← All XDRInternals commands

POWERSHELL COMMAND

Remove-XdrAdvancedHuntingFunction

Removes an Advanced Hunting function from Microsoft Defender XDR.

View source ↗

Deletes a saved function for Advanced Hunting queries in Microsoft Defender XDR. The function must exist before it can be removed. The cmdlet will verify the function exists before attempting deletion.

Syntax

Remove-XdrAdvancedHuntingFunction [-Id] <int> [-WhatIf] [-Confirm] [<CommonParameters>]

Remove-XdrAdvancedHuntingFunction -InputObject <Object> [-WhatIf] [-Confirm] [<CommonParameters>]

Parameters

-Id

Property Value
Type Int32
Required Yes
Position 1
Pipeline input No
Default 0

The ID of the function to remove. This is mandatory to ensure the correct function is deleted.

-InputObject

Property Value
Type Object
Required Yes
Position named
Pipeline input true (ByValue)
Default Not documented

PSObject containing the function to remove. The object must include an Id property. Typically obtained from Get-XdrAdvancedHuntingFunction.

-WhatIf

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Shows what would happen if the cmdlet runs. The function is not created.

-Confirm

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Prompts you for confirmation before running the cmdlet.

Examples

Remove-XdrAdvancedHuntingFunction -Id 6
Removes the function with ID 6.
Get-XdrAdvancedHuntingFunction -Id 6 | Remove-XdrAdvancedHuntingFunction
Gets a function and removes it through the pipeline.
Get-XdrAdvancedHuntingFunction | Where-Object { $_.Name -eq "OldFunction" } | Remove-XdrAdvancedHuntingFunction
Finds a function by name and removes it.

Output

Type: None

This cmdlet does not return any output upon successful deletion.

View source