XDRInternals Module
PowerShell Gallery: XDRInternals Github: MSCloudInternals Copyright: Nathan and Fabian
Install-Module -Name XDRInternals
Description
XDRInternals is a PowerShell module that provides direct access to the Microsoft Defender XDR portal APIs. It enables automation and scripting capabilities for managing and querying XDR resources including endpoints, identities, configurations, and advanced hunting queries.
XDRInternals Cmdlets
Connect-XdrByBrowser
Authenticates to Microsoft Defender XDR using an interactive browser sign-in.
Connect-XdrByCredential
Authenticates to Microsoft Defender XDR using username, password, and optional TOTP MFA.
Connect-XdrByEstsCookie
Establishes an authenticated session to the Microsoft Defender XDR portal.
Connect-XdrByPhoneSignIn
Authenticates to Microsoft Defender XDR using Microsoft Authenticator phone sign-in.
Connect-XdrBySoftwarePasskey
Authenticates to Microsoft Defender XDR using a software passkey.
Connect-XdrBySSO
Authenticates to Microsoft Defender XDR using browser-based single sign-on.
Connect-XdrByTemporaryAccessPass
Authenticates to Microsoft Defender XDR using a Temporary Access Pass (TAP).
Connect-XdrEndpointDeviceLiveResponse
Opens a Live Response session to an endpoint device in Microsoft Defender XDR.
ConvertTo-XdrEncodedAdvancedHuntingQuery
Encodes an Advanced Hunting query for use in Microsoft Defender XDR.
Disconnect-XdrEndpointDeviceLiveResponse
Closes an active Live Response session in Microsoft Defender XDR.
Export-XdrAzureDataExplorer
Exports pipeline data to Azure Data Explorer using queued ingestion.
Export-XdrToSentinel
Exports XDR data to a Microsoft Sentinel (Log Analytics) custom table.
Get-XdrActionsCenterHistory
Retrieves historical actions from the Microsoft Defender XDR Action Center.
Get-XdrActionsCenterPending
Retrieves pending actions from the Microsoft Defender XDR Action Center.
Get-XdrAdvancedHuntingFunction
Retrieves Advanced Hunting functions from Microsoft Defender XDR.
Get-XdrAdvancedHuntingTableSchema
Retrieves the Advanced Hunting table schema from Microsoft Defender XDR.
Get-XdrAdvancedHuntingUnifiedDetectionRules
Retrieves the Unified Detection Rules from Advanced Hunting.
Get-XdrAdvancedHuntingUserHistory
Retrieves Advanced Hunting user history from Microsoft Defender XDR.
Get-XdrAlert
Retrieves alerts from Microsoft Defender XDR.
Get-XdrAzureDataExplorerCluster
Discovers accessible Azure Data Explorer clusters and databases.
Get-XdrAzureDataExplorerIngestionStatus
Gets the status of queued Azure Data Explorer ingestion operations.
Get-XdrCloudAppsActivityTimeline
Retrieves Microsoft Defender for Cloud Apps activity timeline data.
Get-XdrCloudAppsApp
Retrieves app-focused Microsoft Defender for Cloud Apps data.
Get-XdrCloudAppsConfiguration
Retrieves grouped Microsoft Defender for Cloud Apps configuration data.
Get-XdrCloudAppsDiscovery
Retrieves Cloud Discovery data from Microsoft Defender for Cloud Apps.
Get-XdrCloudAppsGeneralSetting
Retrieves general settings from Microsoft Defender for Cloud Apps (Cloud Apps).
Get-XdrCloudAppsGovernance
Retrieves governance data from Microsoft Defender for Cloud Apps and App Governance.
Get-XdrCloudAppsPolicy
Retrieves policies from Microsoft Defender for Cloud Apps.
Get-XdrConfigurationAlertServiceSetting
Retrieves alert service settings from Microsoft Defender XDR.
Get-XdrConfigurationAlertTuning
Retrieves alert tuning configuration from Microsoft Defender XDR.
