391
Total Pages
285
Linux-Friendly Pages
106
Pages with Bias
27.1%
Bias Rate

Bias Trend Over Time

Pages with Bias Issues

488 issues found
Showing 151-175 of 488 flagged pages
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/normalization-entity-application.md .../articles/sentinel/normalization-entity-application.md
High Priority View Details →
Scanned: 2026-01-09 00:34
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First Missing Linux Example 🔧 Windows Tools
Summary
The documentation page demonstrates Windows bias by providing only Windows-centric examples for process names (e.g., 'C:\Windows\explorer.exe', 'C:\Windows\System32\rundll32.exe') and referencing Windows file paths exclusively. There are no Linux-specific examples (such as '/usr/bin/bash'), and Windows terminology and patterns are presented first and exclusively. The guidance for process IDs mentions both Windows and Linux, but examples and details are Windows-focused.
Recommendations
  • Add equivalent Linux examples for process names and paths (e.g., '/usr/bin/sshd', '/bin/bash').
  • Include Linux-specific guidance and terminology where relevant, such as process IDs and file paths.
  • Present examples for both Windows and Linux side-by-side to ensure parity and inclusivity.
  • Avoid using only Windows file path formats in examples; alternate or dual examples should be provided.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/normalization-parsers-list.md ...b/main/articles/sentinel/normalization-parsers-list.md
High Priority View Details →
Scanned: 2026-01-09 00:34
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Windows Event Heavy
Summary
The documentation page lists ASIM parsers for a wide range of sources, including both Windows and Linux systems. However, Windows-specific sources (such as Windows Events, Sysmon for Windows, Microsoft Defender XDR, and Windows Security Events) are consistently listed before their Linux equivalents in most categories. There is a heavy emphasis on Windows event types and connectors (e.g., Azure Monitor Agent, Log Analytics Agent, Security Events connector), while Linux sources are present but less prominently featured and sometimes grouped together at the end. Windows tools and patterns (Sysmon, Windows Events, Defender XDR) are mentioned more frequently and with more detail than Linux equivalents.
Recommendations
  • Ensure Linux sources (e.g., Sysmon for Linux, Linux audit logs, SSHD/Sudo/Su events) are listed alongside or before Windows sources in each parser category to provide parity.
  • Provide equal detail for Linux event collection methods (e.g., Syslog, auditd, NXlog for Linux) as is given for Windows connectors and agents.
  • Add explicit examples or notes for Linux event ingestion, normalization, and connector configuration, similar to the Windows documentation.
  • Consider grouping sources by platform (Windows, Linux, Cloud, Network, etc.) or alphabetically to avoid implicit prioritization.
  • Review parser notes to ensure Linux tools and patterns are described with the same specificity as Windows tools.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/normalization-schema-audit.md ...b/main/articles/sentinel/normalization-schema-audit.md
High Priority View Details →
Scanned: 2026-01-09 00:34
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First Windows Examples Windows Terms
Summary
The documentation demonstrates a mild Windows bias. Windows-specific terms, formats, and examples (e.g., domain\hostname, Windows username types, Windows 10 OS, svchost.exe) are used throughout, and Windows conventions are often mentioned before or instead of Linux equivalents. Linux-specific examples, terms, or patterns are generally missing, and the documentation does not provide parity in illustrating Linux audit event scenarios or field values.
Recommendations
  • Add Linux-specific examples for fields such as ActorUsername, TargetHostname, ActingAppName, and TargetDvcOs (e.g., 'root', 'ubuntu-server', '/usr/bin/sshd', 'Ubuntu 22.04').
  • Explicitly mention Linux/Unix domain and hostname formats (e.g., FQDN as 'host.example.com') alongside Windows formats.
  • Include Linux audit event scenarios and sample values (e.g., SELinux policy changes, systemd service modifications) in field descriptions and examples.
  • Reference Linux/Unix user types and ID formats (e.g., UID/GID, /etc/passwd) in relevant fields.
