← All XDRInternals commands

POWERSHELL COMMAND

Get-XdrAdvancedHuntingFunction

Retrieves Advanced Hunting functions from Microsoft Defender XDR.

View source ↗

Gets saved functions for Advanced Hunting queries in Microsoft Defender XDR. Functions can be filtered by ID or retrieved all at once. This function includes caching support with a 30-minute TTL to reduce API calls.

Syntax

Get-XdrAdvancedHuntingFunction [[-Id] <int>] [-Force] [<CommonParameters>]

Parameters

-Id

Property Value
Type Int32
Required No
Position 1
Pipeline input true (ByValue, ByPropertyName)
Default 0

Optional ID of a specific function to retrieve. If not specified, all functions will be returned.

-Force

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Bypasses the cache and forces a fresh retrieval from the API.

Examples

Get-XdrAdvancedHuntingFunction
Retrieves all Advanced Hunting functions using cached data if available.
Get-XdrAdvancedHuntingFunction -Force
Forces a fresh retrieval of all functions, bypassing the cache.
Get-XdrAdvancedHuntingFunction -Id 6
Retrieves a specific function by ID.
Get-XdrAdvancedHuntingFunction | Where-Object { $_.IsShared -eq $true }
Retrieves only shared functions.
Get-XdrAdvancedHuntingFunction | Where-Object { $_.Path -like "MyFolder*" }
Retrieves functions in a specific folder path.

Output

Type: Object[]

Returns an array of Advanced Hunting function objects containing:

  • Id: Unique identifier for the function
  • Name: Function name
  • Body: KQL query body
  • Description: Function description
  • Path: Folder path
  • IsShared: Sharing status
  • CreatedBy: Creator’s UPN
  • LastUpdatedBy: Last updater’s UPN
  • LastUpdateTime: Last update timestamp
  • InputParameters: Function parameters (if any)
  • OutputColumns: Schema of the function output
  • IsReadOnly: Whether the function is read-only

View source