← All XDRInternals commands

POWERSHELL COMMAND

Get-XdrIncident

Retrieves incidents from Microsoft Defender XDR.

View source ↗

Gets incidents from Microsoft Defender XDR with support for pagination, sorting, and filtering. This cmdlet translates severity values and detection source IDs to friendly names. Severity translations: 32=Information, 64=Low, 128=Medium, 256=High This function includes caching support with a 10-minute TTL to reduce API calls.

Syntax

Get-XdrIncident [-TitleSearchTerms <string[]>] [-LookBackInDays <int>] [-SortByField <string>] [-SortOrder <string>] [-PageSize <int>] [-PageIndex <int>] [-DefenderExpertsLicensed] [-All] [-Force] [<CommonParameters>]

Get-XdrIncident -IncidentId <int> [<CommonParameters>]

Parameters

-TitleSearchTerms

Property Value
Type String[]
Required No
Position named
Pipeline input No
Default Not documented

Array of search terms to filter incidents by title.

-LookBackInDays

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 30

Number of days to look back for incidents. Default is 30.

-SortByField

Property Value
Type String
Required No
Position named
Pipeline input No
Default TopRisk

Field to sort by. Valid values are: TopRisk, CreatedDate, LastUpdatedDate, Status, severity, name. Default is TopRisk.

-SortOrder

Property Value
Type String
Required No
Position named
Pipeline input No
Default Descending

Sort order. Valid values are Ascending or Descending. Default is Descending.

-PageSize

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 40

Number of incidents to retrieve per page. Default is 40.

-PageIndex

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 1

Page index for pagination. Default is 1.

-DefenderExpertsLicensed

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Indicates if Microsoft Defender Experts for XDR license is assigned to the tenant. Default is false.

-All

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Retrieves all incidents by automatically paging through all results. When specified, PageSize and PageIndex parameters are used for the page size, but pagination is automatic.

-Force

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Bypasses the cache and forces a fresh retrieval from the API.

-IncidentId

Property Value
Type Int32
Required Yes
Position named
Pipeline input No
Default 0

Retrieves a specific incident by its ID. When specified, all other filtering and pagination parameters are ignored. Cannot be combined with any other parameters.

Examples

Get-XdrIncident
Retrieves the first 40 incidents from the last 30 days, sorted by TopRisk in descending order.
Get-XdrIncident -LookBackInDays 7 -PageSize 100
Retrieves the first 100 incidents from the last 7 days.
Get-XdrIncident -SortByField CreatedDate -SortOrder Ascending
Retrieves incidents sorted by creation date in ascending order (oldest first).
Get-XdrIncident -TitleSearchTerms "ransomware", "phishing"
Retrieves incidents with titles containing "ransomware" or "phishing".
Get-XdrIncident -All
Retrieves all incidents by automatically paging through all results.
Get-XdrIncident -DefenderExpertsLicensed -LookBackInDays 90
Retrieves incidents from the last 90 days for a tenant with Defender Experts license.
Get-XdrIncident -IncidentId 2823
Retrieves a specific incident by its ID.
Get-XdrIncident | Where-Object { $_.SeverityName -eq "High" }
Retrieves incidents and filters for high severity ones.

Output

Type: Object[]

Returns an array of incident objects with properties including:

  • IncidentId: Unique incident identifier
  • Title: Incident title
  • Severity: Numeric severity value
  • SeverityName: Friendly severity name (Information/Low/Medium/High)
  • DetectionSources: Array of numeric detection source IDs
  • DetectionSourceNames: Array of friendly detection source names
  • Status: Incident status
  • CreatedTime: When the incident was created
  • LastUpdateTime: When the incident was last updated
  • AlertCount: Number of alerts in the incident
  • Classification: Incident classification
  • Determination: Incident determination And many other properties from the API response

View source