  • Balance the mention of Windows and Linux tools, processes, and conventions throughout the schema documentation.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/normalization-schema-authentication.md ...ticles/sentinel/normalization-schema-authentication.md
High Priority View Details →
Scanned: 2026-01-09 00:34
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Windows Examples
Summary
The documentation demonstrates a Windows bias in several ways: Windows is mentioned first and most frequently as an example of authentication event sources, and Windows-specific tools, formats, and terminology (e.g., NTLM, SID, domain\hostname, svchost.exe) are used in field examples and descriptions. Linux or non-Windows equivalents are not provided or are mentioned only generically (e.g., 'firewall', 'VPN gateway'). The schema field examples and explanations predominantly use Windows-centric values and patterns.
Recommendations
  • Include Linux and macOS authentication event sources explicitly in introductory sections and examples.
  • Provide example field values and patterns for Linux (e.g., UID/GID, /usr/bin/sshd, /var/log/auth.log, PAM, Kerberos) and macOS (e.g., user short name, Apple ID, launchd).
  • Mention Linux authentication protocols (e.g., Kerberos, LDAP, PAM) alongside NTLM and Windows-specific protocols.
  • Show examples of device and user identifiers as used in Linux (e.g., numeric UID, hostname formats, systemd service names) and macOS.
  • Clarify that fields such as domain, hostname, and application name can have different formats on Linux/macOS, and provide those formats as examples.
  • Add references to Linux and macOS security event documentation or tools where relevant.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/normalization-schema-dns.md ...lob/main/articles/sentinel/normalization-schema-dns.md
High Priority View Details →
Scanned: 2026-01-09 00:34
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Windows Examples Windows-Centric Field Values
Summary
The documentation exhibits a Windows bias in several areas: Windows domain and hostname formats are mentioned first and in detail, field examples and value types (such as process names, hostnames, and domain types) use Windows-centric formats, and Windows-specific terminology (e.g., 'Primary Domain Controller', 'Contoso\DESKTOP-1282V4D', 'Windows' domain type) is prevalent. Linux equivalents or examples (e.g., Linux process paths, Linux host/domain formats) are missing or only referenced generically. The documentation does mention Linux in passing (e.g., process ID types), but does not provide parity in examples, terminology, or guidance.
Recommendations
  • Add Linux-specific examples for fields such as SrcProcessName (e.g., '/usr/bin/sshd'), SrcHostname (e.g., 'webserver01'), and domain types (e.g., FQDNs typical in Linux environments).
  • When listing possible values for fields like SrcDomainType and DstDomainType, mention FQDN first or equally with Windows domain formats.
  • Provide process ID conversion examples for Linux (e.g., handling hexadecimal PIDs from Linux audit logs).
  • Include Linux-specific device types and terminology in field descriptions and examples (e.g., reference 'systemd', 'init', or Linux service names).
  • Ensure that documentation for custom parsers and normalization includes Linux-based DNS servers (e.g., BIND, Unbound) and their logging patterns.
  • Balance references to Windows tools and concepts with Linux equivalents throughout the schema and usage notes.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/normalization-schema-dhcp.md ...ob/main/articles/sentinel/normalization-schema-dhcp.md
High Priority View Details →
Scanned: 2026-01-09 00:34
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Missing Linux Example
Summary
The documentation page exhibits a moderate Windows bias. Windows-specific terminology and examples (such as 'Windows DHCP server', 'Windows domain', and 'Windows DHCP server logs MAC address in a nonstandard way') are mentioned explicitly and often before or instead of Linux equivalents. There are no examples or notes for Linux/ISC DHCP servers, nor are Linux-specific patterns or tools referenced. The schema fields and examples (e.g., hostnames, domain types, user IDs) are predominantly Windows-centric, and guidance for parsing or handling Linux DHCP logs is missing.
Recommendations
  • Add explicit references and examples for Linux/ISC DHCP servers, including how fields map from common Linux DHCP log formats.
  • Include Linux-specific hostname, domain, and user ID examples alongside Windows ones.
  • Document differences in MAC address formatting for Linux DHCP servers and provide parsing guidance.
