GEMXIT • Microsoft Security • Agent Foskett

Who is Agent Foskett?

Agent Foskett is a fictional educational cyber security persona created by GEMXIT. Agent Foskett helps organisations understand Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID and Kusto Query Language (KQL) through practical, real-world investigation scenarios. Through the Microsoft Security Investigation Hub, the growing Agent Foskett Academy and the first Agent Foskett book, the persona translates complex security telemetry into clear, actionable lessons covering identity protection, email security, cloud investigation, proactive threat hunting, detection engineering and emerging cyber risks.

Explore more: Microsoft SecurityAzure Security MelbourneKQL Threat Hunting Guide
Who is Agent Foskett - GEMXIT Cyber Security Briefings
The short answer

Agent Foskett is a fictional educational cyber security persona created by GEMXIT. The character is used to teach Microsoft Defender XDR investigations, Microsoft Sentinel, Microsoft Entra ID and Kusto Query Language (KQL) through practical, real-world investigation scenarios, the growing Agent Foskett Academy, the SOC Analyst Academy and the Agent Foskett book. The KQL Academy develops practical skills in advanced threat hunting, detection engineering and proactive investigation workflows.

Real Microsoft security investigations
Practical KQL threat hunting and detection engineering
Defender, Sentinel, Entra ID and Azure

Agent Foskett is now also an author

The same evidence-first investigation style used across the Hub and Academy is now available in the first published Agent Foskett book.
Published • Available Now

Agent Foskett Investigates Microsoft Security

The first Agent Foskett book brings together 30 real-world investigations using Microsoft Defender XDR, Microsoft Sentinel, KQL and Microsoft Security Copilot.

The book follows the same approach as the Academy: build the timeline, correlate the telemetry, challenge the working theory and keep asking the question that matters — what does the evidence actually prove?

30 Real-World Investigations Microsoft Defender XDR Microsoft Sentinel KQL Microsoft Security Copilot Kindle • Paperback • Hardcover

Published worldwide 1 September 2026. Available now in Kindle, Paperback and Hardcover editions.

Start here

New to Agent Foskett? Start with some of the most popular Microsoft security investigations and KQL threat hunting guides.
KQL Threat Hunting Guide
EmailEvents Investigations
DMARC & Spoofing
MFA Session Hijacking
Microsoft Defender XDR
Detection Engineering
Agent Foskett Book

Agent Foskett is where security data becomes a story

As a fictional educational cyber security persona, Agent Foskett helps defenders understand the story hidden inside Microsoft security telemetry.
Most organisations already have powerful security platforms in place. Microsoft Defender is collecting email, endpoint and cloud signals. Microsoft Sentinel may be receiving logs. Entra ID is recording sign-ins, MFA prompts, Conditional Access decisions and identity risk. Azure is producing activity, configuration and exposure data.

But the real question is not whether the tools exist.

The real question is: does anyone understand what the data is saying?

That is why Agent Foskett exists. The briefings take technical signals — such as DMARC failures, suspicious sign-ins, unexpected URL clicks, after-hours downloads, exposed cloud services or unusual PowerShell activity — and turn them into clear investigation lessons.
Lesson: security is not just configuration — it is interpretation.

What Agent Foskett focuses on

The briefings sit at the intersection of Microsoft security, real-world investigation and practical business risk.
Microsoft Defender investigations EmailEvents, URLClickEvents, DeviceProcessEvents, authentication outcomes, spoofing signals and suspicious endpoint behaviour.
KQL threat hunting & detection engineering Practical queries that help security teams ask better questions of their data across Defender, Sentinel and Microsoft 365, then turn successful hunts into baselines, detections and repeatable defensive capability.
Email spoofing and DMARC Sender mismatch, AuthenticationDetails, SPF, DKIM, DMARC, CompAuth and delivered messages that should not be trusted.
Identity and MFA risk Entra ID sign-ins, session hijacking, token reuse, Conditional Access exclusions, legacy authentication and account behaviour.
Azure and cloud exposure Public storage, exposed RDP, failed backups, weak resilience, misconfigured services and cloud assumptions that create risk.
AI governance and new risks AI agents, broad access, prompt risk, data exposure and why AI tools need identity, governance and monitoring.

Why Agent Foskett matters

Security does not usually fail because one person forgot to buy a tool. It fails because normal business decisions create small gaps over time: one temporary exclusion, one public setting, one transport rule left disabled, one admin account without enough protection, one alert nobody understood.

Agent Foskett briefings are designed to make those quiet risks visible. The aim is not fear. The aim is clarity. When organisations can see the story behind their logs, they can make better decisions, respond faster and build stronger security habits.
Lesson: the logs often know before the business does — but only if someone asks the right questions.
Visibility before incidents
Practical investigation thinking
Microsoft security context
Better questions from better data

The Agent Foskett Method

Every investigation starts with a clue, not a conclusion. The method is designed to slow the analyst down just enough to ask better questions, connect the evidence and reach a conclusion that can be defended.
1
Something does not look rightStart with the alert, anomaly, user report or small clue that deserves a closer look.
2
Follow the evidenceDo not decide what happened first. Examine the telemetry and let the evidence shape the investigation.
3
Build the timelinePut sign-ins, processes, emails, cloud activity and security events into chronological order.
4
PivotMove from account to IP, device, process, file, application, mailbox or session as the evidence develops.
5
Correlate the signalsOne event rarely tells the whole story. Bring identity, endpoint, email and cloud telemetry together.
6
Challenge the theoryLook for evidence that could disprove the working theory. A good investigation survives being questioned.
7
Reach a defensible conclusionMove beyond “this looks suspicious” and explain what happened, what did not happen and what the evidence supports.

