GEMXIT PTY LTD

GEMXIT PTY LTD GEMXIT PTY LTD - GEMXIT UK LTD
Develop IT.. Solve IT.. GEMXIT

🔎 AGENT FOSKETT — FRIDAY CYBER BRIEFING🏆 The Award I Didn’t Enter Somehow Won Me First PrizeWell, this was a nice surpri...
21/08/2026

🔎 AGENT FOSKETT — FRIDAY CYBER BRIEFING

🏆 The Award I Didn’t Enter Somehow Won Me First Prize

Well, this was a nice surprise.

An email arrived at GEMXIT congratulating us on being selected and approved for the Best Businesses in Australia 2026.

Apparently, after twenty years of building an IT and cybersecurity business, somebody had finally noticed. 😂

According to the email, we'd been recognised for our strong vision, customer satisfaction and business leadership.

There was going to be a verification certificate, a custom badge and even a listing in an exclusive national directory.

Agent Foskett was already wondering where we should put the trophy cabinet. 🏆

There was just one small problem.

I couldn't remember entering anything.

So, we investigated.

The organisation exists. The website exists. The email wasn't necessarily a phishing attempt, and that is what makes this interesting.

As we kept reading, however, some other words appeared amongst all those lovely congratulations.

Membership. Registration. Membership options.

And eventually:

“Applicable administrative fees.”

Ah.

There you are. 😂

Social engineering doesn't always use fear. Sometimes it uses flattery.

Tell someone they've been selected. Tell a business owner their company has been recognised. Give them a certificate and a shiny badge.

Then ask them to take the next step.

That's why we investigate the evidence rather than simply deciding an email “looks legitimate”.

Using Microsoft Defender XDR and KQL, we can examine EmailEvents, investigate the sender and authentication results, pivot into EmailUrlInfo, inspect the URLs and determine what the sender ultimately wants the recipient to do.

Agent Foskett's Notebook:

The word “Congratulations” is not an indicator of compromise.

But it is an excellent reason to ask:

“Congratulations for what, exactly?” 😂

For now, I've decided not to order the new GEMXIT trophy cabinet.
I'll keep the space available though.

You never know. 🏆😂

Develop IT.. Protect IT.. GEMXIT

GEMXIT PTY LTD | GEMXIT UK LTD

🕵️‍♂️ CASE UPDATE: AGENT FOSKETT IS OFFICIALLY HEADING TO PRINT. 📚Well… this just became very real.Agent Foskett Investi...
16/08/2026

🕵️‍♂️ CASE UPDATE: AGENT FOSKETT IS OFFICIALLY HEADING TO PRINT. 📚

Well… this just became very real.

Agent Foskett Investigates Microsoft Security has passed the Amazon KDP review process and is now officially scheduled for release on 1 September 2026.

The book contains 30 real-world cybersecurity investigations, following the evidence across Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra, KQL and Microsoft Security Copilot.

Suspicious sign-ins. MFA fatigue. OAuth consent. Malicious inbox rules. PowerShell. Compromised endpoints.

But this isn't simply a book about security tools.

It's about learning to think like an investigator.

Build the timeline.
Question the obvious answer.
Correlate the evidence.
Follow the logs.

Because, as Agent Foskett would say...

“The logs already knew.”

Available from 1 September 2026 in:

📕 Paperback

📘 Hardcover

📱 Kindle eBook

Develop IT.. Protect IT.. GEMXIT.

GEMXIT PTY LTD | GEMXIT UK LTD

🔎 AGENT FOSKETT HAS A NEW CASE…Except this time, it isn't another investigation.It's a book. 📖After hundreds of KQL quer...
13/08/2026

🔎 AGENT FOSKETT HAS A NEW CASE…

Except this time, it isn't another investigation.

It's a book. 📖

After hundreds of KQL queries, security investigations, Academy lessons, late-night ideas and more suspicious sign-ins than Agent Foskett would care to count, I'm very excited to finally share something I've been working on:

Agent Foskett Investigates Microsoft Security

30 Real-World Investigations Using Microsoft Defender XDR, Microsoft Sentinel, KQL and Microsoft Security Copilot

The idea behind the book is simple.

Cybersecurity isn't really about staring at alerts.

It's about investigation.

A suspicious sign-in.

An unexpected MFA request.

A new inbox rule.

An OAuth consent event.

PowerShell appearing where it shouldn't.

Individually, they can look insignificant.

Connect them together, and suddenly they tell a very different story.

Across 30 investigations, Agent Foskett follows the evidence, builds the timeline, uses KQL to interrogate the logs and asks the question every security analyst eventually learns to ask:

“What actually happened?”

And somewhere along the way, one lesson keeps appearing...

The logs already knew.

