POWERSHELL COMMAND
Get-XdrEndpointDeviceLiveResponseLibrary
Retrieves the Live Response library files from Microsoft Defender XDR.
Gets the list of files available in the Live Response library. These files can be used with the ‘putfile’ and ‘run’ commands during Live Response sessions. Results are cached for 15 minutes.
Syntax
Get-XdrEndpointDeviceLiveResponseLibrary [-Force] [<CommonParameters>]
Parameters
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypasses the cache and forces a fresh retrieval from the API.
Examples
Get-XdrEndpointDeviceLiveResponseLibrary
Lists all files in the Live Response library.
Get-XdrEndpointDeviceLiveResponseLibrary -Force
Forces a fresh retrieval of the library file list.
Output
Type: Object
Returns the library file listing.