← All XDRInternals commands

POWERSHELL COMMAND

Get-XdrXspmAttackPath

Retrieves attack path data from Microsoft Defender XDR XSPM.

View source ↗

Gets attack path information from the XSPM (Extended Security Posture Management) attack surface API. Attack paths represent potential routes attackers could take to compromise critical assets. Supports pagination and can retrieve all available attack paths when using the -All parameter. This function includes caching support with a 30-minute TTL to reduce API calls.

Syntax

Get-XdrXspmAttackPath [[-Top] <int>] [[-Skip] <int>] [-All] [-Force] [<CommonParameters>]

Parameters

-Top

Property Value
Type Int32
Required No
Position 1
Pipeline input No
Default 0

The maximum number of attack paths to return per page. Default is 100. Ignored when -All is specified.

-Skip

Property Value
Type Int32
Required No
Position 2
Pipeline input No
Default 0

The number of attack paths to skip for pagination. Default is 0. Ignored when -All is specified.

-All

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

When specified, retrieves all available attack paths by handling pagination automatically.

-Force

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Bypasses the cache and forces a fresh retrieval from the API.

Examples

Get-XdrXspmAttackPath
Retrieves the first 100 attack paths.
Get-XdrXspmAttackPath -Top 50
Retrieves the first 50 attack paths.
Get-XdrXspmAttackPath -Top 100 -Skip 100
Retrieves attack paths 101-200 (pagination).
Get-XdrXspmAttackPath -All
Retrieves all available attack paths by automatically handling pagination.
Get-XdrXspmAttackPath -All -Force
Retrieves all attack paths, bypassing the cache.

Output

Type: Array

Returns an array of attack path objects containing entry points, targets, paths, risk scores, and status information.

View source