POWERSHELL COMMAND
Get-XdrIncident
Retrieves incidents from Microsoft Defender XDR.
Gets incidents from Microsoft Defender XDR with support for pagination, sorting, and filtering. This cmdlet translates severity values and detection source IDs to friendly names. Severity translations: 32=Information, 64=Low, 128=Medium, 256=High This function includes caching support with a 10-minute TTL to reduce API calls.
Syntax
Get-XdrIncident [-TitleSearchTerms <string[]>] [-LookBackInDays <int>] [-SortByField <string>] [-SortOrder <string>] [-PageSize <int>] [-PageIndex <int>] [-DefenderExpertsLicensed] [-All] [-Force] [<CommonParameters>]
Get-XdrIncident -IncidentId <int> [<CommonParameters>]
Parameters
-TitleSearchTerms
| Property | Value |
|---|---|
| Type | String[] |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Array of search terms to filter incidents by title.
-LookBackInDays
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 30 |
Number of days to look back for incidents. Default is 30.
-SortByField
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | TopRisk |
Field to sort by. Valid values are: TopRisk, CreatedDate, LastUpdatedDate, Status, severity, name. Default is TopRisk.
-SortOrder
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Descending |
Sort order. Valid values are Ascending or Descending. Default is Descending.
-PageSize
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 40 |
Number of incidents to retrieve per page. Default is 40.
-PageIndex
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 1 |
Page index for pagination. Default is 1.
-DefenderExpertsLicensed
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Indicates if Microsoft Defender Experts for XDR license is assigned to the tenant. Default is false.
-All
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Retrieves all incidents by automatically paging through all results. When specified, PageSize and PageIndex parameters are used for the page size, but pagination is automatic.
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypasses the cache and forces a fresh retrieval from the API.
-IncidentId
| Property | Value |
|---|---|
| Type | Int32 |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | 0 |
Retrieves a specific incident by its ID. When specified, all other filtering and pagination parameters are ignored. Cannot be combined with any other parameters.
Examples
Get-XdrIncident
Retrieves the first 40 incidents from the last 30 days, sorted by TopRisk in descending order.
Get-XdrIncident -LookBackInDays 7 -PageSize 100
Retrieves the first 100 incidents from the last 7 days.
Get-XdrIncident -SortByField CreatedDate -SortOrder Ascending
Retrieves incidents sorted by creation date in ascending order (oldest first).
Get-XdrIncident -TitleSearchTerms "ransomware", "phishing"
Retrieves incidents with titles containing "ransomware" or "phishing".
Get-XdrIncident -All
Retrieves all incidents by automatically paging through all results.
Get-XdrIncident -DefenderExpertsLicensed -LookBackInDays 90
Retrieves incidents from the last 90 days for a tenant with Defender Experts license.
Get-XdrIncident -IncidentId 2823
Retrieves a specific incident by its ID.
Get-XdrIncident | Where-Object { $_.SeverityName -eq "High" }
Retrieves incidents and filters for high severity ones.
Output
Type: Object[]
Returns an array of incident objects with properties including:
- IncidentId: Unique incident identifier
- Title: Incident title
- Severity: Numeric severity value
- SeverityName: Friendly severity name (Information/Low/Medium/High)
- DetectionSources: Array of numeric detection source IDs
- DetectionSourceNames: Array of friendly detection source names
- Status: Incident status
- CreatedTime: When the incident was created
- LastUpdateTime: When the incident was last updated
- AlertCount: Number of alerts in the incident
- Classification: Incident classification
- Determination: Incident determination And many other properties from the API response