referencing development tools.
  • Add a note clarifying that any tool capable of generating a GUID is acceptable, and link to platform-agnostic resources.
Sentinel Create Hunting Queries for Microsoft Sentinel Solutions ...n/articles/sentinel/sentinel-hunting-rules-creation.md
Low Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
🔧 Windows Tools Windows First
Summary
The documentation mentions PowerShell's New-GUID cmdlet as a way to generate GUIDs before referencing generic development tools or online generators. No Linux/macOS-specific tools (such as uuidgen) are mentioned, and the only explicit example is Windows/PowerShell. This creates a subtle Windows-first bias in tooling recommendations.
Recommendations
  • Mention Linux/macOS equivalents for GUID generation, such as the uuidgen command.
  • Provide examples for generating GUIDs on multiple platforms (e.g., PowerShell, Bash, online tools).
  • List platform-agnostic options before platform-specific ones, or group them together.
  • Clarify that any tool capable of generating a GUID is acceptable, regardless of OS.
Sentinel Microsoft Sentinel skill-up training ...docs/blob/main/articles/sentinel/skill-up-resources.md
Low Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First 🔧 Windows Tools
Summary
The documentation is generally cross-platform and vendor-neutral, but there are some instances of Windows bias. In several places, Windows is mentioned before Linux (e.g., 'Connect to Azure, Windows, Microsoft, and Amazon services'), and Windows tools or agents are referenced first or exclusively (e.g., agent health monitoring solution is noted as 'Windows only'). PowerShell is mentioned as an alternative to API usage, but Linux CLI or scripting equivalents are not highlighted. However, Linux is supported in most features, and links to Linux-specific resources (e.g., Sysmon for Linux) are present.
Recommendations
  • When listing supported platforms or tools, mention Linux and macOS alongside Windows, and avoid placing Windows first unless it is the most common use case.
  • Where PowerShell is referenced for automation, also provide examples or mention Bash, Azure CLI, or Python for Linux/macOS users.
  • In agent health monitoring, clarify Linux support and provide links to equivalent Linux monitoring solutions.
  • Review all examples and references to ensure Linux and macOS users are equally represented, especially in introductory and summary tables.
Sentinel Use matching analytics to detect threats ...s/sentinel/use-matching-analytics-to-detect-threats.md
Low Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First 🔧 Windows Tools
Summary
The documentation page lists both Windows and Linux data sources (e.g., Windows DNS, Windows Firewall, Syslog/CEF), but Windows-specific connectors and solutions are often mentioned first or given prominence. The table of solutions lists Windows DNS and Windows Firewall connectors alongside cross-platform options, but Windows tools are highlighted before their Linux equivalents (Syslog/CEF). There are no explicit Linux/macOS examples or screenshots, and the configuration steps and incident triage instructions are platform-neutral but do not provide parity examples for Linux environments.
Recommendations
  • Ensure that Linux/macOS data sources (e.g., Syslog, CEF) are given equal prominence to Windows sources in tables and lists.
  • Provide explicit examples or screenshots for Linux/macOS data sources (such as Syslog/CEF) to demonstrate parity.
  • Include guidance or links for configuring and troubleshooting Linux/macOS connectors, not just Windows DNS/Firewall.
  • When listing data connectors, alternate or group by platform rather than listing Windows sources first.
Sentinel Data connector definitions reference for the Codeless Connector Framework ...es/sentinel/data-connector-ui-definitions-reference.md
Low Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
🔧 Windows Tools Windows First
Summary
The documentation references Windows-specific connectors and examples before Linux equivalents, notably in the InstallAgent section and in the example links (e.g., Windows DNS connector). Windows installation options are listed first, and the only detailed connector example provided is for Windows DNS. Linux options are present but less emphasized and not exemplified.
Recommendations
  • Provide Linux/macOS connector examples alongside or before Windows examples.
  • Ensure that installation instructions and sample code are equally detailed for Linux and Windows.
  • Reference Linux connectors (e.g., Linux Syslog, Linux DNS) in example links and screenshots.