  • Clarify how schema fields should be populated for Linux environments, including domain types and user/session IDs.
  • Ensure that all guidance and examples are source-agnostic or provide parity between Windows and Linux systems.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/normalization-schema-file-event.md ...n/articles/sentinel/normalization-schema-file-event.md
High Priority View Details →
Scanned: 2026-01-09 00:34
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First Windows Examples 🔧 Windows Tools
Summary
The documentation demonstrates a mild Windows bias. Windows terminology and examples (e.g., 'Windows File Explorer', 'C:\Windows\System32\notepad.exe', 'explorer.exe') are presented first or exclusively in illustrative sections, such as entity relationships and path structure. Windows-specific notes (e.g., about session ID conversion and case sensitivity) are more detailed than Linux/Unix equivalents. While Unix paths and concepts are mentioned, they are generally secondary and less detailed. There are no Linux/Powershell command examples, but the schema is cross-platform in intent.
Recommendations
  • Provide Linux/Unix examples alongside Windows ones in all illustrative sections (e.g., show a Linux user renaming a file with Nautilus or command line).
  • Ensure parity in explanatory notes (e.g., discuss Linux session IDs and process naming conventions where Windows details are given).
  • List Unix path formats before or alongside Windows formats in tables and explanations.
  • Include references to Linux/Unix tools and patterns (e.g., mention file operations via shell, SFTP, or Linux desktop environments) where Windows tools are cited.
  • Add explicit Linux/Powershell query or parser examples if relevant to usage.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/normalization-schema-process-event.md ...rticles/sentinel/normalization-schema-process-event.md
High Priority View Details →
Scanned: 2026-01-09 00:34
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Windows Examples Windows Concepts
Summary
The documentation exhibits a Windows bias in several ways: Windows paths and process names (e.g., C:\Windows\explorer.exe, rundll32.exe) are used exclusively in examples, and concepts such as integrity levels and User Access Control (UAC) are described only in terms of Windows features. References to process session IDs and other fields often specify Windows-specific formats and conversions, with Linux mentioned only in passing and never illustrated. Key process concepts (e.g., integrity levels) link to Windows documentation, and there are no Linux or cross-platform examples, tools, or references.
Recommendations
  • Provide Linux-specific examples alongside Windows ones, such as using /usr/bin/bash or /usr/bin/sshd for process names and paths.
  • Describe Linux equivalents for concepts like process integrity levels, privilege elevation (e.g., setuid/setgid), and session IDs.
  • Include references to Linux documentation (e.g., man pages, kernel docs) where relevant.
  • Clarify which fields and concepts apply to Linux, macOS, or other platforms, and note any differences.
  • Add examples of process events from Linux EDR or audit sources (e.g., auditd, sysmon for Linux).
  • Avoid using only Windows-centric terminology (e.g., UAC, Win32 apps) without mentioning alternatives or equivalents for other platforms.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/normalization-schema-user-management.md ...icles/sentinel/normalization-schema-user-management.md
High Priority View Details →
Scanned: 2026-01-09 00:34
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Windows Heavy Examples
Summary
The documentation demonstrates a Windows bias in several ways: Windows-specific identifiers (SID) and naming formats are consistently listed before Linux equivalents (UID), and Windows domain/user/group name formats are prioritized in examples and recommended normalization fields. Windows-centric terminology (such as 'Contoso\user', 'Primary Domain Controller', and references to Windows session ID formats) is used throughout, with Linux equivalents mentioned but not given equal prominence or example coverage. There are no Linux-specific examples or tools referenced, and the normalization guidance is tailored to Windows patterns first.
Recommendations
  • Present Linux (UID, simple username, group name) and Windows (SID, domain\user) formats with equal prominence, alternating order or grouping them together.
  • Provide explicit Linux examples (e.g., UID: 1001, username: 'alice', group: 'sudo') alongside Windows examples in all relevant fields.
  • Include normalization and conversion guidance for Linux-specific scenarios (e.g., hexadecimal UID/GID values, Linux session IDs).
