Release date: September 1st 2026

Agent Foskett Investigates Microsoft Security

30 Real-World Investigations Using Microsoft Defender XDR, Microsoft Sentinel, KQL and Microsoft Security Copilot

Security incidents rarely arrive as complete stories. They arrive as fragments: a sign-in, a process, an email, a permission change, a line of telemetry that does not quite fit. This book follows Agent Foskett through 30 investigations and shows how evidence becomes a timeline, a timeline becomes a theory, and a theory must survive the facts before it becomes a conclusion.

First Edition
Microsoft Security
30 Investigations
Agent Foskett book cover artwork — The Logs Already Knew

“The alert is only the beginning. The evidence tells the story.”

Not another software manual

The book is about what it feels like to investigate. Microsoft security technology is present throughout, but the tools are the instruments. The investigator still has to ask the question, test the theory and decide when the evidence is strong enough to support a conclusion.
Build the timeline Learn why isolated alerts can mislead, and why the order of events often changes what the evidence means.
Question every assumption A successful sign-in is evidence. Saying the legitimate user performed it is an interpretation until the evidence supports it.
Ask better questions with KQL Use KQL as an investigative language: narrow time, follow entities, test hypotheses and make the logs answer precise questions.
Concept mockup showing Agent Foskett Investigates Microsoft Security as a printed book
Book Preview

A first look at Agent Foskett in print

The investigations move across identity, email, endpoints, cloud activity and AI-assisted security operations. Defender XDR, Microsoft Sentinel, Microsoft Entra, KQL and Microsoft Security Copilot appear throughout, but every case returns to the same discipline: follow the evidence, build the timeline and challenge the theory.

The final publication is being prepared for release. Availability details and purchase links will be added here as soon as the book is published.

Inside the case files

Thirty investigations move from the email that looked legitimate to the identity that passed MFA, the endpoint that remembered what happened and the modern investigator working alongside Security Copilot.
Email: The SPF Check Passed for the Wrong Domain
Identity: The MFA Method Was Added at 3:14 AM
Endpoint: The Browser Spawned PowerShell
Persistence: The Scheduled Task Was Created at 2:41 AM
Cloud: The Conditional Access Policy Was in Report-Only Mode
Data: The User Shared the File with Everyone
AI: When Copilot Answered the Wrong Question
Final Case: The Final Timeline

About Jonathan Foskett

Jonathan Foskett has worked in Information Technology for more than thirty years. He is a Microsoft Certified Trainer, founder of GEMXIT PTY LTD and creator of the Agent Foskett Academy. His work brings Microsoft security investigations, KQL, Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra and Microsoft Security Copilot together around one practical philosophy: follow the evidence, build the timeline and question every assumption.

Agent Foskett Investigates Microsoft Security — Coming Soon
This page will be updated with publication formats and purchase links when the book becomes available.
Explore Agent Foskett

Agent Foskett Investigates Microsoft Security by Jonathan Foskett

Agent Foskett Investigates Microsoft Security is a forthcoming cyber security book featuring 30 real-world investigations using Microsoft Defender XDR, Microsoft Sentinel, Kusto Query Language (KQL) and Microsoft Security Copilot.

The book explores Microsoft identity security, phishing and email investigation, endpoint telemetry, privilege changes, Conditional Access, session tokens, cloud data access, PowerShell, persistence, Microsoft Entra and AI-assisted security investigation.