← All XDRInternals commands

POWERSHELL COMMAND

Get-XdrXspmTopEntryPoint

Retrieves top entry points from Microsoft Defender XDR XSPM attack paths.

View source ↗

Gets the top entry points from active and new attack paths in the XSPM (Extended Security Posture Management) API. Entry points are the initial access points that attackers could use to begin an attack path. Results are summarized by entry point ID and ordered by the number of attack paths using each entry point. Returns the top 10 entry points by default. This function includes caching support with a 30-minute TTL to reduce API calls.

Syntax

Get-XdrXspmTopEntryPoint [[-Top] <int>] [-Force] [<CommonParameters>]

Parameters

-Top

Property Value
Type Int32
Required No
Position 1
Pipeline input No
Default 10

The maximum number of top entry points to return. Default is 10. Note: The query includes “top 10” logic, so values other than 10 may not affect results unless the query is modified.

-Force

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Bypasses the cache and forces a fresh retrieval from the API.

Examples

Get-XdrXspmTopEntryPoint
Retrieves the top 10 entry points from active and new attack paths.
Get-XdrXspmTopEntryPoint -Force
Retrieves the top entry points, bypassing the cache.

Output

Type: Array

Returns an array of entry point objects containing EntryPointId, EntryPointName, and AttackPathsCount.

View source