  • List Linux installation options before or alongside Windows options in enumerations.
  • Include explicit Linux/macOS sample queries and configuration snippets.
Sentinel Microsoft Sentinel network normalization schema (Legacy version - Public preview)| Microsoft Docs ...blob/main/articles/sentinel/normalization-schema-v1.md
Low Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
🔧 Windows Tools Windows First
Summary
The documentation page exhibits minor Windows bias, primarily through the use of Windows-centric terminology and examples. Several field examples reference Windows-specific concepts (e.g., SIDs, file paths like C:\Malicious\ImNotMalicious.exe, device/domain names such as WORKGROUP, DESKTOP, and Ethernet adapter naming conventions). The HTTP user agent example also references Windows. However, the schema itself is platform-agnostic and includes fields and examples relevant to other operating systems (e.g., eth0, iOS, Samsung Galaxy Note). There are no PowerShell-heavy sections or Windows-only instructions, and Linux/macOS equivalents are not missing, but Windows patterns are often shown first or exclusively in examples.
Recommendations
  • Add more Linux/macOS-centric examples alongside Windows ones (e.g., file paths like /home/user/file.txt, domain names, interface names like enp0s3, Linux user/group representations).
  • Clarify that field values are platform-agnostic and provide guidance/examples for non-Windows environments.
  • Balance examples to include both Windows and Linux/macOS conventions where relevant (e.g., show both C:\path and /path, both WORKGROUP and typical Linux domain names).
  • Explicitly mention that SIDs are Windows-specific and suggest Linux/macOS equivalents (e.g., UID/GID) where appropriate.
Sentinel Microsoft Sentinel user management normalization schema reference | Microsoft Docs ...icles/sentinel/normalization-schema-user-management.md
Low Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First Windows Examples Windows Terms
Summary
The documentation demonstrates a mild Windows bias in several areas: Windows-specific formats (e.g., SID, domain\username) are consistently listed before Linux equivalents (e.g., UID, simple username), and most examples use Windows-centric values. Windows terminology (such as 'SID', 'Contoso\username', 'DESKTOP-1282V4D') is prioritized in field descriptions and examples, while Linux formats are mentioned but not exemplified as frequently or as prominently. No PowerShell or Windows-only tools are referenced, and Linux support is acknowledged throughout, but the ordering and example choices favor Windows.
Recommendations
  • Alternate the order of Windows and Linux formats in field descriptions and examples to avoid implicit prioritization.
  • Provide Linux-specific examples (e.g., UID, simple username, Linux hostnames) alongside Windows ones for each relevant field.
  • Explicitly state that both Windows and Linux formats are equally supported and provide guidance for Linux/macOS normalization where appropriate.
  • Include sample values and normalization patterns for Linux/macOS systems in addition to Windows.
  • Where possible, use neutral examples or rotate between Windows and Linux in documentation tables and sample data.
Sentinel Use matching analytics to detect threats ...s/sentinel/use-matching-analytics-to-detect-threats.md
Low Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First 🔧 Windows Tools
Summary
The documentation page demonstrates a mild Windows bias by listing Windows-specific solutions and connectors (such as Windows DNS and Windows Firewall) before Linux equivalents, and by referencing Windows tools more frequently. However, Linux-compatible data sources like Syslog and CEF are also included, and there are no exclusive Windows-only instructions or examples. No PowerShell-heavy or Windows-only configuration steps are present.
Recommendations
  • Ensure Linux-compatible solutions (e.g., Syslog, CEF) are listed before or alongside Windows solutions in tables and lists.
  • Add explicit examples or references for Linux/macOS environments, such as how to configure Syslog or CEF connectors from Linux hosts.
  • Include screenshots or walkthroughs showing Linux data source integration, not just Windows-centric ones.
  • Clarify that the analytics rule works equally with Linux-originating logs and provide troubleshooting tips for Linux users.
