<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: StoreDesktopExtension.exe - As Malicious in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1245454#M8994</link>
    <description>&lt;P&gt;We are having the same issue this morning within the last hour.&amp;nbsp; Thank you for the solution provided.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Adam&lt;/P&gt;</description>
    <pubDate>Tue, 13 Jan 2026 13:45:10 GMT</pubDate>
    <dc:creator>A.Govoni</dc:creator>
    <dc:date>2026-01-13T13:45:10Z</dc:date>
    <item>
      <title>StoreDesktopExtension.exe - As Malicious</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1245450#M8992</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;recently i receive a lot alerts, related with&amp;nbsp;&lt;CODE class="o8j0Mc" dir="ltr" data-processed="true"&gt;StoreDesktopExtension.exe&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;, this is usually a legitimate Microsoft Store component.&lt;BR /&gt;&lt;BR /&gt;Anyone with same issue?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 12:01:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1245450#M8992</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2026-01-13T12:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe - As Malicious</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1245453#M8993</link>
      <description>&lt;P&gt;Support information:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Probable Root Cause :&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I would like to inform you that I checked the HASH in our Wildfire portal, and would like to inform you that, Initially the file had a local verdict of malware, due to which a local analysis alert got triggered.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Currently, the file is classified as benign, and therefore its a legitimate application, and we can consider the alerts to be false positives.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;As the verdict is globally flagged as a benign file, once the verdict is updated on your endpoints, the alerts will be stopped.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If you are still receiving the alerts, please restart the agent services by following the command:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Open the command prompt with administrative privileges&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Navigate to C:\Program Files\Palo Alto Networks\Traps&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Run the below command to stop the agent services&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;#cytool runtime stop&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Run the below command to start the agent services&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;#cytool runtime start&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 13:08:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1245453#M8993</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2026-01-13T13:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe - As Malicious</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1245454#M8994</link>
      <description>&lt;P&gt;We are having the same issue this morning within the last hour.&amp;nbsp; Thank you for the solution provided.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Adam&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 13:45:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1245454#M8994</guid>
      <dc:creator>A.Govoni</dc:creator>
      <dc:date>2026-01-13T13:45:10Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe - As Malicious</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1245455#M8995</link>
      <description>&lt;P&gt;I've had 10 hosts with this alert since yesterday. Most came overnight. It's also flagging&amp;nbsp;&lt;SPAN&gt;sihost.exe on 1 host but associating it with the same alert.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;StoreDesktopExtension.exe&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;adee0ec3096b4778f6a5951647371f3ff67b8fa0d96c37fb795bcfcfe0e1154e&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;sihost.exe&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1e115ef87c00e685f8e7b1b184eb9fa3470a0ec75b678a70d3d2d3cbfde3dcb7&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 13:47:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1245455#M8995</guid>
      <dc:creator>D.Moore415468</dc:creator>
      <dc:date>2026-01-13T13:47:19Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe - As Malicious</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1245459#M8996</link>
      <description>&lt;P&gt;same situation on my side...support say is a False Positive.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 14:55:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1245459#M8996</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2026-01-13T14:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe - As Malicious</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1245463#M8997</link>
      <description>&lt;P&gt;i am having this problem since yesterday night and even though the process are showing benign the alerts are not stopping. do we need manually add the HASH to allow list to stop the alerts ?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 19:38:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1245463#M8997</guid>
      <dc:creator>karthik21</dc:creator>
      <dc:date>2026-01-13T19:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe - As Malicious</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1245531#M8999</link>
