← All XDRInternals commands

POWERSHELL COMMAND

New-XdrEndpointDeviceLiveResponseLibraryFile

Uploads a script file to the Live Response library.

View source ↗

Uploads a local script file to the Microsoft Defender XDR Live Response library. The file can then be used with the ‘putfile’ and ‘run’ commands during Live Response sessions. Multipart form-data is constructed as a byte array to maintain WebSession cookie compatibility.

Syntax

New-XdrEndpointDeviceLiveResponseLibraryFile [-FilePath] <string> [[-Description] <string>] [[-ParametersDescription] <string>] [-HasParameters] [-OverrideIfExists] [-WhatIf] [-Confirm] [<CommonParameters>]

Parameters

-FilePath

Property Value
Type String
Required Yes
Position 1
Pipeline input No
Default Not documented

The full path to the local script file to upload.

-Description

Property Value
Type String
Required No
Position 2
Pipeline input No
Default Not documented

Optional description for the library file.

-HasParameters

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Indicates that the script accepts parameters during execution.

-ParametersDescription

Property Value
Type String
Required No
Position 3
Pipeline input No
Default Not documented

Description of the parameters accepted by the script. Only relevant when -HasParameters is specified.

-OverrideIfExists

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

If specified, overwrites an existing library file with the same name. Without this switch, uploading a duplicate file name will fail.

-WhatIf

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Shows what would happen if the cmdlet runs. The file is not uploaded.

-Confirm

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Prompts you for confirmation before uploading the file.

Examples

New-XdrEndpointDeviceLiveResponseLibraryFile -FilePath 'C:\Scripts\Remediate.ps1'
Uploads Remediate.ps1 to the Live Response library.
'
Uploads with metadata describing the script parameters.
New-XdrEndpointDeviceLiveResponseLibraryFile -FilePath 'C:\Scripts\Remediate.ps1' -OverrideIfExists
Replaces an existing library file with the same name.

Output

Type: Object

Returns the API response containing the uploaded file metadata.

View source