  • Reference Linux tools and patterns (such as /etc/passwd, /etc/group, getent, id command) where relevant, not just Windows-centric tools.
  • Avoid using Windows domain names and formats as the default or first example; use generic or cross-platform examples where possible.
  • Add a section or note highlighting cross-platform applicability and parity, ensuring Linux and other OSes are equally supported in schema normalization.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/notebook-get-started.md ...cs/blob/main/articles/sentinel/notebook-get-started.md
High Priority View Details →
Scanned: 2026-01-09 00:34
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Missing Linux Example
Summary
The documentation page demonstrates a moderate Windows bias. It consistently references Microsoft Sentinel in the Defender and Azure portals (both Windows-centric), and the workflow is described primarily for Azure Machine Learning workspaces. While there is a mention of running notebooks locally and a brief reference to Linux Host Explorer, the main examples and instructions do not provide explicit Linux setup or usage guidance. Windows hosts are mentioned before Linux hosts in the Entity Explorer series, and PowerShell/C# examples are referenced as alternatives to MSTICPy, with no mention of Bash or Linux-native scripting. There are no step-by-step Linux-specific instructions or examples.
Recommendations
  • Add explicit instructions for running the Getting Started Guide notebook on Linux systems, including installation steps for Python and MSTICPy using Linux package managers (e.g., apt, yum).
  • Provide examples of configuring and launching Jupyter notebooks in popular Linux environments (e.g., Ubuntu, CentOS) outside of Azure Machine Learning.
  • Include Linux shell (Bash) equivalents where PowerShell or C# are mentioned, or clarify cross-platform compatibility.
  • Ensure that references to hosts (Windows and Linux) are balanced and that Linux hosts are not always mentioned after Windows hosts.
  • Add troubleshooting tips for common Linux-specific issues (e.g., file permissions, environment variables).
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/notebooks.md ...cs/azure-docs/blob/main/articles/sentinel/notebooks.md
High Priority View Details →
Scanned: 2026-01-09 00:34
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First Powershell Heavy 🔧 Windows Tools
Summary
The documentation page demonstrates a Windows bias primarily through the prioritization of Windows-centric tools and patterns. PowerShell is mentioned explicitly as a method for managing Azure roles, and Windows/PowerShell options are listed before Linux equivalents (such as Azure CLI). The documentation references Microsoft Sentinel and Azure Machine Learning, which are typically associated with Windows environments, and does not provide Linux-specific examples or guidance for running Jupyter notebooks or managing permissions from Linux systems.
Recommendations
  • Include explicit examples for Linux users, such as using Bash and Azure CLI for role assignments and workspace management.
  • Present cross-platform instructions together, or alternate the order so Linux tools (e.g., Azure CLI) are not always listed after Windows tools (e.g., PowerShell).
  • Add a section or note on how to use Jupyter notebooks with Microsoft Sentinel from Linux environments, including installation and access instructions.
  • Reference Linux-friendly tools and workflows where possible, and clarify that the described processes are platform-agnostic unless there are genuine platform limitations.
  • Provide sample commands for both Windows (PowerShell) and Linux (Bash/Azure CLI) when discussing administrative tasks.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/resource-context-rbac.md ...s/blob/main/articles/sentinel/resource-context-rbac.md
High Priority View Details →
Scanned: 2026-01-09 00:34
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Missing Linux Example
Summary
The documentation page demonstrates Windows bias by prioritizing Windows-centric scenarios and tools. Windows event data is the only specific data type mentioned in the introductory example, and Windows administrators are referenced in table-level RBAC scenarios. There is no mention of Linux-specific event types (e.g., Linux audit logs) or Linux administrators. While Syslog and CEF (cross-platform log formats) are referenced, examples and scenarios do not explicitly address Linux use cases or provide parity for Linux system management. No Linux-specific tools, patterns, or examples are given.
Recommendations
  • Add Linux-specific examples, such as granting access to Linux audit logs or SSH logs, alongside Windows event data scenarios.