Get-XdrConfigurationAssetRuleManagement
Retrieves asset rule management configuration from Microsoft Defender XDR.
Get-XdrConfigurationCriticalAssetManagementClassification
Retrieves critical asset management classification rules from Microsoft Defender XDR.
Get-XdrConfigurationCriticalAssetManagementClassificationSchema
Retrieves the schema for Critical Asset Management rules from Microsoft Defender XDR.
Get-XdrConfigurationPreviewFeatures
Retrieves the configuration for Defender XDR Preview features.
Get-XdrConfigurationServiceAccountClassification
Retrieves service account classification rules from Microsoft Defender XDR.
Get-XdrConfigurationUnifiedRBACWorkload
Retrieves Unified RBAC workload configuration from Microsoft Defender XDR.
Get-XdrDatalakeDatabase
Retrieves databases from Microsoft Defender XDR datalake.
Get-XdrDatalakeTableSchema
Retrieves database entities schema from Microsoft Defender XDR datalake.
Get-XdrEndpointAdvancedFeatures
Retrieves comprehensive advanced features configuration for Microsoft Defender for Endpoint.
Get-XdrEndpointConfigurationAdvancedFeatures
Retrieves the advanced features configuration settings for Microsoft Defender for Endpoint.
Get-XdrEndpointConfigurationAuthenticatedTelemetry
Retrieves the Authenticated Telemetry status for Microsoft Defender for Endpoint.
Get-XdrEndpointConfigurationCustomCollectionRule
Retrieves custom collection rules for Microsoft Defender for Endpoint.
Get-XdrEndpointConfigurationIntuneConnection
Retrieves the Intune connection status for Microsoft Defender for Endpoint.
Get-XdrEndpointConfigurationLiveResponse
Retrieves the Live Response configuration settings for Microsoft Defender for Endpoint.
Get-XdrEndpointConfigurationPotentiallyUnwantedApplications
Retrieves the potentially unwanted applications (PUA) configuration for Microsoft Defender for Endpoint.
Get-XdrEndpointConfigurationPreviewFeature
Retrieves the preview features configuration for Microsoft Defender for Endpoint.
Get-XdrEndpointConfigurationPurviewSharing
Retrieves the Purview alert sharing configuration for Microsoft Defender for Endpoint.
Get-XdrEndpointDevice
Retrieves endpoint devices from Microsoft Defender XDR.
Get-XdrEndpointDeviceActionResult
Gets device action results and download URIs from Microsoft Defender XDR.
Get-XdrEndpointDeviceLiveResponseLibrary
Retrieves the Live Response library files from Microsoft Defender XDR.
Get-XdrEndpointDeviceLiveResponseLibraryFile
Downloads a script file from the Live Response library.
Get-XdrEndpointDeviceModel
Retrieves all device models from Microsoft Defender for Endpoint.
Get-XdrEndpointDeviceOsVersionFriendlyName
Retrieves all OS version friendly names from Microsoft Defender for Endpoint.
Get-XdrEndpointDeviceRbacGroup
Retrieves device groups for Defender for Endpoint.
Get-XdrEndpointDeviceRbacGroupScope
Retrieves all RBAC groups from Microsoft Defender for Endpoint.
Get-XdrEndpointDeviceTag
Retrieves all device tags from Microsoft Defender for Endpoint.
Get-XdrEndpointDeviceTimeline
Retrieves the timeline of events for a specific device from Microsoft Defender XDR.
Get-XdrEndpointDeviceTotals
Retrieves the device totals from Microsoft Defender XDR.
Get-XdrEndpointDeviceVendor
Retrieves all device vendors from Microsoft Defender for Endpoint.
Get-XdrEndpointDeviceWindowsReleaseVersion
Retrieves all Windows release versions from Microsoft Defender for Endpoint.
Get-XdrEndpointLicenseReport
Retrieves license usage report for Microsoft Defender for Endpoint.
Get-XdrExposureManagementRecommendations
Retrieves recommendations from Exposure Management.
