Skip to main content

XDRInternals Module

PowerShell Gallery: XDRInternals Github: MSCloudInternals Copyright: Nathan and Fabian

Install-Module -Name XDRInternals

Description

XDRInternals is a PowerShell module that provides direct access to the Microsoft Defender XDR portal APIs. It enables automation and scripting capabilities for managing and querying XDR resources including endpoints, identities, configurations, and advanced hunting queries.

XDRInternals Cmdlets

Connect-XdrByBrowser

Authenticates to Microsoft Defender XDR using an interactive browser sign-in.

Connect-XdrByCredential

Authenticates to Microsoft Defender XDR using username, password, and optional TOTP MFA.

Connect-XdrByEstsCookie

Establishes an authenticated session to the Microsoft Defender XDR portal.

Connect-XdrByPhoneSignIn

Authenticates to Microsoft Defender XDR using Microsoft Authenticator phone sign-in.

Connect-XdrBySoftwarePasskey

Authenticates to Microsoft Defender XDR using a software passkey.

Connect-XdrBySSO

Authenticates to Microsoft Defender XDR using browser-based single sign-on.

Connect-XdrByTemporaryAccessPass

Authenticates to Microsoft Defender XDR using a Temporary Access Pass (TAP).

Connect-XdrEndpointDeviceLiveResponse

Opens a Live Response session to an endpoint device in Microsoft Defender XDR.

ConvertTo-XdrEncodedAdvancedHuntingQuery

Encodes an Advanced Hunting query for use in Microsoft Defender XDR.

Disconnect-XdrEndpointDeviceLiveResponse

Closes an active Live Response session in Microsoft Defender XDR.

Export-XdrAzureDataExplorer

Exports pipeline data to Azure Data Explorer using queued ingestion.

Export-XdrToSentinel

Exports XDR data to a Microsoft Sentinel (Log Analytics) custom table.

Get-XdrActionsCenterHistory

Retrieves historical actions from the Microsoft Defender XDR Action Center.

Get-XdrActionsCenterPending

Retrieves pending actions from the Microsoft Defender XDR Action Center.

Get-XdrAdvancedHuntingFunction

Retrieves Advanced Hunting functions from Microsoft Defender XDR.

Get-XdrAdvancedHuntingTableSchema

Retrieves the Advanced Hunting table schema from Microsoft Defender XDR.

Get-XdrAdvancedHuntingUnifiedDetectionRules

Retrieves the Unified Detection Rules from Advanced Hunting.

Get-XdrAdvancedHuntingUserHistory

Retrieves Advanced Hunting user history from Microsoft Defender XDR.

Get-XdrAlert

Retrieves alerts from Microsoft Defender XDR.

Get-XdrAzureDataExplorerCluster

Discovers accessible Azure Data Explorer clusters and databases.

Get-XdrAzureDataExplorerIngestionStatus

Gets the status of queued Azure Data Explorer ingestion operations.

Get-XdrCloudAppsActivityTimeline

Retrieves Microsoft Defender for Cloud Apps activity timeline data.

Get-XdrCloudAppsApp

Retrieves app-focused Microsoft Defender for Cloud Apps data.

Get-XdrCloudAppsConfiguration

Retrieves grouped Microsoft Defender for Cloud Apps configuration data.

Get-XdrCloudAppsDiscovery

Retrieves Cloud Discovery data from Microsoft Defender for Cloud Apps.

Get-XdrCloudAppsGeneralSetting

Retrieves general settings from Microsoft Defender for Cloud Apps (Cloud Apps).

Get-XdrCloudAppsGovernance

Retrieves governance data from Microsoft Defender for Cloud Apps and App Governance.

Get-XdrCloudAppsPolicy

Retrieves policies from Microsoft Defender for Cloud Apps.

Get-XdrConfigurationAlertServiceSetting

Retrieves alert service settings from Microsoft Defender XDR.

Get-XdrConfigurationAlertTuning

Retrieves alert tuning configuration from Microsoft Defender XDR.

