POWERSHELL COMMAND
ConvertTo-XdrEncodedAdvancedHuntingQuery
Encodes an Advanced Hunting query for use in Microsoft Defender XDR.
Converts a KQL (Kusto Query Language) query into an encoded format that can be used in Microsoft Defender XDR Advanced Hunting. This is useful for generating shareable query links or for API operations that require encoded queries.
Syntax
ConvertTo-XdrEncodedAdvancedHuntingQuery [-QueryText] <string> [<CommonParameters>]
Parameters
-QueryText
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | 1 |
| Pipeline input | true (ByValue, ByPropertyName) |
| Default | Not documented |
The KQL query text to be encoded. This should be a valid Advanced Hunting query.
Examples
ConvertTo-XdrEncodedAdvancedHuntingQuery -QueryText "DeviceInfo | take 10"
Encodes a simple query to retrieve 10 device records.
$query = @"
ExposureGraphNodes
| where NodeLabel !in ("iam.user" ,"gcp-user", "user")
| where EntityIds has_any ("AzureResourceId","AwsResourceName","GcpFullResourceName")
| where isnotnull(NodeProperties.rawData.criticalityLevel)
"@
ConvertTo-XdrEncodedAdvancedHuntingQuery -QueryText $query
Encodes a multi-line query for exposure graph analysis.
Get-Content query.kql -Raw | ConvertTo-XdrEncodedAdvancedHuntingQuery
Encodes a query from a file using pipeline input.
Output
Type: String
Returns the encoded query string that can be used in URLs or API calls.