← All XDRInternals commands

POWERSHELL COMMAND

Get-XdrThreatAnalyticsOutbreaks

Retrieves threat analytics outbreaks from Microsoft Defender XDR.

View source ↗

Gets threat analytics outbreaks data from the Microsoft Defender XDR portal. This function includes caching support with a 30-minute TTL to reduce API calls.

By default, retrieves the full outbreaks list. Use -ChangeCount or -TopThreats switches to retrieve specific outbreak metrics from dedicated endpoints.

Syntax

Get-XdrThreatAnalyticsOutbreaks [-Force] [<CommonParameters>]

Get-XdrThreatAnalyticsOutbreaks [-Force] [-ChangeCount] [<CommonParameters>]

Get-XdrThreatAnalyticsOutbreaks [-Force] [-TopThreats] [<CommonParameters>]

Parameters

-Force

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Bypasses the cache and forces a fresh retrieval from the API.

-ChangeCount

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Returns the outbreak change count information using the dedicated /changeCount endpoint. This provides metrics about changes in outbreak data over time.

-TopThreats

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Returns the top threats from outbreaks using the dedicated /topThreats endpoint. This provides a prioritized list of the most significant threats.

Examples

Get-XdrThreatAnalyticsOutbreaks
Retrieves threat analytics outbreaks using cached data if available.
Get-XdrThreatAnalyticsOutbreaks -Force
Forces a fresh retrieval of threat analytics outbreaks, bypassing the cache.
Get-XdrThreatAnalyticsOutbreaks -ChangeCount
Retrieves the outbreak change count metrics from the dedicated endpoint.
Get-XdrThreatAnalyticsOutbreaks -TopThreats
Retrieves the top threats from outbreaks, prioritized by significance.
Get-XdrThreatAnalyticsOutbreaks -TopThreats -Force
Forces a fresh retrieval of top threats, bypassing the cache.

Output

Type: Object

Returns the threat analytics outbreaks data, change count, or top threats depending on parameters.

View source