  • Include references to Linux administrators and their access requirements in the RBAC scenario tables.
  • Provide sample configurations or code snippets for common Linux log forwarding tools (e.g., rsyslog, auditd) in addition to Logstash.
  • Mention Linux VM resource IDs and Azure Arc onboarding for Linux systems explicitly, not just generically as 'on-premises VM'.
  • Ensure that all examples and recommendations are presented with equal weight for both Windows and Linux environments.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/sap/deploy-sap-btp-solution.md .../main/articles/sentinel/sap/deploy-sap-btp-solution.md
High Priority View Details →
Scanned: 2026-01-09 00:34
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Missing Linux Example
Summary
The documentation page demonstrates Windows bias primarily through the exclusive use of PowerShell for automation and scripting examples, specifically for rotating the BTP client secret. All provided CLI/script examples use PowerShell and Azure PowerShell modules, with no mention of Bash, Linux shell, or cross-platform alternatives. There is no guidance for Linux users or examples using Azure CLI (az), which is cross-platform. The documentation also references Azure Key Vault and Azure portal workflows, which are accessible from any OS, but the automation focus is Windows-centric.
Recommendations
  • Provide equivalent Bash or Azure CLI script examples for Linux/macOS users, especially for secret rotation and connector management.
  • Explicitly state cross-platform support for all automation steps, and clarify which tools are required for each OS.
  • Add notes or links to documentation for Linux users on installing and using Azure CLI and relevant authentication methods.
  • Where possible, use Azure CLI commands in examples, as they are natively cross-platform, or offer both PowerShell and Bash/CLI alternatives side-by-side.
  • Review all automation and scripting sections to ensure Linux parity and avoid implying that Windows/PowerShell is the only supported or recommended environment.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/scheduled-rules-overview.md ...lob/main/articles/sentinel/scheduled-rules-overview.md
High Priority View Details →
Scanned: 2026-01-09 00:34
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
🔧 Windows Tools Powershell Heavy Windows First Missing Linux Example
Summary
The documentation page demonstrates Windows bias primarily in its 'Next steps' section, where it recommends automating rule enablement via API and PowerShell, with a direct link to the PowerShell Gallery and no mention of Linux-native automation tools or shell scripting alternatives. Throughout the page, examples and tooling references are either Windows-centric or omit Linux equivalents, such as Bash, Azure CLI, or cross-platform scripting. This may hinder parity for Linux users and reinforce a perception that Windows is the primary or preferred platform for managing Microsoft Sentinel analytics rules.
Recommendations
  • Include Linux-native automation examples, such as using Bash scripts, Azure CLI, or Python for rule management.
  • When mentioning PowerShell, clarify that PowerShell Core is cross-platform and provide usage examples for Linux/macOS.
  • Add explicit references and links to Azure CLI documentation and usage for exporting/importing rules.
  • Present automation options in a platform-neutral order (e.g., 'API, Azure CLI, PowerShell, Bash'), rather than listing Windows tools first.
  • Where possible, provide side-by-side examples for Windows (PowerShell) and Linux/macOS (Bash/Azure CLI) to ensure parity and inclusivity.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/sentinel-hunting-rules-creation.md ...n/articles/sentinel/sentinel-hunting-rules-creation.md
High Priority View Details →
Scanned: 2026-01-09 00:34
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Windows First
Summary
The documentation page exhibits Windows bias primarily in the section describing how to generate a GUID for the 'id' attribute. It explicitly mentions the PowerShell 'New-GUID' cmdlet as a method for GUID generation, linking to Windows-specific documentation, and does not provide equivalent Linux or cross-platform alternatives. The Windows/PowerShell method is mentioned before generic options (such as 'any development tool' or 'online generator'), reinforcing a Windows-first approach. No Linux shell or platform-neutral example is given for GUID generation.
Recommendations
  • Provide Linux and cross-platform examples for GUID generation, such as using 'uuidgen' in Bash or Python's 'uuid' module.
  • Mention platform-neutral methods before platform-specific ones, or present them together for parity.
