POWERSHELL COMMAND
Connect-XdrEndpointDeviceLiveResponse
Opens a Live Response session to an endpoint device in Microsoft Defender XDR.
Creates a Live Response session to the specified device. By default, the cmdlet provides an interactive command-line interface where you can type Live Response commands and see results.
When -NonInteractive is specified, the cmdlet establishes the session, loads command definitions, and returns a session object without entering the prompt loop.
Type ‘disconnect’ or ’exit’ to close the session and return to PowerShell. Type ‘help’ to see available Live Response commands.
Available Live Response commands include: analyze, cd, cls, connect, connections, dir, drivers, fg, fileinfo, findfile, getfile, help, jobs, library, log, persistence, prefetch, processes, putfile, registry, remediate, run, scheduledtasks, services, startupfolders, status, trace, undo
Command aliases (e.g. ls, process, download) are supported and resolved automatically.
Use ‘help
Syntax
Connect-XdrEndpointDeviceLiveResponse [-DeviceId] <string> [[-DeviceName] <string>] [[-LastSeen] <Object>] [[-OsPlatform] <string>] [-NonInteractive] [-NoStatusTable] [<CommonParameters>]
Parameters
-DeviceId
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | 1 |
| Pipeline input | true (ByPropertyName) |
| Default | Not documented |
The device ID (SenseMachineId) of the target device.
-DeviceName
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 2 |
| Pipeline input | true (ByPropertyName) |
| Default | Not documented |
Optional device name used for progress display and to avoid an extra lookup when device metadata is already available from pipeline input.
-LastSeen
| Property | Value |
|---|---|
| Type | Object |
| Required | No |
| Position | 3 |
| Pipeline input | true (ByPropertyName) |
| Default | Not documented |
Optional last seen timestamp from pipeline input. When provided together with other device metadata, the cmdlet can reuse it during non-interactive session creation.
-OsPlatform
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 4 |
| Pipeline input | true (ByPropertyName) |
| Default | Not documented |
Optional operating system platform from pipeline input. Used to determine the initial working directory without requiring an additional device metadata lookup.
-NonInteractive
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Connects to Live Response and returns a session object without starting the interactive prompt loop.
-NoStatusTable
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Suppresses the live status table shown during multi-device non-interactive session creation. Returned session objects are unchanged.
Examples
Connect-XdrEndpointDeviceLiveResponse -DeviceId "980dddb7036eae7e38d30dee7f11b51e573a6fc2"
Opens an interactive Live Response session to the specified device.
$lr = Connect-XdrEndpointDeviceLiveResponse -DeviceId "980dddb7036eae7e38d30dee7f11b51e573a6fc2" -NonInteractive
Connects to the device and returns a session object for script-driven command execution.
$devices | Connect-XdrEndpointDeviceLiveResponse -NonInteractive -NoStatusTable
Connects to multiple devices without rendering the live status table.
Invoke-XdrEndpointDeviceAction -DeviceId "980dddb7036eae7e38d30dee7f11b51e573a6fc2" -LiveResponse
Opens a Live Response session via the unified action cmdlet.
Output
Type: PSCustomObject
When -NonInteractive is used, returns an XdrEndpointDeviceLiveResponseSession object. In interactive mode, no output is returned.