      <description>&lt;P&gt;We have more than 100 host getting the same alert, running this command on all host will be difficult, can we exclude this alert?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;SPAN data-teams="true"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jan 2026 08:58:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1245531#M8999</guid>
      <dc:creator>MYadav4</dc:creator>
      <dc:date>2026-01-14T08:58:41Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe - As Malicious</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1245545#M9002</link>
      <description>&lt;P&gt;When devices start updating the WF and tenant information again, the alerts will be closed automatically.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jan 2026 11:54:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1245545#M9002</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2026-01-14T11:54:30Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe - As Malicious</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1245546#M9003</link>
      <description>&lt;P&gt;on my case, i close all issues as false positive, and write command (information give by support).&amp;nbsp;&lt;BR /&gt;but you can add hash to allowlist and alerts close....or force the healthcheck devices, and devices connect again to the tenant and update information and start close the issues...At least that is what support told us.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jan 2026 11:57:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1245546#M9003</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2026-01-14T11:57:21Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe - As Malicious</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1245762#M9015</link>
      <description>&lt;P&gt;same in our company&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jan 2026 07:19:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1245762#M9015</guid>
      <dc:creator>PatrykGorzk</dc:creator>
      <dc:date>2026-01-16T07:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe - As Malicious</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1246026#M9023</link>
      <description>&lt;P&gt;We are experiencing the same issue. It began two days ago over the weekend. We have 150 desktops, and only 25 of them are showing this incident.&lt;/P&gt;
&lt;P&gt;C:\Program Files\WindowsApps\Microsoft.WindowsStore.....\StoreDesktopExtension.exe. what extension is it ?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2026 19:25:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1246026#M9023</guid>
      <dc:creator>Juliortega</dc:creator>
      <dc:date>2026-01-20T19:25:40Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe - As Malicious</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1246299#M9037</link>
      <description>&lt;P&gt;hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/136012"&gt;@Juliortega&lt;/a&gt;&amp;nbsp;, &lt;SPAN&gt;StoreDesktopExtension.exe is&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;an executable file associated with the Microsoft Store&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;I've open case with support and they say:&lt;BR /&gt;"&lt;SPAN&gt;I would like to inform you that our engineering team has confirmed that this is a legitimate file from Microsoft, and it is safe to add the "StoreDesktopExtension.exe" file to the allow list."&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jan 2026 18:16:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1246299#M9037</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2026-01-22T18:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe - As Malicious</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1246459#M9047</link>
      <description>&lt;P&gt;nosotros tenemos el mismo problema con alrededor de 150 dispositivos. habia permitido los siguientes hash:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;winstore.app.exe : adee0ec3096b4778f6a5951647371f3ff67b8fa0d96c37fb795bcfcfe0e1154e&lt;/P&gt;
&lt;P&gt;StoreDesktopExtension.exe:&amp;nbsp; 727d070460fa4764822b5286b1d9b8fbb5512b6e84ad645a99cb34dcede97647&lt;/P&gt;
&lt;P&gt;Cuando puse los hash anteriores en whitelist se soluciono pero ahora nuevamente volvieron aparecer alertas:&lt;/P&gt;
&lt;P&gt;StoreDesktopExtension.exe::::( 1/67 reportado en virustota como malicioso) total6b39c3583b0496f0be88a2c0ab5773f7f2bfef4f82e53f7f3126ee9ca2bf33ca&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Podrian apoyarme con un analisis? saludos&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 18:26:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1246459#M9047</guid>
      <dc:creator>I.AguilarGomez</dc:creator>
      <dc:date>2026-01-23T18:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe - As Malicious</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1246469#M9048</link>
      <description>&lt;P&gt;Hola, I. Aguilar Gómez:&lt;BR /&gt;Nosotros recibimos los incidentes únicamente por un día (20/01/26).&lt;BR /&gt;No realizamos ninguna acción y, actualmente, ya no vemos este tipo de alertas.&lt;BR /&gt;Si ustedes continúan recibiendo alertas, les recomiendo abrir un caso con Palo Alto.&lt;/P&gt;
&lt;P&gt;Por otra parte, no hemos recibido llamadas ni alertas de nuestros usuarios acerca de algún aplicativo que no esté funcionando para ellos.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 19:41:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1246469#M9048</guid>
      <dc:creator>Juliortega</dc:creator>
