GEMXIT • Microsoft Security • Agent Foskett

Who is Agent Foskett?

Agent Foskett is a fictional educational cyber security persona created by GEMXIT. Agent Foskett helps organisations understand Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID and Kusto Query Language (KQL) through practical, real-world investigation scenarios. Through the Microsoft Security Investigation Hub and Agent Foskett Academy, the persona translates complex security telemetry into clear, actionable lessons covering identity protection, email security, cloud security, threat hunting and emerging cyber risks.

Explore more: Microsoft SecurityAzure Security MelbourneKQL Threat Hunting Guide
Who is Agent Foskett - GEMXIT Cyber Security Briefings
The short answer

Agent Foskett is a fictional educational cyber security persona created by GEMXIT. The character is used to teach Microsoft Defender XDR investigations, Microsoft Sentinel, Microsoft Entra ID and Kusto Query Language (KQL) through practical, real-world investigation scenarios.

Real Microsoft security investigations
Practical KQL threat hunting lessons
Defender, Sentinel, Entra ID and Azure

Start here

New to Agent Foskett? Start with some of the most popular Microsoft security investigations and KQL threat hunting guides.
KQL Threat Hunting Guide
EmailEvents Investigations
DMARC & Spoofing
MFA Session Hijacking
Microsoft Defender XDR

Agent Foskett is where security data becomes a story

As a fictional educational cyber security persona, Agent Foskett helps defenders understand the story hidden inside Microsoft security telemetry.
Most organisations already have powerful security platforms in place. Microsoft Defender is collecting email, endpoint and cloud signals. Microsoft Sentinel may be receiving logs. Entra ID is recording sign-ins, MFA prompts, Conditional Access decisions and identity risk. Azure is producing activity, configuration and exposure data.

But the real question is not whether the tools exist.

The real question is: does anyone understand what the data is saying?

That is why Agent Foskett exists. The briefings take technical signals — such as DMARC failures, suspicious sign-ins, unexpected URL clicks, after-hours downloads, exposed cloud services or unusual PowerShell activity — and turn them into clear investigation lessons.
Lesson: security is not just configuration — it is interpretation.

What Agent Foskett focuses on

The briefings sit at the intersection of Microsoft security, real-world investigation and practical business risk.
Microsoft Defender investigations EmailEvents, URLClickEvents, DeviceProcessEvents, authentication outcomes, spoofing signals and suspicious endpoint behaviour.
KQL threat hunting Practical queries that help security teams ask better questions of their data across Defender, Sentinel and Microsoft 365.
Email spoofing and DMARC Sender mismatch, AuthenticationDetails, SPF, DKIM, DMARC, CompAuth and delivered messages that should not be trusted.
Identity and MFA risk Entra ID sign-ins, session hijacking, token reuse, Conditional Access exclusions, legacy authentication and account behaviour.
Azure and cloud exposure Public storage, exposed RDP, failed backups, weak resilience, misconfigured services and cloud assumptions that create risk.
AI governance and new risks AI agents, broad access, prompt risk, data exposure and why AI tools need identity, governance and monitoring.

Why Agent Foskett matters

Security does not usually fail because one person forgot to buy a tool. It fails because normal business decisions create small gaps over time: one temporary exclusion, one public setting, one transport rule left disabled, one admin account without enough protection, one alert nobody understood.

Agent Foskett briefings are designed to make those quiet risks visible. The aim is not fear. The aim is clarity. When organisations can see the story behind their logs, they can make better decisions, respond faster and build stronger security habits.
Lesson: the logs often know before the business does — but only if someone asks the right questions.
Visibility before incidents
Practical investigation thinking
Microsoft security context
Better questions from better data

How Agent Foskett connects to GEMXIT

Agent Foskett is part of GEMXIT’s broader mission: Develop IT. Protect IT. GEMXIT.

GEMXIT works across cloud services, cyber security, Microsoft training and software development. The Agent Foskett briefings bring those areas together by showing how systems, users, identity, cloud services and security telemetry interact in the real world.

For organisations using Microsoft 365, Azure, Defender, Sentinel or Entra ID, the briefings provide a practical way to understand security gaps before they become operational or business problems.
Start exploring the Microsoft Security Investigation Hub
Explore practical Microsoft Defender, Sentinel, Entra ID, Azure and KQL investigations built around real-world security lessons.

Related Agent Foskett investigations

Continue the investigation with practical Microsoft security scenarios focused on identity risk, email telemetry, suspicious behaviour and the signals hidden behind normal-looking activity.
Detect DMARC Fail Emails in Microsoft Defender Investigate emails where sender authentication failed, then determine whether the message was still delivered and trusted by the environment.
Lesson: DMARC fail does not always mean blocked.
DMARC EmailEvents KQL
The MFA Was Enabled… But the Attacker Still Got In A practical investigation into session hijacking, token reuse and why successful MFA authentication does not always end the investigation.
Lesson: MFA protects authentication, but trusted sessions can still become a major risk.
MFA Identity Session Risk
The After-Hours Download Nobody Questioned Files started moving late at night, but everything appeared technically allowed. Investigate suspicious SharePoint access and behavioural anomalies.
Lesson: allowed access does not always mean safe behaviour.
SharePoint Behaviour Data Access
Cyber Security Is Not Just Antivirus Explore how modern attacks increasingly target identities, sessions, cloud services and trusted access rather than traditional malware alone.
Lesson: modern investigations focus on telemetry, behaviour and hidden signals — not just antivirus alerts.
Modern Threats Identity Telemetry
Investigating a Business Email Compromise (BEC) Follow a compromised mailbox investigation across email, identity and endpoint activity to understand how attackers gain access and abuse trusted accounts.
Lesson: BEC investigations rarely stop at the email — the identity trail often tells the rest of the story.
BEC Email Identity
Investigating Living Off The Land (LOLBins) Investigate trusted Windows tools such as rundll32, certutil, mshta and PowerShell when attackers use normal binaries to hide suspicious activity.
Lesson: trusted tools can still become attacker tools when the process chain and command line look wrong.
LOLBins Endpoint KQL
Need someone to look at what your Microsoft security data is really saying?
GEMXIT can help review Microsoft 365, Defender, Sentinel, Entra ID and Azure security posture with practical, plain-English findings.

Who is Agent Foskett?

Agent Foskett is a fictional educational cyber security persona created by GEMXIT. Through the Microsoft Security Investigation Hub and Agent Foskett Academy, the character teaches Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Azure Security and Kusto Query Language (KQL) using practical real-world investigation scenarios.

Agent Foskett briefings highlight real-world scenarios including email spoofing, DMARC failures, session hijacking, impossible travel sign-ins, exposed cloud services, AI governance risks and misconfigured security controls.

The Agent Foskett hub connects practical investigations across Microsoft Defender, Sentinel, Entra ID, Exchange Online and Azure so organisations can understand the signals behind security events and improve their defensive posture.