Get-XdrConfigurationAssetRuleManagement

Retrieves asset rule management configuration from Microsoft Defender XDR.

Get-XdrConfigurationCriticalAssetManagementClassification

Retrieves critical asset management classification rules from Microsoft Defender XDR.

Get-XdrConfigurationCriticalAssetManagementClassificationSchema

Retrieves the schema for Critical Asset Management rules from Microsoft Defender XDR.

Get-XdrConfigurationPreviewFeatures

Retrieves the configuration for Defender XDR Preview features.

Get-XdrConfigurationServiceAccountClassification

Retrieves service account classification rules from Microsoft Defender XDR.

Get-XdrConfigurationUnifiedRBACWorkload

Retrieves Unified RBAC workload configuration from Microsoft Defender XDR.

Get-XdrDatalakeDatabase

Retrieves databases from Microsoft Defender XDR datalake.

Get-XdrDatalakeTableSchema

Retrieves database entities schema from Microsoft Defender XDR datalake.

Get-XdrEndpointAdvancedFeatures

Retrieves comprehensive advanced features configuration for Microsoft Defender for Endpoint.

Get-XdrEndpointConfigurationAdvancedFeatures

Retrieves the advanced features configuration settings for Microsoft Defender for Endpoint.

Get-XdrEndpointConfigurationAuthenticatedTelemetry

Retrieves the Authenticated Telemetry status for Microsoft Defender for Endpoint.

Get-XdrEndpointConfigurationCustomCollectionRule

Retrieves custom collection rules for Microsoft Defender for Endpoint.

Get-XdrEndpointConfigurationIntuneConnection

Retrieves the Intune connection status for Microsoft Defender for Endpoint.

Get-XdrEndpointConfigurationLiveResponse

Retrieves the Live Response configuration settings for Microsoft Defender for Endpoint.

Get-XdrEndpointConfigurationPotentiallyUnwantedApplications

Retrieves the potentially unwanted applications (PUA) configuration for Microsoft Defender for Endpoint.

Get-XdrEndpointConfigurationPreviewFeature

Retrieves the preview features configuration for Microsoft Defender for Endpoint.

Get-XdrEndpointConfigurationPurviewSharing

Retrieves the Purview alert sharing configuration for Microsoft Defender for Endpoint.

Get-XdrEndpointDevice

Retrieves endpoint devices from Microsoft Defender XDR.

Get-XdrEndpointDeviceActionResult

Gets device action results and download URIs from Microsoft Defender XDR.

Get-XdrEndpointDeviceLiveResponseLibrary

Retrieves the Live Response library files from Microsoft Defender XDR.

Get-XdrEndpointDeviceLiveResponseLibraryFile

Downloads a script file from the Live Response library.

Get-XdrEndpointDeviceModel

Retrieves all device models from Microsoft Defender for Endpoint.

Get-XdrEndpointDeviceOsVersionFriendlyName

Retrieves all OS version friendly names from Microsoft Defender for Endpoint.

Get-XdrEndpointDeviceRbacGroup

Retrieves device groups for Defender for Endpoint.

Get-XdrEndpointDeviceRbacGroupScope

Retrieves all RBAC groups from Microsoft Defender for Endpoint.

Get-XdrEndpointDeviceTag

Retrieves all device tags from Microsoft Defender for Endpoint.

Get-XdrEndpointDeviceTimeline

Retrieves the timeline of events for a specific device from Microsoft Defender XDR.

Get-XdrEndpointDeviceTotals

Retrieves the device totals from Microsoft Defender XDR.

Get-XdrEndpointDeviceVendor

Retrieves all device vendors from Microsoft Defender for Endpoint.

Get-XdrEndpointDeviceWindowsReleaseVersion

Retrieves all Windows release versions from Microsoft Defender for Endpoint.

Get-XdrEndpointLicenseReport

Retrieves license usage report for Microsoft Defender for Endpoint.

Get-XdrExposureManagementRecommendations

Retrieves recommendations from Exposure Management.

