Agent Foskett is a fictional educational cyber security persona created by GEMXIT. Agent Foskett helps organisations understand Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID and Kusto Query Language (KQL) through practical, real-world investigation scenarios. Through the Microsoft Security Investigation Hub, the growing Agent Foskett Academy and the first Agent Foskett book, the persona translates complex security telemetry into clear, actionable lessons covering identity protection, email security, cloud investigation, proactive threat hunting, detection engineering and emerging cyber risks.
Agent Foskett is a fictional educational cyber security persona created by GEMXIT. The character is used to teach Microsoft Defender XDR investigations, Microsoft Sentinel, Microsoft Entra ID and Kusto Query Language (KQL) through practical, real-world investigation scenarios, the growing Agent Foskett Academy, the SOC Analyst Academy and the Agent Foskett book. The KQL Academy develops practical skills in advanced threat hunting, detection engineering and proactive investigation workflows.
Real Microsoft security investigations
Practical KQL threat hunting and detection engineering
Defender, Sentinel, Entra ID and Azure
Agent Foskett is now also an author
The same evidence-first investigation style used across the Hub and Academy is now available in the first published Agent Foskett book.
Published • Available Now
Agent Foskett Investigates Microsoft Security
The first Agent Foskett book brings together 30 real-world investigations using Microsoft Defender XDR, Microsoft Sentinel, KQL and Microsoft Security Copilot.
The book follows the same approach as the Academy: build the timeline, correlate the telemetry, challenge the working theory and keep asking the question that matters — what does the evidence actually prove?
New to Agent Foskett? Start with some of the most popular Microsoft security investigations and KQL threat hunting guides.
KQL Threat Hunting Guide
EmailEvents Investigations
DMARC & Spoofing
MFA Session Hijacking
Microsoft Defender XDR
Detection Engineering
Agent Foskett Book
Agent Foskett is where security data becomes a story
As a fictional educational cyber security persona, Agent Foskett helps defenders understand the story hidden inside Microsoft security telemetry.
Most organisations already have powerful security platforms in place. Microsoft Defender is collecting email, endpoint and cloud signals. Microsoft Sentinel may be receiving logs. Entra ID is recording sign-ins, MFA prompts, Conditional Access decisions and identity risk. Azure is producing activity, configuration and exposure data.
But the real question is not whether the tools exist.
The real question is: does anyone understand what the data is saying?
That is why Agent Foskett exists. The briefings take technical signals — such as DMARC failures, suspicious sign-ins, unexpected URL clicks, after-hours downloads, exposed cloud services or unusual PowerShell activity — and turn them into clear investigation lessons.
Lesson: security is not just configuration — it is interpretation.
What Agent Foskett focuses on
The briefings sit at the intersection of Microsoft security, real-world investigation and practical business risk.
Microsoft Defender investigationsEmailEvents, URLClickEvents, DeviceProcessEvents, authentication outcomes, spoofing signals and suspicious endpoint behaviour.
KQL threat hunting & detection engineeringPractical queries that help security teams ask better questions of their data across Defender, Sentinel and Microsoft 365, then turn successful hunts into baselines, detections and repeatable defensive capability.
Email spoofing and DMARCSender mismatch, AuthenticationDetails, SPF, DKIM, DMARC, CompAuth and delivered messages that should not be trusted.
Identity and MFA riskEntra ID sign-ins, session hijacking, token reuse, Conditional Access exclusions, legacy authentication and account behaviour.
Azure and cloud exposurePublic storage, exposed RDP, failed backups, weak resilience, misconfigured services and cloud assumptions that create risk.
AI governance and new risksAI agents, broad access, prompt risk, data exposure and why AI tools need identity, governance and monitoring.
Why Agent Foskett matters
Security does not usually fail because one person forgot to buy a tool. It fails because normal business decisions create small gaps over time: one temporary exclusion, one public setting, one transport rule left disabled, one admin account without enough protection, one alert nobody understood.
Agent Foskett briefings are designed to make those quiet risks visible. The aim is not fear. The aim is clarity. When organisations can see the story behind their logs, they can make better decisions, respond faster and build stronger security habits.
Lesson: the logs often know before the business does — but only if someone asks the right questions.