  • Avoid linking only to Windows/PowerShell documentation; include references to Linux and macOS equivalents.
  • Review other tooling or process references to ensure Linux and macOS users are equally supported.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/sentinel-analytic-rules-creation.md .../articles/sentinel/sentinel-analytic-rules-creation.md
High Priority View Details →
Scanned: 2026-01-09 00:34
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
🔧 Windows Tools Powershell Heavy Windows First
Summary
The documentation page exhibits Windows bias primarily in the section describing GUID generation, where PowerShell's New-GUID cmdlet is mentioned explicitly as a method, with no Linux or cross-platform alternatives provided. The only tool referenced for this common development task is a Windows-specific one, and it is listed before generic alternatives ("any development tool, an online generator"). No Linux command-line example (such as uuidgen) is given. The rest of the documentation is platform-neutral, focusing on YAML, KQL, and Microsoft Sentinel concepts.
Recommendations
  • Provide Linux/macOS equivalents for GUID generation, such as the uuidgen command-line tool.
  • List platform-neutral or cross-platform methods first (e.g., 'any development tool, online generator'), then mention OS-specific tools.
  • Include example commands for both Windows (PowerShell) and Linux/macOS (uuidgen) to ensure parity.
  • Review other sections for similar tool references and ensure alternatives are provided for non-Windows environments.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/sentinel-playbook-creation.md ...b/main/articles/sentinel/sentinel-playbook-creation.md
High Priority View Details →
Scanned: 2026-01-09 00:34
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Missing Linux Example Windows First
Summary
The documentation page demonstrates a strong Windows bias in the sections describing how to generate and sanitize ARM templates for playbooks. The only provided method is a PowerShell script, with instructions and troubleshooting focused on Windows environments (Visual Studio Code, Windows PowerShell, PowerShell Core). There are no Linux or cross-platform alternatives mentioned, nor are there CLI/bash examples or notes about running the script on Linux/macOS. The documentation assumes familiarity with Windows tooling and does not address Linux users' needs.
Recommendations
  • Provide equivalent instructions and examples for Linux and macOS users, such as using Azure CLI, Bash scripts, or cross-platform PowerShell (pwsh) with explicit Linux setup steps.
  • Mention and link to cross-platform tools for ARM template generation and sanitization, or clarify PowerShell Core compatibility on Linux/macOS.
  • Add troubleshooting notes for non-Windows environments (e.g., script execution policies, dependencies, file paths).
  • Consider presenting Linux/macOS instructions before or alongside Windows instructions to avoid 'windows_first' bias.
  • Explicitly state platform requirements and alternatives for each step involving tooling.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/sentinel-summary-rules-creation.md ...n/articles/sentinel/sentinel-summary-rules-creation.md
High Priority View Details →
Scanned: 2026-01-09 00:34
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
🔧 Windows Tools Windows First Missing Linux Example
Summary
The documentation page exhibits Windows bias by referencing PowerShell's New-GUID cmdlet as the primary method for generating GUIDs, without mentioning Linux or cross-platform alternatives. No Linux-specific tools or commands are provided for this task, and the Windows/PowerShell approach is presented first and exclusively.
Recommendations
  • Include Linux and cross-platform methods for generating GUIDs, such as the 'uuidgen' command (available on most Linux distributions) or Python's uuid module.
  • Present platform-neutral or cross-platform solutions before or alongside Windows-specific tools.
  • Add explicit examples for both Windows (PowerShell) and Linux/macOS (shell commands), ensuring parity in guidance.
  • Review other sections for similar bias and ensure that any tooling or workflow recommendations are inclusive of non-Windows environments.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/stix-objects-api.md ...e-docs/blob/main/articles/sentinel/stix-objects-api.md
High Priority View Details →
Scanned: 2026-01-09 00:34
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Missing Linux Example Windows First
Summary
The documentation provides a detailed PowerShell example for interacting with the API, relying on the MSAL.PS module and Windows certificate store paths, but does not offer equivalent Linux or cross-platform examples (e.g., Bash, curl, Python). Windows-centric tools and patterns are presented exclusively and first, which may hinder accessibility for Linux users.