The paperback is currently scheduled for release on September 1st 2026.

I genuinely can't quite believe I'm writing that. 😁

From a Commodore 64 all those years ago to Microsoft security, KQL, Agent Foskett... and now an actual book.

What a journey.

More soon. 🔎📖

Develop IT.. Protect IT.. GEMXIT

GEMXIT PTY LTD | GEMXIT UK LTD

🔐 Another Microsoft Certification Renewed!Apparently Microsoft looked at my certification list and decided I hadn't answ...
11/08/2026

🔐 Another Microsoft Certification Renewed!

Apparently Microsoft looked at my certification list and decided I hadn't answered enough questions lately… 😂

So today it was time to renew:

🎓 Microsoft Certified: Identity and Access Administrator Associate

25 questions later…

✅ RENEWED

📅 Valid until 7 February 2028

This one was a good workout too… Microsoft Entra ID, Conditional Access, Identity Protection, Lifecycle Workflows, Global Secure Access, Private Access, Application Proxy and, naturally, a little KQL lurking around the corner.

Agent Foskett's conclusion:

Identity is still the new perimeter.

And Microsoft is making absolutely sure I remember it. 😂

Another certification safely locked away until 2028. 🔐

Now I can get back to investigating things that definitely weren't caused by Conditional Access…

Probably. 🕵️‍♂️😂

Develop IT.. Protect IT.. GEMXIT

GEMXIT PTY LTD | GEMXIT UK LTD

🕵️‍♂️ AGENT FOSKETT - CASE FILE  -100The Case of the Cybersecurity Architect Who Refused to Expire 😂CASE STATUS: SOLVED ...
08/08/2026

🕵️‍♂️ AGENT FOSKETT - CASE FILE -100

The Case of the Cybersecurity Architect Who Refused to Expire 😂

CASE STATUS: SOLVED ✅

There are certain messages you don't particularly want to receive from Microsoft.

"Your certification is eligible for renewal."

It sounds friendly enough.

What it actually means is:

"Hello Jonathan. We'd just like to check that you still know what you're talking about." 😂

Challenge accepted.

25 questions.

The interrogation began.

Microsoft Sentinel was first into the interview room.

"Where would you keep seven years of security logs, Mr Foskett?"

Sentinel Data Lake. Next suspect. 😂

Defender for Cloud arrived carrying Azure subscriptions, GitHub repositories and a suspicious collection of secrets.

Dealt with.

Then Microsoft Entra walked in with Conditional Access, break-glass accounts, phishing-resistant authentication and Zero Trust.

Nice try. 😂

Microsoft Purview wanted to discuss Copilot.

GitHub brought Dependabot.

Azure Policy produced a JSON file.

Then MITRE ATLAS turned up carrying prompt injection, model theft and a collection of AI security threats.

At this point I began to suspect Microsoft had been reading the Agent Foskett Academy. 😂🕵️‍♂️

Finally, Question 25.

API Management. Microservices. Azure SQL. Sensitive data. Third-party APIs.

A public upload endpoint.

"What should you do first?"

Agent Foskett opened the notebook.

Draw the data flow diagram.

Case closed. 🕵️‍♂️

🏆 Microsoft Certified: Cybersecurity Architect Expert… successfully renewed until February 2028.

I've held this certification since October 2022, and I'm very pleased to have renewed it again.

Behind the Agent Foskett nonsense 😂, there's a serious reason I continue doing this.

Cybersecurity doesn't stand still... and neither can we.

I'll keep learning.

I'll keep building.

I'll keep investigating.

And every now and then, Microsoft will apparently call me back into the interview room to make sure I still know what I'm doing. 😂

🕵️‍♂️ CASE FILE -100

STATUS: SOLVED ✅

CERTIFICATION: RENEWED 🏆

NEXT INVESTIGATION: Coffee. ☕

Develop IT.. Protect IT.. GEMXIT

GEMXIT PTY LTD | GEMXIT UK LTD

🕵️‍♂️ Agent Foskett’s Friday Cyber Briefing“The user said they never opened the attachment…”“…but the endpoint told a di...
07/08/2026

🕵️‍♂️ Agent Foskett’s Friday Cyber Briefing

“The user said they never opened the attachment…”

“…but the endpoint told a different story.”

👉 The email was delivered.

👉 The attachment looked harmless.

👉 No major alert fired.

☕ Everything looked normal… until the telemetry started connecting together.

🔍 What we found:

• Suspicious attachment delivered through email

• SHA256 activity on the endpoint

• File creation in user directories

• PowerShell ex*****on shortly afterwards

• Outbound network connections detected

The attachment itself wasn’t the entire story.

What happened AFTER delivery mattered far more.

