
Cross-platform interactive shell for Microsoft Defender for Endpoint Live Response
Cross-platform interactive shell for Microsoft Defender for Endpoint Live Response.
| Feature | Detail |
|---|---|
| Platform | PowerShell Core 7.0+ (Windows, Linux, macOS) |
| API modes | Internal (portal, near-realtime) and Official (public, stateless) |
| Execution | Arbitrary commands + 25 native LR commands |
| Auth | 7 authentication methods, unified menu, auto-refresh |
| License | MIT |
LaraC2 Shell connects to MDE Live Response through two independent API paths -- the internal portal API (persistent sessions, ~2-5s latency) and the official public API (per-command, ~20-60s latency). It auto-uploads executor stubs, handles rate limiting transparently, and provides a full REPL with machine management, library management, and a built-in help system.
| Doc | Purpose |
|---|---|
| User Guide | Step-by-step setup, auth, and operation |
| Command Reference | All commands, routing, batching, tab completion |
| Error Reference | HTTP codes, shell errors, auth errors, fixes |
| Performance | Internal vs Official latency, throughput, limits |
| Architecture | Internals, auth chains, endpoints, file layout |
| Contributing | How to contribute, test, submit PRs |
| Security Policy | How to report a vulnerability privately |
| References | Prior art, related research, credits |
| Disclaimer | Authorization, credits |
connect command re-authenticates when session expiresmulti command with name pattern filtering and top-N limitingMachine.LiveResponse + Library.Manage permissions (official mode)git clone https://github.com/akefallonitis/larac2shell.git
cd larac2shell
pwsh -File shell/Invoke-MDEShell.ps1
That's it. The shell presents a unified 7-method auth menu on first launch — pick one, authenticate, select a machine, and you're in a REPL. No config file, no flags, nothing to set up.
Select API mode:
Internal API (security.microsoft.com — near real-time, ~2-5s/cmd)
1 Credentials + MFA username + password, TOTP/push/SMS [auto-refresh]
2 Software passkey FIDO2/WebAuthn JSON key file [auto-refresh]
3 ESTS cookie ESTSAUTHPERSISTENT from browser (~24hr)
4 Temporary Access Pass one-time admin-issued code
5 Direct sccauth + XSRF cookies from browser DevTools (~1hr)
Official API (api.securitycenter.microsoft.com — CI/CD ready, ~20-60s/cmd)
6 Device code browser login (interactive)
7 Client credentials app registration with client secret
Auth method (1-7):
Choices 1-5 set internal mode, 6-7 set official. You can switch modes later without restarting — see Switching modes inline below.
[INT myhost C:\]> mode
Current mode: Internal API
Switch with: 'mode internal' or 'mode official'.
[INT myhost C:\]> mode official
[Mode] Switching from Internal API to official...
(auth menu for official mode opens)
[Mode] Now in official mode.
Run 'machines' to list targets or 'connect <name|id>' to select one.
mode <target> disconnects any current LR session, clears the old auth state, and re-runs the auth flow for the target mode. When it returns you're authenticated in the new mode with no machine selected — run machines to list, or connect <name|id> to jump straight to a target. No restart required.
For scripting or when you want to skip the unified menu:
# Pre-select the mode (narrows the auth menu to 1-5 or 6-7)
pwsh -File shell/Invoke-MDEShell.ps1 -Mode internal
pwsh -File shell/Invoke-MDEShell.ps1 -Mode official
# Pre-select a machine (skips the picker)
pwsh -File shell/Invoke-MDEShell.ps1 -Machine myhost
# Software passkey path (internal mode)
pwsh -File shell/Invoke-MDEShell.ps1 -PasskeyPath ./keys/passkey.json
# Non-interactive single command (exits with remote command's exit code)
pwsh -File shell/Invoke-MDEShell.ps1 -Machine myhost -Command 'whoami'
Only used for one scenario: official mode with a client secret, non-interactively. Every other auth method prompts you interactively and stores nothing on disk. If you don't need unattended client-credentials auth, you can skip this section entirely.
Copy-Item shell/config/shell-config.example.json shell/config/shell-config.json
# Edit the file: set official.tenantId, official.clientId, official.clientSecret
pwsh -File shell/Invoke-MDEShell.ps1 -Config shell/config/shell-config.json
Config schema (all fields optional except official.tenantId + official.clientId when using client credentials):