Recommendations
  • Add sample API request examples using curl and/or Python requests, which are cross-platform and commonly used on Linux.
  • Document how to acquire and use certificates and tokens on Linux (e.g., using OpenSSL, environment variables, or .pem files) instead of Windows certificate store.
  • Include instructions for installing and using MSAL libraries in Python or other languages/platforms popular on Linux.
  • Explicitly mention that the API can be called from any OS and provide parity in examples for both Windows and Linux environments.
  • Consider reordering examples so that cross-platform or Linux options are presented before or alongside Windows/PowerShell examples.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/sentinel-solutions-deploy.md ...ob/main/articles/sentinel/sentinel-solutions-deploy.md
High Priority View Details →
Scanned: 2026-01-09 00:34
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First Powershell Heavy Missing Linux Example
Summary
The documentation page demonstrates a Windows bias primarily through its focus on Microsoft portals (Defender and Azure), and by referencing PowerShell as a deployment option for ARM templates, without providing equivalent Linux-specific examples or mentioning cross-platform CLI tools first. There are no explicit Linux command-line examples, and the documentation assumes users are operating in a Windows-centric environment.
Recommendations
  • Add explicit Linux examples for ARM template deployment, such as using Azure CLI on Linux or Bash scripts.
  • Mention cross-platform tools (e.g., Azure CLI) before or alongside PowerShell, clarifying that both Windows and Linux users are supported.
  • Include screenshots or instructions for accessing Microsoft Sentinel features from Linux environments, where applicable.
  • Clearly state platform requirements and note any differences in experience or tooling for Linux users.
  • Provide links to documentation on using Microsoft Sentinel and Azure services from Linux systems.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/skill-up-resources.md ...docs/blob/main/articles/sentinel/skill-up-resources.md
High Priority View Details →
Scanned: 2026-01-09 00:34
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Powershell Heavy Missing Linux Example
Summary
The documentation page for Microsoft Sentinel skill-up training demonstrates a moderate Windows bias. Windows and PowerShell tools are mentioned first or exclusively in several places, such as data connector integration, agent health monitoring, and API usage. Windows-centric terminology (e.g., Windows Events, Windows DNS, WEF) is prevalent, and PowerShell is highlighted as the main automation method. Linux equivalents (e.g., Sysmon for Linux, Linux agent health) are mentioned less frequently and often as secondary options. There are few explicit Linux-focused examples, and Linux tools or patterns are rarely given parity in explanations or walkthroughs.
Recommendations
  • Ensure Linux examples and tools are presented alongside Windows ones, especially in sections about data collection, agent health, and automation.
  • Provide PowerShell and Bash/CLI examples for API usage and automation tasks.
  • Highlight Linux-specific connectors, logs, and monitoring solutions with equal detail as Windows ones.
  • Include walkthroughs or case studies that focus on Linux or mixed environments.
  • Review terminology to avoid Windows-centric language when describing generic SIEM concepts.
  • Expand documentation on Sysmon for Linux, Linux agent health, and other Linux-native integrations.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/ueba-reference.md ...ure-docs/blob/main/articles/sentinel/ueba-reference.md
High Priority View Details →
Scanned: 2026-01-09 00:34
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Missing Linux Example
Summary
The documentation demonstrates a Windows bias in several areas. Windows-specific event sources (such as Windows Security Events, Windows Forwarded Events, and Windows device logon events) are listed and described in detail, while Linux equivalents (e.g., Linux audit logs, syslog, SSH logins) are not mentioned at all. Device-related enrichments and examples focus exclusively on Windows (e.g., 'Device family: Windows', 'Operating system: Windows 10'), with no reference to Linux, macOS, or other platforms. There are no examples or guidance for Linux-based data sources, connectors, or device insights, and no mention of Linux-specific security events or log schemas. The documentation assumes a Microsoft-centric environment, with Active Directory and Defender for Identity as the only on-premises identity providers, and does not address hybrid or non-Windows scenarios.
