POWERSHELL COMMAND
Invoke-XdrEndpointDeviceLiveResponseCommand
Sends a command to an active Live Response session in Microsoft Defender XDR.
Submits a command to an active Live Response session and polls for the result. Parses the raw command line to extract the command definition ID and parameters, then sends the command via the Live Response API and waits for completion.
Supports the full Live Response command syntax including:
- Positional parameters mapped by order from the command definition
- Named parameters using -paramName value syntax (e.g. -output json, -name notepad.exe)
- Boolean flags using -flagName syntax (e.g. -full_path, -upload, -overwrite, -keep)
- Alias resolution (ls -> dir, process -> processes, download -> getfile, etc.)
This cmdlet can be used programmatically or is called automatically by Connect-XdrEndpointDeviceLiveResponse during interactive sessions.
Syntax
Invoke-XdrEndpointDeviceLiveResponseCommand [-SessionId] <string> [-Command] <string> [[-CurrentDirectory] <string>] [[-TimeoutSeconds] <int>] [[-PollIntervalSeconds] <int>] [[-CommandDefinitions] <array>] [[-DeviceName] <string>] [[-DeviceId] <string>] [-BackgroundMode] [-ExpandTableOutput] [-IncludeCommandResult] [-RawCommandResult] [<CommonParameters>]
Parameters
-SessionId
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | 1 |
| Pipeline input | true (ByValue, ByPropertyName) |
| Default | Not documented |
The Live Response session ID (starts with CLR prefix).
-Command
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | 2 |
| Pipeline input | No |
| Default | Not documented |
The raw command line to execute (e.g., “dir /Applications”, “processes”, “getfile /etc/hosts”). Supports all Live Response command aliases (ls, process, download, etc.). Values containing spaces must be quoted: getfile “/Applications/Utilities/Activity Monitor.app/Contents/Info.plist”
-CurrentDirectory
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 3 |
| Pipeline input | true (ByPropertyName) |
| Default | C:</code> |
The current working directory on the remote device. Defaults to “C:" for Windows sessions. For macOS and Linux sessions, use ‘/’ or the session’s reported current directory.
-BackgroundMode
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Run the command in background mode if supported.
-TimeoutSeconds
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | 4 |
| Pipeline input | No |
| Default | 300 |
Maximum time to wait for command completion. Defaults to 300 seconds (5 minutes). Automatically extended to 600s for analyze commands.
-PollIntervalSeconds
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | 5 |
| Pipeline input | No |
| Default | 2 |
How often to check for command completion. Defaults to 2 seconds.
-CommandDefinitions
| Property | Value |
|---|---|
| Type | Array |
| Required | No |
| Position | 6 |
| Pipeline input | true (ByPropertyName) |
| Default | Not documented |
Array of command definition objects from the Live Response API’s get_command_definitions endpoint. Used to resolve aliases and correctly classify -name tokens as flags or named parameters. When not provided, falls back to heuristic parsing with ‘path’ as the default param_id.
-DeviceName
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 7 |
| Pipeline input | true (ByPropertyName) |
| Default | Not documented |
Optional device name to stamp onto the returned command object.
-DeviceId
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 8 |
| Pipeline input | true (ByPropertyName) |
| Default | Not documented |
Optional device ID to stamp onto the returned command object.
-ExpandTableOutput
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
When set, emits PowerShell-native row objects for table outputs and stamps each row with Timestamp, DeviceName, DeviceId, command, and status metadata.
-IncludeCommandResult
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
When used with -ExpandTableOutput, also emits the original command result object before the flattened table rows.
-RawCommandResult
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Returns the original command result object without default structured table expansion. Useful for callers such as the interactive Live Response shell that need the raw outputs, context, and error collections from the API response.
Examples
Invoke-XdrEndpointDeviceLiveResponseCommand -SessionId "CLR0c33ce1c-1665-4e00-9059-8fa39da9e2cb" -Command "processes"
Lists running processes on the remote device.
Invoke-XdrEndpointDeviceLiveResponseCommand -SessionId "CLR0c33ce1c-1665-4e00-9059-8fa39da9e2cb" -Command "dir /Applications" -CurrentDirectory "/"
Lists the contents of /Applications on a macOS device.
Invoke-XdrEndpointDeviceLiveResponseCommand -SessionId "CLR0c33ce1c-1665-4e00-9059-8fa39da9e2cb" -Command "dir -full_path"
Lists all files with full paths. The -full_path flag is correctly sent in the flags[] array.
Invoke-XdrEndpointDeviceLiveResponseCommand -SessionId "CLR0c33ce1c-1665-4e00-9059-8fa39da9e2cb" -Command "process -name launchd"
Filters processes by name using the 'process' alias and a named -name parameter on macOS.
Invoke-XdrEndpointDeviceLiveResponseCommand -SessionId "CLR0c33ce1c-1665-4e00-9059-8fa39da9e2cb" -Command "getfile /etc/hosts" -TimeoutSeconds 120
Downloads a file from a macOS device with a 2-minute timeout.
Invoke-XdrEndpointDeviceLiveResponseCommand -SessionId "CLR0c33ce1c-1665-4e00-9059-8fa39da9e2cb" -Command "ls"
Lists files using the 'ls' alias for 'dir'. Alias is preserved in raw_command_line.
$sessions | Invoke-XdrEndpointDeviceLiveResponseCommand -Command "processes" -ExpandTableOutput
Returns one PowerShell object per process row, stamped with device and execution metadata.
$sessions | Invoke-XdrEndpointDeviceLiveResponseCommand -Command "processes" -ExpandTableOutput -IncludeCommandResult
Returns the original command result object followed by flattened process rows.
Invoke-XdrEndpointDeviceLiveResponseCommand -SessionId "CLR0c33ce1c-1665-4e00-9059-8fa39da9e2cb" -Command "drivers" -RawCommandResult
Returns the original command result object without expanding structured table rows.
Output
Type: PSCustomObject
Returns the command result object including output, status, context, and errors. With -ExpandTableOutput, returns flattened table row objects when table outputs are present.