POWERSHELL COMMAND
Get-XdrThreatAnalyticsOutbreaks
Retrieves threat analytics outbreaks from Microsoft Defender XDR.
Gets threat analytics outbreaks data from the Microsoft Defender XDR portal. This function includes caching support with a 30-minute TTL to reduce API calls.
By default, retrieves the full outbreaks list. Use -ChangeCount or -TopThreats switches to retrieve specific outbreak metrics from dedicated endpoints.
Syntax
Get-XdrThreatAnalyticsOutbreaks [-Force] [<CommonParameters>]
Get-XdrThreatAnalyticsOutbreaks [-Force] [-ChangeCount] [<CommonParameters>]
Get-XdrThreatAnalyticsOutbreaks [-Force] [-TopThreats] [<CommonParameters>]
Parameters
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypasses the cache and forces a fresh retrieval from the API.
-ChangeCount
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Returns the outbreak change count information using the dedicated /changeCount endpoint. This provides metrics about changes in outbreak data over time.
-TopThreats
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Returns the top threats from outbreaks using the dedicated /topThreats endpoint. This provides a prioritized list of the most significant threats.
Examples
Get-XdrThreatAnalyticsOutbreaks
Retrieves threat analytics outbreaks using cached data if available.
Get-XdrThreatAnalyticsOutbreaks -Force
Forces a fresh retrieval of threat analytics outbreaks, bypassing the cache.
Get-XdrThreatAnalyticsOutbreaks -ChangeCount
Retrieves the outbreak change count metrics from the dedicated endpoint.
Get-XdrThreatAnalyticsOutbreaks -TopThreats
Retrieves the top threats from outbreaks, prioritized by significance.
Get-XdrThreatAnalyticsOutbreaks -TopThreats -Force
Forces a fresh retrieval of top threats, bypassing the cache.
Output
Type: Object
Returns the threat analytics outbreaks data, change count, or top threats depending on parameters.