100 Friday Cyber Briefings • Microsoft Defender XDR • KQL • Incident Response

One Hundred Briefings. One Investigation Mindset.

When the first Friday Cyber Briefing was published, it was simply an investigation.

An interesting Microsoft Defender event. A useful KQL query. A small lesson from real-world security work.

But after one hundred briefings, something became obvious.

The investigations were never really about PowerShell, phishing, identity, ransomware, OAuth, process trees or alerts.

They were all teaching the same thing: how to think like an investigator.

Agent Foskett 100 Friday Cyber Briefings Microsoft Defender XDR investigation mindset
Briefing #100

One hundred investigations. Hundreds of KQL queries. Thousands of Microsoft Defender events. The same lesson kept appearing: the evidence was already there.

Ask better questions
Build the timeline
Follow relationships

The investigation mindset

Tools matter. Telemetry matters. KQL matters. But the strongest investigations start with how the analyst thinks.
Ask questions first Do not start with conclusions. Start with curiosity. Why did this process launch? Why did this login succeed? Why did this email reach the user?
Build timelines One event rarely tells the whole story. Multiple events in the right order usually do.
Follow relationships Processes, users, devices, IPs, emails, apps and sessions all connect. Those relationships solve incidents.

One hundred briefings later

Across identity attacks, endpoint behaviour, email compromise, Defender XDR, Sentinel and Azure security, the pattern kept repeating.
The logs already knew Microsoft security telemetry often contains the answer before anyone understands the question.
KQL became the flashlight KQL does not create evidence. It reveals evidence that was already sitting in the data.
Every investigation starts somewhere Sometimes it starts with an alert. Sometimes with a user report. Sometimes with one strange event that does not fit.

Start with recent activity

A simple first query can help an investigator orient themselves before diving into deeper pivots.
start-with-recent-activity.kql
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
DeviceProcessEvents
| where Timestamp > ago(24h)
| project Timestamp, DeviceName, AccountName, InitiatingProcessFileName, FileName, ProcessCommandLine
| order by Timestamp desc

Expand the timeline

Once something looks unusual, expand from one table into related endpoint evidence.
expand-the-endpoint-timeline.kql
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
  7. 7
  8. 8
  9. 9
  10. 10
  11. 11
  12. 12
  13. 13
  14. 14
  15. 15
  16. 16
  17. 17
  18. 18
  19. 19
  20. 20
  21. 21
  22. 22
  23. 23
  24. 24
let InvestigationDevice = "DEVICE-NAME-HERE";
let StartTime = ago(1d);
union isfuzzy=true
(
    DeviceProcessEvents
    | where Timestamp > StartTime
    | where DeviceName =~ InvestigationDevice
    | project Timestamp, DeviceName, EvidenceType="Process", ActionType, Detail=ProcessCommandLine
),
(
    DeviceNetworkEvents
    | where Timestamp > StartTime
    | where DeviceName =~ InvestigationDevice
    | project Timestamp, DeviceName, EvidenceType="Network", ActionType, Detail=strcat(RemoteUrl, " ", RemoteIP)
),
(
    DeviceFileEvents
    | where Timestamp > StartTime
    | where DeviceName =~ InvestigationDevice
    | project Timestamp, DeviceName, EvidenceType="File", ActionType, Detail=strcat(FolderPath, "\\", FileName)
)
| order by Timestamp asc

Follow the user

Identity telemetry often explains whether activity belongs to the user, the device, the location and the session.
follow-the-user.kql
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
SigninLogs
| where TimeGenerated > ago(7d)
| project TimeGenerated, UserPrincipalName, AppDisplayName, IPAddress, Location, ConditionalAccessStatus, ResultType, ResultDescription
| order by TimeGenerated desc

Follow the device

Endpoint telemetry turns suspicion into a sequence: process, network, file and registry activity.
follow-the-device.kql
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
  7. 7
  8. 8
  9. 9
  10. 10
  11. 11
  12. 12
  13. 13
  14. 14
  15. 15
  16. 16
  17. 17
  18. 18
  19. 19
  20. 20
  21. 21
  22. 22
  23. 23
let DeviceToInvestigate = "DEVICE-NAME-HERE";
union isfuzzy=true
(
    DeviceProcessEvents
    | where Timestamp > ago(7d)
    | where DeviceName =~ DeviceToInvestigate
    | project Timestamp, DeviceName, EvidenceType="Process", Detail=ProcessCommandLine
),
(
    DeviceNetworkEvents
    | where Timestamp > ago(7d)
    | where DeviceName =~ DeviceToInvestigate
    | project Timestamp, DeviceName, EvidenceType="Network", Detail=strcat(RemoteUrl, " ", RemoteIP)
),
(
    DeviceRegistryEvents
    | where Timestamp > ago(7d)
    | where DeviceName =~ DeviceToInvestigate
    | project Timestamp, DeviceName, EvidenceType="Registry", Detail=strcat(RegistryKey, " ", RegistryValueData)
)
| order by Timestamp asc

