← All XDRInternals commands

POWERSHELL COMMAND

ConvertTo-XdrEncodedAdvancedHuntingQuery

Encodes an Advanced Hunting query for use in Microsoft Defender XDR.

View source ↗

Converts a KQL (Kusto Query Language) query into an encoded format that can be used in Microsoft Defender XDR Advanced Hunting. This is useful for generating shareable query links or for API operations that require encoded queries.

Syntax

ConvertTo-XdrEncodedAdvancedHuntingQuery [-QueryText] <string> [<CommonParameters>]

Parameters

-QueryText

Property Value
Type String
Required Yes
Position 1
Pipeline input true (ByValue, ByPropertyName)
Default Not documented

The KQL query text to be encoded. This should be a valid Advanced Hunting query.

Examples

ConvertTo-XdrEncodedAdvancedHuntingQuery -QueryText "DeviceInfo | take 10"
Encodes a simple query to retrieve 10 device records.
$query = @"
ExposureGraphNodes
| where NodeLabel !in ("iam.user" ,"gcp-user", "user")
| where EntityIds has_any ("AzureResourceId","AwsResourceName","GcpFullResourceName")
| where isnotnull(NodeProperties.rawData.criticalityLevel)
"@
ConvertTo-XdrEncodedAdvancedHuntingQuery -QueryText $query
Encodes a multi-line query for exposure graph analysis.
Get-Content query.kql -Raw | ConvertTo-XdrEncodedAdvancedHuntingQuery
Encodes a query from a file using pipeline input.

Output

Type: String

Returns the encoded query string that can be used in URLs or API calls.

View source