Get-XdrIdentityAlertThreshold

Retrieves alert threshold configuration for Microsoft Defender for Identity.

Get-XdrIdentityConfigurationDirectoryServiceAccount

Retrieves directory service accounts for Microsoft Defender for Identity.

Get-XdrIdentityConfigurationRemediationActionAccount

Retrieves the remediation action account configuration for Microsoft Defender for Identity.

Get-XdrIdentityDomainControllerCoverage

Retrieves domain controller coverage from Microsoft Defender for Identity.

Get-XdrIdentityIdentity

Retrieves identities from Microsoft Defender for Identity.

Get-XdrIdentityOnboardingStatus

Retrieves the onboarding status of Microsoft Defender for Identity.

Get-XdrIdentityServiceAccount

Retrieves service accounts from Microsoft Defender for Identity.

Get-XdrIdentityStatistic

Retrieves aggregated identity statistics from Microsoft Defender for Identity.

Get-XdrIdentityUser

Retrieves detailed user identity information from Microsoft Defender for Identity.

Get-XdrIdentityUserTimeline

Retrieves the timeline of events for a specific user from Microsoft Defender for Identity.

Get-XdrIncident

Retrieves incidents from Microsoft Defender XDR.

Get-XdrIncidentAssociatedAlert

Retrieves alerts associated with a specific incident from Microsoft Defender XDR.

Get-XdrMtoTenantList

Retrieves the list of accessible tenants from Microsoft Defender XDR.

Get-XdrStreamingApiConfiguration

Retrieves Streaming API configuration from Microsoft Defender XDR.

Get-XdrSuppressionRule

Retrieves alert suppression rules from Microsoft Defender XDR.

Get-XdrTenantContext

Retrieves the tenant context information from Microsoft Defender XDR.

Get-XdrTenantWorkloadStatus

Retrieves and evaluates the workload status from Microsoft Defender XDR tenant context.

Get-XdrThreatAnalyticsOutbreaks

Retrieves threat analytics outbreaks from Microsoft Defender XDR.

Get-XdrVulnerabilityManagementAdvisories

Retrieves security advisories from Vulnerability Management.

Get-XdrVulnerabilityManagementBaseline

Retrieves security baseline assessment data from Microsoft Defender XDR.

Get-XdrVulnerabilityManagementCertificates

Retrieves certificates from Vulnerability Management.

Get-XdrVulnerabilityManagementChangeEvents

Retrieves change events from Vulnerability Management.

Get-XdrVulnerabilityManagementDashboard

Retrieves Microsoft Defender Vulnerability Management dashboard analytics data.

Get-XdrVulnerabilityManagementExtensions

Retrieves browser extensions from Vulnerability Management.

Get-XdrVulnerabilityManagementProducts

Retrieves products from Vulnerability Management.

Get-XdrVulnerabilityManagementRemediationTasks

Retrieves remediation tasks from Vulnerability Management.

Get-XdrVulnerabilityManagementVulnerabilities

Retrieves vulnerabilities from Vulnerability Management.

Get-XdrXspmAttackPath

Retrieves attack path data from Microsoft Defender XDR XSPM.

Get-XdrXspmChokePoint

Retrieves choke point data from Microsoft Defender XDR XSPM.

Get-XdrXspmTopEntryPoint

Retrieves top entry points from Microsoft Defender XDR XSPM attack paths.

Get-XdrXspmTopTarget

Retrieves top targets from Microsoft Defender XDR XSPM attack paths.

Invoke-XdrAzureDataExplorerQuery

Executes a KQL query or management command against an Azure Data Explorer cluster.

Invoke-XdrEndpointDeviceAction

Invokes response actions on an endpoint device in Microsoft Defender XDR.

Invoke-XdrEndpointDeviceAutomatedInvestigation

Starts an automated investigation on an endpoint device in Microsoft Defender XDR.

Invoke-XdrEndpointDeviceLiveResponseCommand

Sends a command to an active Live Response session in Microsoft Defender XDR.

