← All XDRInternals commands

POWERSHELL COMMAND

Invoke-XdrEndpointDeviceLiveResponseCommand

Sends a command to an active Live Response session in Microsoft Defender XDR.

View source ↗

Submits a command to an active Live Response session and polls for the result. Parses the raw command line to extract the command definition ID and parameters, then sends the command via the Live Response API and waits for completion.

Supports the full Live Response command syntax including:

  • Positional parameters mapped by order from the command definition
  • Named parameters using -paramName value syntax (e.g. -output json, -name notepad.exe)
  • Boolean flags using -flagName syntax (e.g. -full_path, -upload, -overwrite, -keep)
  • Alias resolution (ls -> dir, process -> processes, download -> getfile, etc.)

This cmdlet can be used programmatically or is called automatically by Connect-XdrEndpointDeviceLiveResponse during interactive sessions.

Syntax

Invoke-XdrEndpointDeviceLiveResponseCommand [-SessionId] <string> [-Command] <string> [[-CurrentDirectory] <string>] [[-TimeoutSeconds] <int>] [[-PollIntervalSeconds] <int>] [[-CommandDefinitions] <array>] [[-DeviceName] <string>] [[-DeviceId] <string>] [-BackgroundMode] [-ExpandTableOutput] [-IncludeCommandResult] [-RawCommandResult] [<CommonParameters>]

Parameters

-SessionId

Property Value
Type String
Required Yes
Position 1
Pipeline input true (ByValue, ByPropertyName)
Default Not documented

The Live Response session ID (starts with CLR prefix).

-Command

Property Value
Type String
Required Yes
Position 2
Pipeline input No
Default Not documented

The raw command line to execute (e.g., “dir /Applications”, “processes”, “getfile /etc/hosts”). Supports all Live Response command aliases (ls, process, download, etc.). Values containing spaces must be quoted: getfile “/Applications/Utilities/Activity Monitor.app/Contents/Info.plist”

-CurrentDirectory

Property Value
Type String
Required No
Position 3
Pipeline input true (ByPropertyName)
Default C:</code>

The current working directory on the remote device. Defaults to “C:" for Windows sessions. For macOS and Linux sessions, use ‘/’ or the session’s reported current directory.

-BackgroundMode

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Run the command in background mode if supported.

-TimeoutSeconds

Property Value
Type Int32
Required No
Position 4
Pipeline input No
Default 300

Maximum time to wait for command completion. Defaults to 300 seconds (5 minutes). Automatically extended to 600s for analyze commands.

-PollIntervalSeconds

Property Value
Type Int32
Required No
Position 5
Pipeline input No
Default 2

How often to check for command completion. Defaults to 2 seconds.

-CommandDefinitions

Property Value
Type Array
Required No
Position 6
Pipeline input true (ByPropertyName)
Default Not documented

Array of command definition objects from the Live Response API’s get_command_definitions endpoint. Used to resolve aliases and correctly classify -name tokens as flags or named parameters. When not provided, falls back to heuristic parsing with ‘path’ as the default param_id.

-DeviceName

Property Value
Type String
Required No
Position 7
Pipeline input true (ByPropertyName)
Default Not documented

Optional device name to stamp onto the returned command object.

-DeviceId

Property Value
Type String
Required No
Position 8
Pipeline input true (ByPropertyName)
Default Not documented

Optional device ID to stamp onto the returned command object.

-ExpandTableOutput

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

When set, emits PowerShell-native row objects for table outputs and stamps each row with Timestamp, DeviceName, DeviceId, command, and status metadata.

-IncludeCommandResult

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

When used with -ExpandTableOutput, also emits the original command result object before the flattened table rows.

-RawCommandResult

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Returns the original command result object without default structured table expansion. Useful for callers such as the interactive Live Response shell that need the raw outputs, context, and error collections from the API response.

Examples

Invoke-XdrEndpointDeviceLiveResponseCommand -SessionId "CLR0c33ce1c-1665-4e00-9059-8fa39da9e2cb" -Command "processes"
Lists running processes on the remote device.
Invoke-XdrEndpointDeviceLiveResponseCommand -SessionId "CLR0c33ce1c-1665-4e00-9059-8fa39da9e2cb" -Command "dir /Applications" -CurrentDirectory "/"
Lists the contents of /Applications on a macOS device.
Invoke-XdrEndpointDeviceLiveResponseCommand -SessionId "CLR0c33ce1c-1665-4e00-9059-8fa39da9e2cb" -Command "dir -full_path"
Lists all files with full paths. The -full_path flag is correctly sent in the flags[] array.
Invoke-XdrEndpointDeviceLiveResponseCommand -SessionId "CLR0c33ce1c-1665-4e00-9059-8fa39da9e2cb" -Command "process -name launchd"
Filters processes by name using the 'process' alias and a named -name parameter on macOS.
Invoke-XdrEndpointDeviceLiveResponseCommand -SessionId "CLR0c33ce1c-1665-4e00-9059-8fa39da9e2cb" -Command "getfile /etc/hosts" -TimeoutSeconds 120
Downloads a file from a macOS device with a 2-minute timeout.
Invoke-XdrEndpointDeviceLiveResponseCommand -SessionId "CLR0c33ce1c-1665-4e00-9059-8fa39da9e2cb" -Command "ls"
Lists files using the 'ls' alias for 'dir'. Alias is preserved in raw_command_line.
$sessions | Invoke-XdrEndpointDeviceLiveResponseCommand -Command "processes" -ExpandTableOutput
Returns one PowerShell object per process row, stamped with device and execution metadata.
$sessions | Invoke-XdrEndpointDeviceLiveResponseCommand -Command "processes" -ExpandTableOutput -IncludeCommandResult
Returns the original command result object followed by flattened process rows.
Invoke-XdrEndpointDeviceLiveResponseCommand -SessionId "CLR0c33ce1c-1665-4e00-9059-8fa39da9e2cb" -Command "drivers" -RawCommandResult
Returns the original command result object without expanding structured table rows.

Output

Type: PSCustomObject

Returns the command result object including output, status, context, and errors. With -ExpandTableOutput, returns flattened table row objects when table outputs are present.

View source