Visibility before incidents
Practical investigation thinking
Microsoft security context
Better questions from better data
The Agent Foskett Method
Every investigation starts with a clue, not a conclusion. The method is designed to slow the analyst down just enough to ask better questions, connect the evidence and reach a conclusion that can be defended.
1
Something does not look rightStart with the alert, anomaly, user report or small clue that deserves a closer look.
2
Follow the evidenceDo not decide what happened first. Examine the telemetry and let the evidence shape the investigation.
3
Build the timelinePut sign-ins, processes, emails, cloud activity and security events into chronological order.
4
PivotMove from account to IP, device, process, file, application, mailbox or session as the evidence develops.
5
Correlate the signalsOne event rarely tells the whole story. Bring identity, endpoint, email and cloud telemetry together.
6
Challenge the theoryLook for evidence that could disprove the working theory. A good investigation survives being questioned.
7
Reach a defensible conclusionMove beyond “this looks suspicious” and explain what happened, what did not happen and what the evidence supports.
What does “The Logs Already Knew” mean?
The alert is only the beginning. The evidence tells the story.
“The Logs Already Knew” captures the central idea behind Agent Foskett. Long before an investigation reaches its conclusion, the environment may already contain the sign-in, process, email, session, configuration or cloud event that explains what happened. The investigator's job is to find those signals, put them in context and connect them without forcing the evidence to fit an assumption.
That is why the recurring Agent Foskett question is simple: what do the logs actually prove?
Learn with Agent Foskett
Agent Foskett has grown into a connected learning environment for people developing practical Microsoft security investigation skills.
Agent Foskett was created by Jonathan Foskett through GEMXIT as a way to teach cyber security investigation through stories rather than isolated product features.
The approach combines practical IT and Microsoft security experience with the structure of technical training: begin with a realistic clue, investigate the available evidence, explain the reasoning and finish with a lesson that can be applied to the next case.
Agent Foskett is fictional. The investigation mindset behind the character is deliberately practical: follow the evidence, build the timeline, question assumptions and never stop at the first explanation.
The investigation continues
Agent Foskett is not a finished collection of lessons. New investigations continue to follow the way Microsoft security, identity, cloud platforms, attacker techniques and AI-assisted security operations evolve.
The Investigation Hub, Academy, SOC Analyst learning path and published books are different parts of the same idea: help people become better investigators by learning how to recognise weak signals, connect evidence and explain what happened.
The next clue is already somewhere in the logs.
How Agent Foskett connects to GEMXIT
Agent Foskett is part of GEMXIT’s broader mission: Develop IT. Protect IT. GEMXIT.
GEMXIT works across cloud services, cyber security, Microsoft training and software development. Agent Foskett brings those areas together through the Investigation Hub, the Agent Foskett Academy, detection engineering content and the first published book, showing how systems, users, identity, cloud services and security telemetry interact in the real world.
For organisations using Microsoft 365, Azure, Defender, Sentinel or Entra ID, the briefings provide a practical way to understand security gaps before they become operational or business problems.
Explore the Agent Foskett Investigation Hub, Academy and Book Explore practical Microsoft Defender, Sentinel, Entra ID, Azure and KQL investigations, continue through the Agent Foskett Academy, or discover the first Agent Foskett book.
Continue the investigation with practical Microsoft security scenarios
focused on identity risk, email telemetry,
suspicious behaviour and the signals hidden behind normal-looking activity.
Need someone to look at what your Microsoft security data is really saying? GEMXIT can help review Microsoft 365, Defender, Sentinel, Entra ID and Azure security posture with practical, plain-English findings.
Agent Foskett is a fictional educational cyber security persona created by GEMXIT. Through the Microsoft Security Investigation Hub, the growing Agent Foskett Academy and the Agent Foskett book, the character teaches Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Azure Security, Kusto Query Language (KQL), proactive threat hunting and detection engineering using practical real-world investigation scenarios.
Agent Foskett briefings highlight real-world scenarios including email spoofing, DMARC failures, session hijacking,
impossible travel sign-ins, exposed cloud services, AI governance risks and misconfigured security controls.
The Agent Foskett hub connects practical investigations across Microsoft Defender, Sentinel, Entra ID,
Exchange Online and Azure so organisations can understand the signals behind security events and improve
their defensive posture.