Get-XdrIdentityAlertThreshold
Retrieves alert threshold configuration for Microsoft Defender for Identity.
Get-XdrIdentityConfigurationDirectoryServiceAccount
Retrieves directory service accounts for Microsoft Defender for Identity.
Get-XdrIdentityConfigurationRemediationActionAccount
Retrieves the remediation action account configuration for Microsoft Defender for Identity.
Get-XdrIdentityDomainControllerCoverage
Retrieves domain controller coverage from Microsoft Defender for Identity.
Get-XdrIdentityIdentity
Retrieves identities from Microsoft Defender for Identity.
Get-XdrIdentityOnboardingStatus
Retrieves the onboarding status of Microsoft Defender for Identity.
Get-XdrIdentityServiceAccount
Retrieves service accounts from Microsoft Defender for Identity.
Get-XdrIdentityStatistic
Retrieves aggregated identity statistics from Microsoft Defender for Identity.
Get-XdrIdentityUser
Retrieves detailed user identity information from Microsoft Defender for Identity.
Get-XdrIdentityUserTimeline
Retrieves the timeline of events for a specific user from Microsoft Defender for Identity.
Get-XdrIncident
Retrieves incidents from Microsoft Defender XDR.
Get-XdrIncidentAssociatedAlert
Retrieves alerts associated with a specific incident from Microsoft Defender XDR.
Get-XdrMtoTenantList
Retrieves the list of accessible tenants from Microsoft Defender XDR.
Get-XdrStreamingApiConfiguration
Retrieves Streaming API configuration from Microsoft Defender XDR.
Get-XdrSuppressionRule
Retrieves alert suppression rules from Microsoft Defender XDR.
Get-XdrTenantContext
Retrieves the tenant context information from Microsoft Defender XDR.
Get-XdrTenantWorkloadStatus
Retrieves and evaluates the workload status from Microsoft Defender XDR tenant context.
Get-XdrThreatAnalyticsOutbreaks
Retrieves threat analytics outbreaks from Microsoft Defender XDR.
Get-XdrVulnerabilityManagementAdvisories
Retrieves security advisories from Vulnerability Management.
Get-XdrVulnerabilityManagementBaseline
Retrieves security baseline assessment data from Microsoft Defender XDR.
Get-XdrVulnerabilityManagementCertificates
Retrieves certificates from Vulnerability Management.
Get-XdrVulnerabilityManagementChangeEvents
Retrieves change events from Vulnerability Management.
Get-XdrVulnerabilityManagementDashboard
Retrieves Microsoft Defender Vulnerability Management dashboard analytics data.
Get-XdrVulnerabilityManagementExtensions
Retrieves browser extensions from Vulnerability Management.
Get-XdrVulnerabilityManagementProducts
Retrieves products from Vulnerability Management.
Get-XdrVulnerabilityManagementRemediationTasks
Retrieves remediation tasks from Vulnerability Management.
Get-XdrVulnerabilityManagementVulnerabilities
Retrieves vulnerabilities from Vulnerability Management.
Get-XdrXspmAttackPath
Retrieves attack path data from Microsoft Defender XDR XSPM.
Get-XdrXspmChokePoint
Retrieves choke point data from Microsoft Defender XDR XSPM.
Get-XdrXspmTopEntryPoint
Retrieves top entry points from Microsoft Defender XDR XSPM attack paths.
Get-XdrXspmTopTarget
Retrieves top targets from Microsoft Defender XDR XSPM attack paths.
Invoke-XdrAzureDataExplorerQuery
Executes a KQL query or management command against an Azure Data Explorer cluster.
Invoke-XdrEndpointDeviceAction
Invokes response actions on an endpoint device in Microsoft Defender XDR.
Invoke-XdrEndpointDeviceAutomatedInvestigation
Starts an automated investigation on an endpoint device in Microsoft Defender XDR.
Invoke-XdrEndpointDeviceLiveResponseCommand
Sends a command to an active Live Response session in Microsoft Defender XDR.
