Agent Foskett Investigates Microsoft Security
30 Real-World Investigations Using Microsoft Defender XDR, Microsoft Sentinel, KQL and Microsoft Security Copilot
Security incidents rarely arrive as complete stories. They arrive as fragments: a sign-in, a process, an email, a permission change, a line of telemetry that does not quite fit. This book follows Agent Foskett through 30 investigations and shows how evidence becomes a timeline, a timeline becomes a theory, and a theory must survive the facts before it becomes a conclusion.
“The alert is only the beginning. The evidence tells the story.”
Not another software manual
A first look at Agent Foskett in print
The investigations move across identity, email, endpoints, cloud activity and AI-assisted security operations. Defender XDR, Microsoft Sentinel, Microsoft Entra, KQL and Microsoft Security Copilot appear throughout, but every case returns to the same discipline: follow the evidence, build the timeline and challenge the theory.
The final publication is being prepared for release. Availability details and purchase links will be added here as soon as the book is published.