POWERSHELL COMMAND
Get-XdrEndpointDeviceLiveResponseLibraryFile
Downloads a script file from the Live Response library.
Retrieves the content of a specific file from the Microsoft Defender XDR Live Response library. Accepts pipeline input from Get-XdrEndpointDeviceLiveResponseLibrary. If -OutputPath is specified, the file is saved to disk. Otherwise the decoded content is returned as a string.
Syntax
Get-XdrEndpointDeviceLiveResponseLibraryFile [-FileName] <string> [[-OutputPath] <string>] [<CommonParameters>]
Parameters
-FileName
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | 1 |
| Pipeline input | true (ByPropertyName) |
| Default | Not documented |
The name of the file to download from the library (e.g. ‘PasskeyLogin.ps1’). Accepts ValueFromPipelineByPropertyName, so objects from Get-XdrEndpointDeviceLiveResponseLibrary pipe directly using the file_name property.
-OutputPath
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 2 |
| Pipeline input | No |
| Default | Not documented |
Optional file path to save the downloaded content. If omitted, the content is returned as a string.
Examples
Get-XdrEndpointDeviceLiveResponseLibraryFile -FileName 'PasskeyLogin.ps1'
Returns the content of PasskeyLogin.ps1 as a string.
Get-XdrEndpointDeviceLiveResponseLibraryFile -FileName 'PasskeyLogin.ps1' -OutputPath 'C:\Temp\PasskeyLogin.ps1'
Downloads and saves the file to disk.
Get-XdrEndpointDeviceLiveResponseLibrary | Where-Object file_name -eq 'PasskeyLogin.ps1' | Get-XdrEndpointDeviceLiveResponseLibraryFile
Downloads a library file using pipeline input.
Output
Type: System.String
Returns the file content as a string when no OutputPath is specified.