      <dc:date>2026-01-23T19:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe - As Malicious</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1246472#M9049</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/136012"&gt;@Juliortega&lt;/a&gt;&amp;nbsp; and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/692901067"&gt;@I.AguilarGomez&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this can be appear, because some devices have issue to update the local WFdb .&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;If you are still receiving the alerts, please restart the agent services by following the command:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Open the command prompt with administrative privileges&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Navigate to C:\Program Files\Palo Alto Networks\Traps&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Run the below command to stop the agent services&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;#cytool runtime stop&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Run the below command to start the agent services&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;#cytool runtime start&lt;BR /&gt;&lt;BR /&gt;with this devices will try connect again to the tenant and get the last informations.&lt;BR /&gt;sometimes, we need clear agent db:&lt;BR /&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-3.x-Documentation/Clear-agent-database" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-3.x-Documentation/Clear-agent-database&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 19:43:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1246472#M9049</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2026-01-23T19:43:50Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe - As Malicious</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1246473#M9050</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;A id="link_86" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307134" target="_self" aria-label="View Profile of tlmarques"&gt;&lt;SPAN class=""&gt;tlmarques&lt;/SPAN&gt;&lt;/A&gt;,&lt;/P&gt;
&lt;P&gt;Thank you for the response.&lt;BR /&gt;This solution seems better suited for organizations with only a few endpoints and no users in remote locations. However, when you have more than 100 endpoints—some of them in remote areas—this approach isn’t feasible, and we end up having to open the CDM in Admin mode.&lt;BR /&gt;I assume we could use the live terminal to handle this instead.&lt;BR /&gt;For now, we’ve simply ignored the alert, and we haven’t seen any new ones since January 20.&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 20:09:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1246473#M9050</guid>
      <dc:creator>Juliortega</dc:creator>
      <dc:date>2026-01-23T20:09:14Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe - As Malicious</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1246579#M9054</link>
      <description>&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/136012"&gt;@Juliortega&lt;/a&gt;&amp;nbsp;,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In our company, we have approximately 6,000 machines. What I did was restart the agent via the tenant, and it worked.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For restart agent via tenant you can use this: &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-3.x-Documentation/Restart-agent" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-3.x-Documentation/Restart-agent&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jan 2026 10:01:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1246579#M9054</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2026-01-26T10:01:27Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe - As Malicious</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1246837#M9059</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I've been bothered with this problem too and I tried your method.&lt;BR /&gt;However my "cytool runtime stop" command takes too long (minutes/hours).&lt;BR /&gt;We have "anti-tampering" on our Agent settings so before running this command I run the command to disable protection: "cytool protect disable"&lt;BR /&gt;It seems like something is blocking and so our agent services cannot stop for some reasons.&lt;BR /&gt;&lt;BR /&gt;If someone got the answer it will be great.&lt;BR /&gt;We have a ton of users and machines that suffers this False polsitive alert and I need to stop it.&lt;BR /&gt;&lt;BR /&gt;Thanks for your help&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jan 2026 09:52:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1246837#M9059</guid>
      <dc:creator>L.Filloux</dc:creator>
      <dc:date>2026-01-28T09:52:51Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe - As Malicious</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1246899#M9064</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;have you attempted to restart the agent—or all agents—within your tenant?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-3.x-Documentation/Restart-agent" target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-3.x-Documentation/Restart-agent&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jan 2026 19:49:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1246899#M9064</guid>
      <dc:creator>Juliortega</dc:creator>
      <dc:date>2026-01-28T19:49:35Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe - As Malicious</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1246992#M9069</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;Thanks for your answer, the restart worked.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jan 2026 08:51:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-malicious/m-p/1246992#M9069</guid>
      <dc:creator>L.Filloux</dc:creator>
      <dc:date>2026-01-29T08:51:37Z</dc:date>
    </item>
  </channel>
</rss>

