← All XDRInternals commands

POWERSHELL COMMAND

Remove-XdrEndpointDeviceLiveResponseLibraryFile

Deletes a file from the Live Response library.

View source ↗

Removes a script file from the Microsoft Defender XDR Live Response library. When only -FileName is provided, the cmdlet automatically looks up the file metadata (last_updated_time) required by the API. Accepts pipeline input from Get-XdrEndpointDeviceLiveResponseLibrary.

Syntax

Remove-XdrEndpointDeviceLiveResponseLibraryFile [-FileName] <string> [-WhatIf] [-Confirm] [<CommonParameters>]

Remove-XdrEndpointDeviceLiveResponseLibraryFile -InputObject <Object> [-WhatIf] [-Confirm] [<CommonParameters>]

Parameters

-FileName

Property Value
Type String
Required Yes
Position 1
Pipeline input true (ByPropertyName)
Default Not documented

The name of the file to delete from the library (e.g. ‘PasskeyLogin.ps1’).

-InputObject

Property Value
Type Object
Required Yes
Position named
Pipeline input true (ByValue)
Default Not documented

A library file object from Get-XdrEndpointDeviceLiveResponseLibrary. Extracts file_name and last_updated_time automatically.

-WhatIf

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Shows what would happen if the cmdlet runs. The file is not deleted.

-Confirm

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Prompts you for confirmation before deleting the file. Confirmation is required by default.

Examples

Remove-XdrEndpointDeviceLiveResponseLibraryFile -FileName 'OldScript.ps1'
Deletes OldScript.ps1 from the library after confirmation.
Remove-XdrEndpointDeviceLiveResponseLibraryFile -FileName 'OldScript.ps1' -Confirm:$false
Deletes without prompting.
Get-XdrEndpointDeviceLiveResponseLibrary | Where-Object file_name -eq 'OldScript.ps1' | Remove-XdrEndpointDeviceLiveResponseLibraryFile
Deletes using pipeline input from the library listing.
Remove-XdrEndpointDeviceLiveResponseLibraryFile -FileName 'OldScript.ps1' -WhatIf
Shows what would be deleted without performing the deletion.

Output

Type: None

This cmdlet does not return output on successful deletion.

View source