What does “The Logs Already Knew” mean?

The alert is only the beginning. The evidence tells the story.

“The Logs Already Knew” captures the central idea behind Agent Foskett. Long before an investigation reaches its conclusion, the environment may already contain the sign-in, process, email, session, configuration or cloud event that explains what happened. The investigator's job is to find those signals, put them in context and connect them without forcing the evidence to fit an assumption.

That is why the recurring Agent Foskett question is simple: what do the logs actually prove?

Who created Agent Foskett?

Agent Foskett was created by Jonathan Foskett through GEMXIT as a way to teach cyber security investigation through stories rather than isolated product features.

The approach combines practical IT and Microsoft security experience with the structure of technical training: begin with a realistic clue, investigate the available evidence, explain the reasoning and finish with a lesson that can be applied to the next case.

Agent Foskett is fictional. The investigation mindset behind the character is deliberately practical: follow the evidence, build the timeline, question assumptions and never stop at the first explanation.

The investigation continues

Agent Foskett is not a finished collection of lessons. New investigations continue to follow the way Microsoft security, identity, cloud platforms, attacker techniques and AI-assisted security operations evolve.

The Investigation Hub, Academy, SOC Analyst learning path and published books are different parts of the same idea: help people become better investigators by learning how to recognise weak signals, connect evidence and explain what happened.
The next clue is already somewhere in the logs.

How Agent Foskett connects to GEMXIT

Agent Foskett is part of GEMXIT’s broader mission: Develop IT. Protect IT. GEMXIT.

GEMXIT works across cloud services, cyber security, Microsoft training and software development. Agent Foskett brings those areas together through the Investigation Hub, the Agent Foskett Academy, detection engineering content and the first published book, showing how systems, users, identity, cloud services and security telemetry interact in the real world.

For organisations using Microsoft 365, Azure, Defender, Sentinel or Entra ID, the briefings provide a practical way to understand security gaps before they become operational or business problems.
Explore the Agent Foskett Investigation Hub, Academy and Book
Explore practical Microsoft Defender, Sentinel, Entra ID, Azure and KQL investigations, continue through the Agent Foskett Academy, or discover the first Agent Foskett book.

Related Agent Foskett investigations

Continue the investigation with practical Microsoft security scenarios focused on identity risk, email telemetry, suspicious behaviour and the signals hidden behind normal-looking activity.
Detect DMARC Fail Emails in Microsoft Defender Investigate emails where sender authentication failed, then determine whether the message was still delivered and trusted by the environment.
Lesson: DMARC fail does not always mean blocked.
DMARC EmailEvents KQL
The MFA Was Enabled… But the Attacker Still Got In A practical investigation into session hijacking, token reuse and why successful MFA authentication does not always end the investigation.
Lesson: MFA protects authentication, but trusted sessions can still become a major risk.
MFA Identity Session Risk
The After-Hours Download Nobody Questioned Files started moving late at night, but everything appeared technically allowed. Investigate suspicious SharePoint access and behavioural anomalies.
Lesson: allowed access does not always mean safe behaviour.
SharePoint Behaviour Data Access
Cyber Security Is Not Just Antivirus Explore how modern attacks increasingly target identities, sessions, cloud services and trusted access rather than traditional malware alone.
Lesson: modern investigations focus on telemetry, behaviour and hidden signals — not just antivirus alerts.
Modern Threats Identity Telemetry
Investigating a Business Email Compromise (BEC) Follow a compromised mailbox investigation across email, identity and endpoint activity to understand how attackers gain access and abuse trusted accounts.
Lesson: BEC investigations rarely stop at the email — the identity trail often tells the rest of the story.
BEC Email Identity
Investigating Living Off The Land (LOLBins) Investigate trusted Windows tools such as rundll32, certutil, mshta and PowerShell when attackers use normal binaries to hide suspicious activity.
Lesson: trusted tools can still become attacker tools when the process chain and command line look wrong.
LOLBins Endpoint KQL
Need someone to look at what your Microsoft security data is really saying?
GEMXIT can help review Microsoft 365, Defender, Sentinel, Entra ID and Azure security posture with practical, plain-English findings.

Who is Agent Foskett?

Agent Foskett is a fictional educational cyber security persona created by GEMXIT. Through the Microsoft Security Investigation Hub, the growing Agent Foskett Academy and the Agent Foskett book, the character teaches Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Azure Security, Kusto Query Language (KQL), proactive threat hunting and detection engineering using practical real-world investigation scenarios.

Agent Foskett briefings highlight real-world scenarios including email spoofing, DMARC failures, session hijacking, impossible travel sign-ins, exposed cloud services, AI governance risks and misconfigured security controls.

The Agent Foskett hub connects practical investigations across Microsoft Defender, Sentinel, Entra ID, Exchange Online and Azure so organisations can understand the signals behind security events and improve their defensive posture.