🧠 So we didn’t trust the dashboard; we hunted behaviour.

Even simple Microsoft Defender XDR pivots can expose the full chain:

EmailAttachmentInfo

| where Timestamp > ago(30d)

| project

Timestamp,

FileName,

SHA256,

RecipientEmailAddress,

SenderFromAddress

👉 Sometimes the compromise is not the email.

It’s the activity that follows the attachment.

💥 What this kind of activity can indicate:

• Malicious attachment delivery

• Living-off-the-land ex*****on

• PowerShell abuse

• Secondary payload downloads

• Endpoint compromise workflows

• Delayed malware ex*****on

No noisy ransomware alert required.

🔐 The takeaway:

“The attachment looked harmless…”

“…but the telemetry already knew.”

👉 Modern attacks do not always explode immediately.

Sometimes they arrive quietly…

then unfold across the endpoint later.

🧭 Built on:

Microsoft Defender XDR | Microsoft Defender for Endpoint | Microsoft Sentinel | KQL Threat Hunting

🕵️‍♂️ Agent Foskett’s note:

The email did not look dangerous.

The behaviour did.

Develop IT.. Protect IT.. GEMXIT

GEMXIT PTY LTD | GEMXIT UK LTD

🕵️‍♂️ Agent Foskett's Case File  -104Case Status: Solved. ✅After another interrogation by Microsoft... I can confirm I s...
31/07/2026

🕵️‍♂️ Agent Foskett's Case File -104

Case Status: Solved. ✅

After another interrogation by Microsoft... I can confirm I survived the Azure Administrator Associate renewal assessment and have successfully renewed my certification until January 2028. 🎉

Agent Foskett's report:

🔍 The suspect attempted to hide in deployment slots.

🔍 Azure Storage tried to hide behind Service Endpoints and Private Endpoints.

🔍 Recovery Services Vaults insisted snapshots and recovery points were the same thing.

🔍 And someone thought it would be funny to ask about update domains... again.

Fortunately, after a couple of hours of investigation, a bucket load of coffee, and resisting the urge to ask Copilot for hints, the evidence finally stacked up in my favour.

One thing I genuinely like about Microsoft's certification program is that it's not about passing an exam once and forgetting everything. The renewal process encourages us to keep learning because Azure changes constantly, and that's exactly how it should be.

Every certification renewal is a reminder that technology never stands still. The day we stop learning is the day we start falling behind.

Microsoft continues to evolve at an incredible pace, and that's exactly why I value the renewal program. It's not about collecting another badge, it's about making sure the knowledge behind it stays current.

Now... Agent Foskett is closing this case and opening the next one.

🎯 Next investigations: SC-500 and AZ-700.

Until then...

Develop IT. Protect IT. GEMXIT.

GEMXIT PTY LTD | GEMXIT UK LTD

🕵️‍♂️ Agent Foskett’s Friday Cyber Briefing"The weakest device wasn't the server...""...it was the $40 gadget nobody tho...
30/07/2026

🕵️‍♂️ Agent Foskett’s Friday Cyber Briefing

"The weakest device wasn't the server..."
"...it was the $40 gadget nobody thought about."

👉 The firewall was patched.
👉 Multi-Factor Authentication was enabled.
👉 Microsoft Defender was reporting healthy.
👉 The SOC dashboard looked green.

☕ Then Agent Foskett noticed something nobody else had looked at...
A small Bluetooth-enabled IoT device.
Not a server.
Not a laptop.
Not even a phone.

Just a cheap piece of hardware that had quietly become part of the network.

🔍 What we found:
• A connected device with outdated firmware
• Weak or poorly implemented wireless security
• Default configuration still enabled
• No one knew who was responsible for managing it
• It had quietly become another attack surface

Everything important was protected.
The forgotten gadget wasn't.

🧠 So we stopped looking at the data centre.

Modern cyber attacks don't always begin with Active Directory.
Or Microsoft 365.
Or Azure.

Sometimes they begin with a device that costs less than lunch.

Attackers don't care what the device does.

They care whether it gives them a way in.

💥 What this kind of device could be:

• Bluetooth accessories
• IP security cameras
• Smart TVs
• Network printers
• Environmental sensors
• Building automation systems
• IoT gateways
• Barcode scanners
• Smart lighting
• GPS trackers

Every connected device deserves an owner.
Every connected device deserves updates.
Every connected device deserves to be part of your security strategy.

🔐 The takeaway:

"Your biggest cyber risk..."
"...might not even have a keyboard."

Because cyber security isn't just about protecting computers anymore.

It's about protecting everything that connects.

