POWERSHELL COMMAND
Get-XdrXspmTopEntryPoint
Retrieves top entry points from Microsoft Defender XDR XSPM attack paths.
Gets the top entry points from active and new attack paths in the XSPM (Extended Security Posture Management) API. Entry points are the initial access points that attackers could use to begin an attack path. Results are summarized by entry point ID and ordered by the number of attack paths using each entry point. Returns the top 10 entry points by default. This function includes caching support with a 30-minute TTL to reduce API calls.
Syntax
Get-XdrXspmTopEntryPoint [[-Top] <int>] [-Force] [<CommonParameters>]
Parameters
-Top
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | 1 |
| Pipeline input | No |
| Default | 10 |
The maximum number of top entry points to return. Default is 10. Note: The query includes “top 10” logic, so values other than 10 may not affect results unless the query is modified.
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypasses the cache and forces a fresh retrieval from the API.
Examples
Get-XdrXspmTopEntryPoint
Retrieves the top 10 entry points from active and new attack paths.
Get-XdrXspmTopEntryPoint -Force
Retrieves the top entry points, bypassing the cache.
Output
Type: Array
Returns an array of entry point objects containing EntryPointId, EntryPointName, and AttackPathsCount.