Sentinel Common Event Format (CEF) key and CommonSecurityLog field mapping ...e-docs/blob/main/articles/sentinel/cef-name-mapping.md
Low Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows Terms Windows Examples Windows Fields
Summary
The documentation is largely platform-neutral, focusing on field mappings between CEF and Microsoft Sentinel's CommonSecurityLog. However, there are minor instances of Windows bias: several field descriptions reference Windows-specific concepts (e.g., 'Windows domain', 'C:\ProgramFiles\WindowsNT\Accessories\wordpad.exe'), and some field names include 'NTDomain' or reference Windows domains. Linux/UNIX equivalents are mentioned in a few places (e.g., process names like 'sshd', file paths like '/usr/bin/zip'), but Windows terminology and examples are slightly more prevalent.
Recommendations
  • Where Windows-specific terms are used (e.g., 'Windows domain'), add Linux/UNIX equivalents or clarify applicability (e.g., 'Active Directory domain (Windows) or NIS domain (UNIX)').
  • When giving file path examples, always provide both Windows and Linux/UNIX examples, and list them in parallel (e.g., 'C:\... (Windows)' and '/usr/... (Linux)').
  • For fields like 'deviceNtDomain' and 'dntdom', clarify that these are only relevant for Windows environments, and mention what Linux/UNIX users should expect (e.g., field may be empty or not applicable).
  • Review all field descriptions for implicit Windows assumptions and add Linux/UNIX context where appropriate.
Sentinel Create a codeless connector for Microsoft Sentinel ...ob/main/articles/sentinel/create-codeless-connector.md
Low Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
🔧 Windows Tools Windows First
Summary
The documentation demonstrates a mild Windows bias in its recommendations for API testing tools, listing PowerShell and Microsoft Edge tools (both Windows-centric) before cross-platform or Linux-native options. However, Linux-friendly tools like curl and Bruno are also mentioned. No critical steps are Windows-only, and the ARM template/deployment process is platform-agnostic.
Recommendations
  • List cross-platform tools (e.g., curl, Bruno) before or alongside Windows-specific tools in the API testing tools section.
  • Provide explicit Linux/macOS command-line examples (e.g., using curl) where PowerShell is mentioned.
  • Clarify that all steps, including ARM template deployment, can be performed from Linux/macOS using Azure CLI or portal.
  • If referencing Visual Studio Code, note its cross-platform availability.
  • Avoid implying PowerShell is the default or preferred method for API testing.
Sentinel Microsoft Sentinel entity types reference | Microsoft Docs ...docs/blob/main/articles/sentinel/entities-reference.md
Low Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
🔧 Windows Tools Windows First
Summary
The documentation shows a mild Windows bias through the use of Windows-specific terminology (e.g., NTDomain, NetBiosName, SID, RegistryKey/Hive) and by referencing Windows-centric concepts (such as AlternateDataStreamName, WindowsSecurityZoneType, and Mark of the Web) without equivalent Linux/macOS context. Windows identifiers and fields are often listed first or exclusively, while Linux/macOS equivalents are not explained or are absent. However, the document does acknowledge Linux and other OSes in some schema fields (e.g., OSFamily), and the bias does not prevent Linux/macOS users from understanding or using the documentation.
Recommendations
  • Where Windows-specific fields (e.g., NTDomain, NetBiosName, SID, RegistryKey) are described, add notes or parallel fields for Linux/macOS equivalents (e.g., UID/GID, /etc/passwd, file permissions, etc.) if applicable.
  • In the Host and Account schemas, clarify how these fields map (or do not map) to Linux/macOS systems, and provide examples for non-Windows environments.
  • For fields like AlternateDataStreamName and WindowsSecurityZoneType, explicitly state that these are Windows-only and describe what, if any, analogous concepts exist on Linux/macOS.
  • Consider including Linux/macOS-specific entity types or attributes where relevant (e.g., systemd unit names, Linux process attributes, etc.).
  • When listing identifier combinations, provide Linux/macOS-centric examples alongside Windows ones.