Recommendations
  • Add Linux-specific data sources and connectors (e.g., Linux audit logs, syslog, SSH authentication logs) to the UEBA data sources table.
  • Include device enrichment examples for Linux and macOS (e.g., 'Device family: Linux', 'Operating system: Ubuntu 22.04', 'Device type: Server').
  • Document how UEBA analyzes and enriches Linux and non-Windows device events, including schema fields and sample values.
  • Provide parity in event categories and enrichments for Linux, such as failed SSH logins, sudo usage, and Linux user management events.
  • Clarify whether non-Windows devices are supported and, if so, how to onboard and analyze them in Microsoft Sentinel UEBA.
  • Mention Linux identity providers (e.g., LDAP, FreeIPA) if supported, or explicitly state limitations.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/use-matching-analytics-to-detect-threats.md ...s/sentinel/use-matching-analytics-to-detect-threats.md
High Priority View Details →
Scanned: 2026-01-09 00:34
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Missing Linux Example
Summary
The documentation page demonstrates a Windows bias by listing Windows-specific data sources (Windows DNS, Windows Firewall) and connectors before Linux equivalents, and by providing examples and solutions focused on Windows tools. While syslog and CEF are mentioned, there are no explicit Linux-focused examples, nor are Linux-specific tools or patterns discussed. The configuration and triage steps reference Microsoft portals and interfaces, which are platform-agnostic but do not address Linux-specific operational concerns.
Recommendations
  • Add explicit Linux-focused examples, such as configuring matching analytics with Linux-based syslog sources or Linux firewall logs.
  • Include references to Linux-native tools (e.g., iptables, auditd) and how their logs can be ingested and matched.
  • Balance the order of data source presentation, listing Linux and Windows sources together or alternating, rather than listing Windows sources first.
  • Provide screenshots or walkthroughs using Linux data sources to demonstrate parity.
  • Clarify any platform-specific requirements or differences in connector setup for Linux environments.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/data-source-schema-reference.md ...main/articles/sentinel/data-source-schema-reference.md
High Priority View Details →
Scanned: 2026-01-08 00:53
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Missing Linux Example
Summary
The documentation page demonstrates a Windows bias by listing Windows-centric data sources (such as IIS Logs and VMinsights) before Linux equivalents, and by referencing Windows-native tools and schemas (e.g., IIS, VMinsights, AzureActivity) more prominently. Only one Linux-specific example (Syslog) is provided, with no parity for other common Linux log types (e.g., auth.log, secure, auditd). There is a lack of Linux-specific schema references and examples, and the documentation does not provide equal coverage or guidance for Linux environments compared to Windows.
Recommendations
  • Add more Linux-specific data source examples, such as auditd, auth.log, and other common Linux logs.
  • Provide schema references and integration guidance for popular Linux logging frameworks (e.g., journald, rsyslog, auditd).
  • Ensure Linux data sources are listed with equal prominence and detail as Windows data sources.
  • Include example log entries and mapping for Linux sources similar to what is provided for Windows sources.
  • Review ordering and presentation to avoid listing Windows/Windows-centric tools first unless justified by usage statistics.
Sentinel https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/includes/sap-agentless-prerequisites.md ...icles/sentinel/includes/sap-agentless-prerequisites.md
High Priority View Details →
Scanned: 2026-01-08 00:53
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy Missing Linux Example Windows First
Summary
The documentation provides only a PowerShell script as the example for triggering the SAP prerequisites checker, which is specific to Windows environments. There are no equivalent examples for Linux or cross-platform tools (e.g., curl, bash). The PowerShell example is given without mention of alternatives, implying a Windows-first approach and missing Linux parity.
Recommendations
  • Add equivalent examples using Linux-native tools such as curl or wget, and bash scripting.
  • Explicitly mention that any REST client can be used, and provide cross-platform sample commands.
  • Reorder or supplement the documentation so that Linux and Windows examples are presented with equal prominence.
  • Clarify any platform-specific requirements or limitations for running the prerequisites checker.