POWERSHELL COMMAND
New-XdrAdvancedHuntingFunction
Creates a new Advanced Hunting function in Microsoft Defender XDR.
Creates a new saved function for Advanced Hunting queries in Microsoft Defender XDR. These functions can be reused across multiple hunting queries and detection rules. Functions can be shared with the organization or kept private in folder structures.
Syntax
New-XdrAdvancedHuntingFunction [-Name] <string> [-KQLQuery] <string> [[-Description] <string>] [[-FolderPath] <string>] [-IsShared] [-WhatIf] [-Confirm] [<CommonParameters>]
Parameters
-Name
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | 1 |
| Pipeline input | No |
| Default | Not documented |
The name of the function. This will be used to call the function in queries.
-KQLQuery
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | 2 |
| Pipeline input | No |
| Default | Not documented |
The KQL (Kusto Query Language) body of the function. This is the query logic that will be executed when the function is called.
-Description
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 3 |
| Pipeline input | No |
| Default | Not documented |
Optional description of what the function does.
-IsShared
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Switch to make the function shared with the organization. If not specified, the function will be private to the creator.
-FolderPath
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 4 |
| Pipeline input | No |
| Default | Not documented |
Optional folder path for organizing private functions. Use forward slashes (/) or backslashes () - they will be automatically converted to double backslashes. Example: “MyFolder/SubFolder” or “MyFolder\SubFolder”
-WhatIf
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Shows what would happen if the cmdlet runs. The function is not created.
-Confirm
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Prompts you for confirmation before running the cmdlet.
Examples
New-XdrAdvancedHuntingFunction -Name "GetSuspiciousLogons" -KQLQuery "DeviceLogonEvents | where LogonType == 'Network'" -IsShared
Creates a shared function that can be used across the organization.
New-XdrAdvancedHuntingFunction -Name "ExtendedEntraIdSignInEvents" -KQLQuery $query -Description "Combines XDR and Sentinel data" -IsShared
Creates a shared function with a description.
New-XdrAdvancedHuntingFunction -Name "MyFunction" -KQLQuery "DeviceEvents" -FolderPath "TestFolder/SubFolder"
Creates a private function in a folder structure.
$query = @"
EntraIdSignInEvents
| where RiskLevelAggregated > 50
| project Timestamp, AccountUpn, IPAddress
"@
New-XdrAdvancedHuntingFunction -Name "HighRiskSignIns" -KQLQuery $query -Description "Returns high-risk sign-ins" -IsShared
Creates a shared function with a multi-line query.
Output
Type: Object
Returns the created function object from the API including:
- Id: Unique identifier for the function
- Name: Function name
- Body: KQL query body
- Description: Function description
- Path: Folder path
- IsShared: Sharing status
- CreatedBy: Creator’s UPN
- LastUpdatedBy: Last updater’s UPN
- LastUpdateTime: Last update timestamp
- OutputColumns: Schema of the function output