  • Review terminology throughout to ensure cross-platform clarity (e.g., avoid assuming 'domain' always means Active Directory).
Sentinel Advanced multistage attack detection in Microsoft Sentinel ...tDocs/azure-docs/blob/main/articles/sentinel/fusion.md
Low Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Powershell Heavy Windows First
Summary
The documentation page for Microsoft Sentinel's Fusion technology demonstrates a mild Windows bias. While the content is largely platform-neutral, several attack detection scenarios specifically reference Windows-centric technologies (such as PowerShell and WMI) and provide examples that are focused on Windows environments. These examples are listed before any Linux/macOS equivalents, and there is no mention of Linux-specific attack patterns, tools, or detection scenarios. The absence of Linux/macOS examples or references may make it harder for non-Windows users to relate the guidance to their environments.
Recommendations
  • Include Linux/macOS-specific attack detection scenarios and examples, such as suspicious Bash commands, SSH brute force, or anomalous sudo usage.
  • Add references to Linux/macOS data sources (e.g., syslog, auditd, OSSEC) in the scenario tables and descriptions.
  • Provide parity in examples by listing Linux/macOS attack patterns alongside Windows ones, rather than focusing on PowerShell and WMI.
  • Clarify that Fusion can correlate signals from Linux/macOS endpoints and provide guidance on connecting and configuring these data sources.
Sentinel The Advanced Security Information Model (ASIM) Authentication normalization schema reference | Microsoft Docs ...ticles/sentinel/normalization-schema-authentication.md
Low Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Windows Examples
Summary
The documentation exhibits mild Windows bias, primarily through the use of Windows-centric terminology, examples, and field values. Windows is mentioned first and most frequently when discussing authentication event sources, device naming conventions, and example values (e.g., 'C:\Windows\System32\svchost.exe', 'DESKTOP-1282V4D', 'Contoso\DESKTOP-1282V4D', 'SID'). Protocol examples such as NTLM are Windows-specific, and username types like 'Windows' are highlighted. Linux/macOS equivalents, such as PAM authentication, UIDs, or typical Linux hostnames, are not provided as examples, nor are Linux/macOS-specific authentication protocols or patterns discussed.
Recommendations
  • Include Linux/macOS authentication event examples (e.g., PAM, SSH, Kerberos, SSSD).
  • Provide sample values for fields using Linux/macOS conventions (e.g., '/usr/bin/sshd', 'ubuntu-server', UIDs, FQDNs in Linux format).
  • Mention Linux/macOS authentication protocols and logon types alongside Windows-specific ones.
  • Clarify that the schema supports non-Windows systems and explicitly list common Linux/macOS sources.
  • Balance example values and terminology to reflect cross-platform environments.
Sentinel List of Microsoft Sentinel Advanced Security Information Model (ASIM) parsers | Microsoft Docs ...b/main/articles/sentinel/normalization-parsers-list.md
Low Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Windows Heavy
Summary
The documentation lists ASIM parsers for a wide variety of sources, including both Windows and Linux systems. However, Windows-specific sources (e.g., Windows Events, Sysmon for Windows, Microsoft Defender XDR, Windows Security Events, IIS) are consistently listed and described in detail, often with explicit mention of Windows event IDs and collection methods (Azure Monitor Agent, Log Analytics Agent). Linux sources are present but less emphasized, and Windows tools and patterns (event IDs, connectors) are referenced more frequently and in greater detail than their Linux equivalents. In some sections, Windows examples or tools are listed before Linux ones, suggesting a subtle ordering bias.
Recommendations
  • Ensure Linux sources and parsers are described with equal detail, including collection methods and event types (e.g., Syslog, auditd, etc.).
  • Where Windows event IDs and connectors are mentioned, provide equivalent Linux log/event references and collection patterns.
  • Consider alternating the order of Windows and Linux sources in tables or lists, or group by OS type for parity.
  • Add more explicit examples and guidance for Linux/macOS users, especially regarding ingestion and normalization.
  • Review for any missing Linux/macOS sources that could be supported and document them.