← All XDRInternals commands

POWERSHELL COMMAND

Get-XdrXspmTopTarget

Retrieves top targets from Microsoft Defender XDR XSPM attack paths.

View source ↗

Gets the top targets from active and new attack paths in the XSPM (Extended Security Posture Management) API. Targets are the critical assets that attackers are attempting to compromise through attack paths. Results are summarized by target ID and ordered by the number of attack paths targeting each asset. Returns the top 3 targets by default. This function includes caching support with a 30-minute TTL to reduce API calls.

Syntax

Get-XdrXspmTopTarget [[-Top] <int>] [-Force] [<CommonParameters>]

Parameters

-Top

Property Value
Type Int32
Required No
Position 1
Pipeline input No
Default 10

The maximum number of top targets to return. Default is 3. Note: The query includes “top N” logic embedded.

-Force

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Bypasses the cache and forces a fresh retrieval from the API.

Examples

Get-XdrXspmTopTarget
Retrieves the top 3 targets from active and new attack paths.
Get-XdrXspmTopTarget -Top 10
Retrieves the top 10 targets from active and new attack paths.
Get-XdrXspmTopTarget -Force
Retrieves the top targets, bypassing the cache.

Output

Type: Array

Returns an array of target objects containing TargetId, TargetName, and count (number of attack paths).

View source