POWERSHELL COMMAND
Invoke-XdrHuntingQueryValidation
Validates an Advanced Hunting query for custom detection rules in Microsoft Defender XDR.
Validates whether an Advanced Hunting query is allowed and checks the permissions required for creating custom detection rules. This is useful before attempting to create a custom detection rule to ensure the query syntax is valid and the user has appropriate permissions.
Syntax
Invoke-XdrHuntingQueryValidation [-QueryText] <string> [[-HuntingRule] <Object>] [<CommonParameters>]
Parameters
-QueryText
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | 1 |
| Pipeline input | No |
| Default | Not documented |
The KQL (Kusto Query Language) query text to validate. This should be a valid Advanced Hunting query.
-HuntingRule
| Property | Value |
|---|---|
| Type | Object |
| Required | No |
| Position | 2 |
| Pipeline input | No |
| Default | Not documented |
Optional hunting rule object to validate. If not specified, defaults to null.
Examples
ago(1h)"
Validates the specified Advanced Hunting query.
$query = @"
DeviceEvents
| where ActionType == "ProcessCreated"
| where FileName == "powershell.exe"
| project Timestamp, DeviceName, AccountName, ProcessCommandLine
"@
Invoke-XdrHuntingQueryValidation -QueryText $query
Validates a multi-line Advanced Hunting query.
Invoke-XdrHuntingQueryValidation -QueryText "DeviceProcessEvents | where false"
Validates a simple test query that returns no results.
Output
Type: Object
Returns a validation response object containing:
- IsAllowed: Boolean indicating if the query is allowed
- Permissions: Object containing permission details for each workload (Mdatp, etc.)