POWERSHELL COMMAND
Get-XdrAdvancedHuntingFunction
Retrieves Advanced Hunting functions from Microsoft Defender XDR.
Gets saved functions for Advanced Hunting queries in Microsoft Defender XDR. Functions can be filtered by ID or retrieved all at once. This function includes caching support with a 30-minute TTL to reduce API calls.
Syntax
Get-XdrAdvancedHuntingFunction [[-Id] <int>] [-Force] [<CommonParameters>]
Parameters
-Id
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | 1 |
| Pipeline input | true (ByValue, ByPropertyName) |
| Default | 0 |
Optional ID of a specific function to retrieve. If not specified, all functions will be returned.
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypasses the cache and forces a fresh retrieval from the API.
Examples
Get-XdrAdvancedHuntingFunction
Retrieves all Advanced Hunting functions using cached data if available.
Get-XdrAdvancedHuntingFunction -Force
Forces a fresh retrieval of all functions, bypassing the cache.
Get-XdrAdvancedHuntingFunction -Id 6
Retrieves a specific function by ID.
Get-XdrAdvancedHuntingFunction | Where-Object { $_.IsShared -eq $true }
Retrieves only shared functions.
Get-XdrAdvancedHuntingFunction | Where-Object { $_.Path -like "MyFolder*" }
Retrieves functions in a specific folder path.
Output
Type: Object[]
Returns an array of Advanced Hunting function objects containing:
- Id: Unique identifier for the function
- Name: Function name
- Body: KQL query body
- Description: Function description
- Path: Folder path
- IsShared: Sharing status
- CreatedBy: Creator’s UPN
- LastUpdatedBy: Last updater’s UPN
- LastUpdateTime: Last update timestamp
- InputParameters: Function parameters (if any)
- OutputColumns: Schema of the function output
- IsReadOnly: Whether the function is read-only