Agent Foskett Academy
Learn practical Microsoft security through over 300 published lessons covering KQL, Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Defender for Endpoint, Microsoft Defender for Cloud and Microsoft Security Copilot β now joined by the 100-lesson SOC Analyst Academy, with 21 lessons already published. Modules 1 and 2 are complete and Module 3: Identity Incidents is underway. The KQL Academy has now reached Lesson 170, progressing from foundations and investigation workflows into complete identity, endpoint and cloud investigations, proactive threat hunting and advanced detection engineering.
Practical Microsoft security training
Start with KQL foundations, step into the SOC Analyst Academy with 21 published lessons, or choose a dedicated academy for Sentinel, Entra ID, Defender for Endpoint, Defender for Cloud or Microsoft Security Copilot.
Take the Academy Mindset Into the Investigation
Agent Foskett Investigates Microsoft Security is officially scheduled for release on 1 September 2026, with Kindle, paperback and hardcover editions.
The book brings the skills taught throughout the Academy into 30 real-world investigations using Microsoft Defender XDR, Microsoft Sentinel, KQL and Microsoft Security Copilot.
Follow the evidence across identity, email, endpoint and cloud telemetry, build defensible timelines and see how the investigator mindset turns individual security events into a complete story.
Explore the Agent Foskett Academy structure
What is Agent Foskett Academy?
Browse the Academy by learning path
π Academy lessons by learning path
join techniques to correlate data across multiple Microsoft Defender XDR tables and build more powerful threat hunting queries.
let statements in KQL to create reusable variables, simplify complex queries and build more efficient Microsoft Defender XDR threat hunting investigations.
Continue into the dedicated Agent Foskett KQL Academy for the latest lessons, including Module 14: Advanced Detection Engineering & Proactive Threat Hunting.
Your first KQL idea
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
EmailEvents | where Timestamp > ago(24h) | project Timestamp, SenderFromAddress, RecipientEmailAddress, Subject, DeliveryAction | order by Timestamp desc
How to think in KQL
Learn through real Agent Foskett investigations
Final thought
Start with one question. Choose the right table. Filter the noise. Project the useful fields. Follow the evidence.
That is how investigations begin.
Agent Foskett Academy exists to help defenders learn KQL through real Microsoft security stories.
It is: βWhat question am I asking the data?β
Continue learning with Microsoft Defender KQL Threat Hunting Guide, KQL Threat Hunting in Defender and Sentinel, EmailEvents KQL Guide, KQL Email Spoofing, Microsoft Security, Security Operations and the GEMXIT Security Review.
Develop IT. Protect IT. GEMXIT PTY LTD | GEMXIT UK LTD