POWERSHELL COMMAND
Get-XdrXspmTopTarget
Retrieves top targets from Microsoft Defender XDR XSPM attack paths.
Gets the top targets from active and new attack paths in the XSPM (Extended Security Posture Management) API. Targets are the critical assets that attackers are attempting to compromise through attack paths. Results are summarized by target ID and ordered by the number of attack paths targeting each asset. Returns the top 3 targets by default. This function includes caching support with a 30-minute TTL to reduce API calls.
Syntax
Get-XdrXspmTopTarget [[-Top] <int>] [-Force] [<CommonParameters>]
Parameters
-Top
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | 1 |
| Pipeline input | No |
| Default | 10 |
The maximum number of top targets to return. Default is 3. Note: The query includes “top N” logic embedded.
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypasses the cache and forces a fresh retrieval from the API.
Examples
Get-XdrXspmTopTarget
Retrieves the top 3 targets from active and new attack paths.
Get-XdrXspmTopTarget -Top 10
Retrieves the top 10 targets from active and new attack paths.
Get-XdrXspmTopTarget -Force
Retrieves the top targets, bypassing the cache.
Output
Type: Array
Returns an array of target objects containing TargetId, TargetName, and count (number of attack paths).