POWERSHELL COMMAND
Remove-XdrEndpointDeviceLiveResponseLibraryFile
Deletes a file from the Live Response library.
Removes a script file from the Microsoft Defender XDR Live Response library. When only -FileName is provided, the cmdlet automatically looks up the file metadata (last_updated_time) required by the API. Accepts pipeline input from Get-XdrEndpointDeviceLiveResponseLibrary.
Syntax
Remove-XdrEndpointDeviceLiveResponseLibraryFile [-FileName] <string> [-WhatIf] [-Confirm] [<CommonParameters>]
Remove-XdrEndpointDeviceLiveResponseLibraryFile -InputObject <Object> [-WhatIf] [-Confirm] [<CommonParameters>]
Parameters
-FileName
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | 1 |
| Pipeline input | true (ByPropertyName) |
| Default | Not documented |
The name of the file to delete from the library (e.g. ‘PasskeyLogin.ps1’).
-InputObject
| Property | Value |
|---|---|
| Type | Object |
| Required | Yes |
| Position | named |
| Pipeline input | true (ByValue) |
| Default | Not documented |
A library file object from Get-XdrEndpointDeviceLiveResponseLibrary. Extracts file_name and last_updated_time automatically.
-WhatIf
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Shows what would happen if the cmdlet runs. The file is not deleted.
-Confirm
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Prompts you for confirmation before deleting the file. Confirmation is required by default.
Examples
Remove-XdrEndpointDeviceLiveResponseLibraryFile -FileName 'OldScript.ps1'
Deletes OldScript.ps1 from the library after confirmation.
Remove-XdrEndpointDeviceLiveResponseLibraryFile -FileName 'OldScript.ps1' -Confirm:$false
Deletes without prompting.
Get-XdrEndpointDeviceLiveResponseLibrary | Where-Object file_name -eq 'OldScript.ps1' | Remove-XdrEndpointDeviceLiveResponseLibraryFile
Deletes using pipeline input from the library listing.
Remove-XdrEndpointDeviceLiveResponseLibraryFile -FileName 'OldScript.ps1' -WhatIf
Shows what would be deleted without performing the deletion.
Output
Type: None
This cmdlet does not return output on successful deletion.