When I start a simulated incident, the agent picker lets me choose a Linux host, but the report it generates is the Windows scenario: a "deedees-way-in.exe" RAT launched by PowerShell with WScript as parent under C:\Users\..., a Run-key foothold in HKU\...\CurrentVersion\Run via rundll32, a remediation step to delete a registry value, and "Security Products: Windows Defender" for a Linux server.
It would be great if the simulation matched the host's OS. For Linux, for example: a malicious ELF dropped in /tmp by a "curl | sh", persistence through a cron job, systemd service or authorized_keys entry, and remediation steps for those.
We use simulations to practice our response and to show clients what an incident looks like. A Windows report for their Linux server makes that confusing. If Linux simulations aren't supported yet, a note in the picker or leaving Linux agents out of it would help.