Agent Foskett Academy
KQL is not just query syntax.
It is how investigators ask questions of telemetry.
Inside Microsoft Defender XDR, Microsoft Sentinel, Entra ID and Exchange Online, the logs are constantly telling a story. The challenge is learning how to read that story, narrow the noise and follow the evidence.
Agent Foskett Academy was built to help analysts, engineers, students and defenders learn practical KQL through real-world investigations, Microsoft security telemetry and genuine threat hunting workflows.
This is not about memorising commands. It is about learning how to think like an investigator.
Academy overview
Learn how to investigate Microsoft security telemetry using practical KQL examples, Defender XDR hunting, Sentinel investigations and real-world attack scenarios.
What is Agent Foskett Academy?
π KQL Learning Path
π§ New lessons coming soon
Your first KQL idea
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
EmailEvents | where Timestamp > ago(24h) | project Timestamp, SenderFromAddress, RecipientEmailAddress, Subject, DeliveryAction | order by Timestamp desc
How to think in KQL
Beginner topics coming next
Learn through real Agent Foskett investigations
Final thought
Start with one question. Choose the right table. Filter the noise. Project the useful fields. Follow the evidence.
That is how investigations begin.
Agent Foskett Academy exists to help defenders learn KQL through real Microsoft security stories.
It is: βWhat question am I asking the data?β
Continue learning with Microsoft Defender KQL Threat Hunting Guide, KQL Threat Hunting in Defender and Sentinel, EmailEvents KQL Guide, KQL Email Spoofing, Microsoft Security, Security Operations and the GEMXIT Security Review.
Develop IT. Protect IT.GEMXIT PTY LTD | GEMXIT UK LTD