← All XDRInternals commands

POWERSHELL COMMAND

Get-XdrEndpointDeviceLiveResponseLibraryFile

Downloads a script file from the Live Response library.

View source ↗

Retrieves the content of a specific file from the Microsoft Defender XDR Live Response library. Accepts pipeline input from Get-XdrEndpointDeviceLiveResponseLibrary. If -OutputPath is specified, the file is saved to disk. Otherwise the decoded content is returned as a string.

Syntax

Get-XdrEndpointDeviceLiveResponseLibraryFile [-FileName] <string> [[-OutputPath] <string>] [<CommonParameters>]

Parameters

-FileName

Property Value
Type String
Required Yes
Position 1
Pipeline input true (ByPropertyName)
Default Not documented

The name of the file to download from the library (e.g. ‘PasskeyLogin.ps1’). Accepts ValueFromPipelineByPropertyName, so objects from Get-XdrEndpointDeviceLiveResponseLibrary pipe directly using the file_name property.

-OutputPath

Property Value
Type String
Required No
Position 2
Pipeline input No
Default Not documented

Optional file path to save the downloaded content. If omitted, the content is returned as a string.

Examples

Get-XdrEndpointDeviceLiveResponseLibraryFile -FileName 'PasskeyLogin.ps1'
Returns the content of PasskeyLogin.ps1 as a string.
Get-XdrEndpointDeviceLiveResponseLibraryFile -FileName 'PasskeyLogin.ps1' -OutputPath 'C:\Temp\PasskeyLogin.ps1'
Downloads and saves the file to disk.
Get-XdrEndpointDeviceLiveResponseLibrary | Where-Object file_name -eq 'PasskeyLogin.ps1' | Get-XdrEndpointDeviceLiveResponseLibraryFile
Downloads a library file using pipeline input.

Output

Type: System.String

Returns the file content as a string when no OutputPath is specified.

View source