Invoke-XdrEndpointDevicePolicySync

Forces a policy sync on an endpoint device in Microsoft Defender XDR.

Invoke-XdrHuntingQueryValidation

Validates an Advanced Hunting query for custom detection rules in Microsoft Defender XDR.

Invoke-XdrMtoAdvancedHunting

Executes an Advanced Hunting query across multiple tenants in MTO (Multi-Tenant Organization).

Invoke-XdrRestMethod

Invokes a REST API call to Microsoft Defender XDR with authenticated session.

Invoke-XdrXspmHuntingQuery

Executes a hunting query against the Microsoft Defender XDR XSPM attack surface API.

Merge-XdrIncident

Merges multiple incidents into a single incident in Microsoft Defender XDR.

Move-XdrAlertToIncident

Moves alerts to a specific incident or creates a new one.

New-XdrAdvancedHuntingFunction

Creates a new Advanced Hunting function in Microsoft Defender XDR.

New-XdrConfigurationCriticalAssetManagementClassification

Creates a new Critical Asset Management classification rule in Microsoft Defender XDR.

New-XdrEndpointConfigurationCustomCollectionRule

Creates a new custom collection rule for Microsoft Defender for Endpoint from a YAML file.

New-XdrEndpointDeviceLiveResponseLibraryFile

Uploads a script file to the Live Response library.

New-XdrEndpointDeviceRbacGroup

Creates a device group in Defender for Endpoint used for RBAC and policies.

New-XdrIdentityConfigurationRemediationActionAccount

Registers a new remediation action account for Microsoft Defender for Identity.

Remove-XdrAdvancedHuntingFunction

Removes an Advanced Hunting function from Microsoft Defender XDR.

Remove-XdrConfigurationCriticalAssetManagementClassification

Removes a Critical Asset Management classification rule from Microsoft Defender XDR.

Remove-XdrEndpointDeviceLiveResponseLibraryFile

Deletes a file from the Live Response library.

Remove-XdrIdentityConfigurationRemediationActionAccount

Removes a remediation action account from Microsoft Defender for Identity.

Set-XdrAdvancedHuntingFunction

Updates an existing Advanced Hunting function in Microsoft Defender XDR.

Set-XdrAzureDataExplorerConnection

Configures Azure Data Explorer connection settings for export cmdlets.

Set-XdrCloudAppsDiscoveredApp

Updates a discovered app note in Microsoft Defender for Cloud Apps.

Set-XdrConfigurationCriticalAssetManagementClassification

Updates critical asset management classification rule metadata in Microsoft Defender XDR.

Set-XdrConfigurationPreviewFeatures

Sets the configuration for Defender XDR Preview features.

Set-XdrConnectionSettings

Creates XDR connection settings using authentication cookies.

Set-XdrEndpointAdvancedFeatures

Configures advanced features settings for Microsoft Defender for Endpoint.

Set-XdrEndpointConfigurationCustomCollectionRule

Updates an existing custom collection rule for Microsoft Defender for Endpoint.

Set-XdrEndpointDeviceAssetValue

Sets the asset value on endpoint devices in Microsoft Defender XDR.

Set-XdrEndpointDeviceCriticalityLevel

Sets the criticality level on endpoint devices in Microsoft Defender XDR.

Set-XdrEndpointDeviceExclusionState

Sets the exclusion state on endpoint devices in Microsoft Defender XDR.

Set-XdrEndpointDeviceRbacGroup

Updates Defender for Endpoint device groups.

Set-XdrEndpointDeviceTag

Sets, adds, or removes user-defined tags on endpoint devices in Microsoft Defender XDR.

Set-XdrIdentityConfigurationRemediationActionAccount

Configures the remediation action account type for Microsoft Defender for Identity.

Set-XdrSentinelConnection

Configures the Sentinel (Log Analytics) workspace connection for data export.

Stop-XdrEndpointDeviceAction

Cancels a pending device action in Microsoft Defender XDR.

Update-XdrConnectionSettings

Updates XDR connection session cookies and authentication tokens.