← All XDRInternals commands

POWERSHELL COMMAND

Connect-XdrEndpointDeviceLiveResponse

Opens a Live Response session to an endpoint device in Microsoft Defender XDR.

View source ↗

Creates a Live Response session to the specified device. By default, the cmdlet provides an interactive command-line interface where you can type Live Response commands and see results.

When -NonInteractive is specified, the cmdlet establishes the session, loads command definitions, and returns a session object without entering the prompt loop.

Type ‘disconnect’ or ’exit’ to close the session and return to PowerShell. Type ‘help’ to see available Live Response commands.

Available Live Response commands include: analyze, cd, cls, connect, connections, dir, drivers, fg, fileinfo, findfile, getfile, help, jobs, library, log, persistence, prefetch, processes, putfile, registry, remediate, run, scheduledtasks, services, startupfolders, status, trace, undo

Command aliases (e.g. ls, process, download) are supported and resolved automatically. Use ‘help ’ for detailed syntax and flags for a specific command.

Syntax

Connect-XdrEndpointDeviceLiveResponse [-DeviceId] <string> [[-DeviceName] <string>] [[-LastSeen] <Object>] [[-OsPlatform] <string>] [-NonInteractive] [-NoStatusTable] [<CommonParameters>]

Parameters

-DeviceId

Property Value
Type String
Required Yes
Position 1
Pipeline input true (ByPropertyName)
Default Not documented

The device ID (SenseMachineId) of the target device.

-DeviceName

Property Value
Type String
Required No
Position 2
Pipeline input true (ByPropertyName)
Default Not documented

Optional device name used for progress display and to avoid an extra lookup when device metadata is already available from pipeline input.

-LastSeen

Property Value
Type Object
Required No
Position 3
Pipeline input true (ByPropertyName)
Default Not documented

Optional last seen timestamp from pipeline input. When provided together with other device metadata, the cmdlet can reuse it during non-interactive session creation.

-OsPlatform

Property Value
Type String
Required No
Position 4
Pipeline input true (ByPropertyName)
Default Not documented

Optional operating system platform from pipeline input. Used to determine the initial working directory without requiring an additional device metadata lookup.

-NonInteractive

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Connects to Live Response and returns a session object without starting the interactive prompt loop.

-NoStatusTable

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Suppresses the live status table shown during multi-device non-interactive session creation. Returned session objects are unchanged.

Examples

Connect-XdrEndpointDeviceLiveResponse -DeviceId "980dddb7036eae7e38d30dee7f11b51e573a6fc2"
Opens an interactive Live Response session to the specified device.
$lr = Connect-XdrEndpointDeviceLiveResponse -DeviceId "980dddb7036eae7e38d30dee7f11b51e573a6fc2" -NonInteractive
Connects to the device and returns a session object for script-driven command execution.
$devices | Connect-XdrEndpointDeviceLiveResponse -NonInteractive -NoStatusTable
Connects to multiple devices without rendering the live status table.
Invoke-XdrEndpointDeviceAction -DeviceId "980dddb7036eae7e38d30dee7f11b51e573a6fc2" -LiveResponse
Opens a Live Response session via the unified action cmdlet.

Output

Type: PSCustomObject

When -NonInteractive is used, returns an XdrEndpointDeviceLiveResponseSession object. In interactive mode, no output is returned.

View source