Correlate everything

The strongest investigations cross identity, email, endpoint and cloud activity.
correlate-identity-email-endpoint-cloud.kql
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
  7. 7
  8. 8
  9. 9
  10. 10
  11. 11
  12. 12
  13. 13
  14. 14
  15. 15
  16. 16
  17. 17
  18. 18
  19. 19
  20. 20
  21. 21
  22. 22
  23. 23
  24. 24
  25. 25
  26. 26
  27. 27
  28. 28
  29. 29
  30. 30
  31. 31
  32. 32
let InvestigationUser = "user@domain.com";
let StartTime = ago(7d);
union isfuzzy=true
(
    SigninLogs
    | where TimeGenerated > StartTime
    | where UserPrincipalName =~ InvestigationUser
    | project Timestamp=TimeGenerated, EvidenceType="Identity", Detail=strcat(AppDisplayName, " ", IPAddress, " ", Location)
),
(
    EmailEvents
    | where Timestamp > StartTime
    | where RecipientEmailAddress =~ InvestigationUser
    | project Timestamp, EvidenceType="Email", Detail=strcat(SenderFromAddress, " ", Subject)
),
(
    DeviceProcessEvents
    | where Timestamp > StartTime
    | where AccountUpn =~ InvestigationUser
    | project Timestamp, EvidenceType="Endpoint", Detail=ProcessCommandLine
),
(
    CloudAppEvents
    | where Timestamp > StartTime
    | where AccountId has InvestigationUser or AccountDisplayName has InvestigationUser
    | project Timestamp, EvidenceType="CloudApp", Detail=strcat(ActionType, " ", Application)
)
| order by Timestamp asc

Lessons from the first hundred

Every briefing had its own story, but the same lessons kept coming back.
Technology helps Microsoft Defender XDR, Sentinel, Entra ID and KQL provide visibility. But thinking turns visibility into understanding.
Alerts are clues An alert is not a conclusion. It is a starting point that needs context, sequence and evidence.
Curiosity wins Every investigation improves when someone asks one more question: why did this happen?

Continue the investigation

Briefing #100 links back to the investigations that shaped the Agent Foskett mindset.
The Timeline Told The Story Sequence matters more than isolated alerts.
The Child Process Shouldn't Have Existed Parent-child process relationships can change everything.
The Script Ran From AppData Suspicious execution from a user-writable folder.
The Scheduled Task Was The Persistence Persistence hidden inside legitimate Windows automation.
Nothing Flagged The PowerShell Download Why no alert does not mean no activity.
Mshta.exe Wasn't The Real Problem A LOLBin investigation where the process tree mattered.
The Browser Spawned PowerShell Unexpected browser-to-PowerShell execution chains.
The PowerShell Command Was Base64 Encoded Encoded PowerShell and command-line obfuscation.
The Login Was Successful But The Risk Was High Successful authentication still needed investigation.
The User Clicked Accept And Gave Away The Entire Mailbox OAuth consent abuse and mailbox access.
KQL Threat Hunting Guide The practical playbook behind the investigation mindset.
Agent Foskett Academy Learn KQL and Defender XDR through structured lessons.

Agent Foskett’s takeaway

One hundred Friday Cyber Briefings. Hundreds of KQL queries. Thousands of Microsoft Defender events. Countless hours reading logs.

Yet every investigation came back to the same lesson.

The technology was never the hero.

The hero was the investigator willing to ask one more question.
Here’s to the next hundred.
Thank you to everyone who has read, shared and learned alongside the Agent Foskett Friday Cyber Briefings.
Visit the Academy

Final thought

The evidence was already there. The logs already knew. The only thing missing was someone prepared to ask the right question.
— Jonathan Foskett Agent Foskett. GEMXIT. Develop IT. Protect IT.
The investigator matters Security tooling can surface signals, but people still connect the story.
The next chapter The first hundred briefings built the foundation. The next hundred will go even deeper.
Develop IT. Protect IT.
GEMXIT PTY LTD | GEMXIT UK LTD
Talk to GEMXIT

One Hundred Briefings. One Investigation Mindset.

This 100th Agent Foskett Friday Cyber Briefing explains the investigation mindset behind Microsoft Defender XDR, KQL threat hunting, Microsoft Sentinel, Entra ID, endpoint telemetry, email security and incident response.

Microsoft Defender XDR Investigation Mindset

Security investigations require more than alerts. Analysts use KQL, timelines, process relationships, identity telemetry, email evidence, device activity and cloud app signals to understand what happened.

GEMXIT Microsoft Security And KQL Threat Hunting

GEMXIT helps organisations understand Microsoft Defender XDR, Microsoft Sentinel, Entra ID, KQL threat hunting, endpoint investigation, identity security and practical incident response.