← All XDRInternals commands

POWERSHELL COMMAND

Invoke-XdrHuntingQueryValidation

Validates an Advanced Hunting query for custom detection rules in Microsoft Defender XDR.

View source ↗

Validates whether an Advanced Hunting query is allowed and checks the permissions required for creating custom detection rules. This is useful before attempting to create a custom detection rule to ensure the query syntax is valid and the user has appropriate permissions.

Syntax

Invoke-XdrHuntingQueryValidation [-QueryText] <string> [[-HuntingRule] <Object>] [<CommonParameters>]

Parameters

-QueryText

Property Value
Type String
Required Yes
Position 1
Pipeline input No
Default Not documented

The KQL (Kusto Query Language) query text to validate. This should be a valid Advanced Hunting query.

-HuntingRule

Property Value
Type Object
Required No
Position 2
Pipeline input No
Default Not documented

Optional hunting rule object to validate. If not specified, defaults to null.

Examples

ago(1h)"
Validates the specified Advanced Hunting query.
$query = @"
DeviceEvents
| where ActionType == "ProcessCreated"
| where FileName == "powershell.exe"
| project Timestamp, DeviceName, AccountName, ProcessCommandLine
"@
Invoke-XdrHuntingQueryValidation -QueryText $query
Validates a multi-line Advanced Hunting query.
Invoke-XdrHuntingQueryValidation -QueryText "DeviceProcessEvents | where false"
Validates a simple test query that returns no results.

Output

Type: Object

Returns a validation response object containing:

  • IsAllowed: Boolean indicating if the query is allowed
  • Permissions: Object containing permission details for each workload (Mdatp, etc.)

View source