Invoke-XdrEndpointDevicePolicySync
Forces a policy sync on an endpoint device in Microsoft Defender XDR.
Invoke-XdrHuntingQueryValidation
Validates an Advanced Hunting query for custom detection rules in Microsoft Defender XDR.
Invoke-XdrMtoAdvancedHunting
Executes an Advanced Hunting query across multiple tenants in MTO (Multi-Tenant Organization).
Invoke-XdrRestMethod
Invokes a REST API call to Microsoft Defender XDR with authenticated session.
Invoke-XdrXspmHuntingQuery
Executes a hunting query against the Microsoft Defender XDR XSPM attack surface API.
Merge-XdrIncident
Merges multiple incidents into a single incident in Microsoft Defender XDR.
Move-XdrAlertToIncident
Moves alerts to a specific incident or creates a new one.
New-XdrAdvancedHuntingFunction
Creates a new Advanced Hunting function in Microsoft Defender XDR.
New-XdrConfigurationCriticalAssetManagementClassification
Creates a new Critical Asset Management classification rule in Microsoft Defender XDR.
New-XdrEndpointConfigurationCustomCollectionRule
Creates a new custom collection rule for Microsoft Defender for Endpoint from a YAML file.
New-XdrEndpointDeviceLiveResponseLibraryFile
Uploads a script file to the Live Response library.
New-XdrEndpointDeviceRbacGroup
Creates a device group in Defender for Endpoint used for RBAC and policies.
New-XdrIdentityConfigurationRemediationActionAccount
Registers a new remediation action account for Microsoft Defender for Identity.
Remove-XdrAdvancedHuntingFunction
Removes an Advanced Hunting function from Microsoft Defender XDR.
Remove-XdrConfigurationCriticalAssetManagementClassification
Removes a Critical Asset Management classification rule from Microsoft Defender XDR.
Remove-XdrEndpointDeviceLiveResponseLibraryFile
Deletes a file from the Live Response library.
Remove-XdrIdentityConfigurationRemediationActionAccount
Removes a remediation action account from Microsoft Defender for Identity.
Set-XdrAdvancedHuntingFunction
Updates an existing Advanced Hunting function in Microsoft Defender XDR.
Set-XdrAzureDataExplorerConnection
Configures Azure Data Explorer connection settings for export cmdlets.
Set-XdrCloudAppsDiscoveredApp
Updates a discovered app note in Microsoft Defender for Cloud Apps.
Set-XdrConfigurationCriticalAssetManagementClassification
Updates critical asset management classification rule metadata in Microsoft Defender XDR.
Set-XdrConfigurationPreviewFeatures
Sets the configuration for Defender XDR Preview features.
Set-XdrConnectionSettings
Creates XDR connection settings using authentication cookies.
Set-XdrEndpointAdvancedFeatures
Configures advanced features settings for Microsoft Defender for Endpoint.
Set-XdrEndpointConfigurationCustomCollectionRule
Updates an existing custom collection rule for Microsoft Defender for Endpoint.
Set-XdrEndpointDeviceAssetValue
Sets the asset value on endpoint devices in Microsoft Defender XDR.
Set-XdrEndpointDeviceCriticalityLevel
Sets the criticality level on endpoint devices in Microsoft Defender XDR.
Set-XdrEndpointDeviceExclusionState
Sets the exclusion state on endpoint devices in Microsoft Defender XDR.
Set-XdrEndpointDeviceRbacGroup
Updates Defender for Endpoint device groups.
Set-XdrEndpointDeviceTag
Sets, adds, or removes user-defined tags on endpoint devices in Microsoft Defender XDR.
Set-XdrIdentityConfigurationRemediationActionAccount
Configures the remediation action account type for Microsoft Defender for Identity.
Set-XdrSentinelConnection
Configures the Sentinel (Log Analytics) workspace connection for data export.
Stop-XdrEndpointDeviceAction
Cancels a pending device action in Microsoft Defender XDR.
Update-XdrConnectionSettings
Updates XDR connection session cookies and authentication tokens.