🧭 Built on:
Microsoft Defender XDR | Microsoft Sentinel | Microsoft Defender for IoT | Microsoft Entra ID | KQL

🕵️‍♂️ Agent Foskett's note:

The attacker didn't beat the firewall.
They didn't crack the password.
They simply found the one device everyone had forgotten existed.

Sometimes the weakest link isn't hidden.
It's sitting on a shelf with a flashing blue light.

Develop IT.. Protect IT.. GEMXIT

GEMXIT PTY LTD | GEMXIT UK LTD

🕵️‍♂️ Agent Foskett’s Friday Cyber Briefing“The sign-in was successful…”“…so everyone moved on.”👉 That’s when investigat...
24/07/2026

🕵️‍♂️ Agent Foskett’s Friday Cyber Briefing
“The sign-in was successful…”
“…so everyone moved on.”
👉 That’s when investigations go wrong.
The password was correct.
MFA was approved.
Conditional Access allowed the session.

Everything looked normal…
…until we looked at what happened next.

🔍 What’s really happening
Attackers don’t always break in.
👉 Sometimes they simply log in.
The credentials are valid.
The authentication succeeds.
The user appears legitimate.
👉 The investigation doesn’t begin with the sign-in.
It begins with the activity that follows.

🧠 Agent Foskett’s mindset
Don’t ask:
❌ “Did the login succeed?”
Ask:
👉 What happened after authentication?
👉 What resources were accessed?
👉 Was this behaviour normal for this user?
👉 Should this session have continued?

💻 How we prove it
We don’t guess… we investigate.
Using Microsoft Entra and Microsoft Defender:
• Sign-in Logs
• Authentication Details
• Conditional Access evaluation
• Risky Sign-ins
• Audit Logs
• Authentication Methods
👉 We build the complete identity timeline.

💥 What that reveals
• Successful logins from unusual locations
• MFA approved… by an attacker
• New authentication methods added
• Privileged role assignments
• Mass SharePoint and OneDrive access
• Enterprise application consent
👉 No malware.
👉 No failed logons.
Just behaviour that doesn’t belong.

⚠️ The reality
Many investigations focus on failed authentication.
Modern attackers prefer successful authentication.
That’s why Zero Trust isn’t about proving who logged in…
👉 It’s about continuously verifying what they’re doing afterwards.

🚀 Takeaway
A successful sign-in is not proof that everything is okay.
It’s simply the beginning of the investigation.
👉 If you stop looking once authentication succeeds…
…you’re probably stopping too early.

Develop IT. Protect IT. GEMXIT
GEMXIT PTY LTD | GEMXIT UK LTD

🕵️‍♂️ Agent Foskett's Friday Cyber Briefing"The Conditional Access policy existed...""...but it wasn't actually protecti...
17/07/2026

🕵️‍♂️ Agent Foskett's Friday Cyber Briefing

"The Conditional Access policy existed..."
"...but it wasn't actually protecting anything."

👉 MFA policy configured
👉 Risk policy configured
👉 Device compliance checks configured
👉 Named locations configured

☕ Everything looked secure.

Until we opened the policy.
It was still running in Report-Only mode.

The dashboard looked healthy.
The tenant wasn't.

🔍 What the investigation showed:

• Conditional Access policies evaluating every sign-in
• User and sign-in risk detected correctly
• Device compliance being assessed
• Policies calculating the correct outcome
• No enforcement ever taking place

The policies were working...
They just weren't protecting anyone.

Report-Only mode evaluates every sign-in and tells you what would have happened...
without actually blocking the session.

🧠 This is one of the most common Microsoft 365 security gaps I encounter in real environments.

From the surface everything appears healthy:

✅ MFA configured
✅ Conditional Access configured
✅ Risk policies configured
✅ Reports look normal

But none of those controls are actually stopping users from signing in.
It often starts during:

• pilot deployments
• migration projects
• testing new policies
• temporary troubleshooting exclusions

Then months pass...
Everyone assumes the protection is active.
It isn't.

🛡️ Security lesson
Monitoring is valuable.
Visibility is essential.

But Report-Only mode is not protection.
A security control that only reports what would have happened...

will never stop an attacker.
Zero Trust only works when policies are enforced.

🕵️‍♂️ Agent Foskett
"The logs already knew."

Develop IT.. Protect IT.. GEMXIT

GEMXIT PTY LTD | GEMXIT UK LTD

Address

Suite 8, Level 1, 33 Flemington Road, North Melbourne
Evanston, SA
3051

Opening Hours

Monday 5am - 10pm
Tuesday 5am - 10pm
Wednesday 5am - 10pm
Thursday 5am - 10pm
Friday 5am - 10pm
Saturday 4am - 10pm
Sunday 4am - 10pm

Telephone

+611300951505

Alerts

Be the first to know and let us send you an email when GEMXIT PTY LTD posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share