<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: StoreDesktopExtension.exe As greyware in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-greyware/m-p/1246005#M9018</link>
    <description>&lt;P&gt;Nos esta pasando lo mismo con&amp;nbsp;&lt;SPAN&gt;StoreDesktopExtension.exe actualmente, alguna respuesta desde Palo Alto?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;727d070460fa4764822b5286b1d9b8fbb5512b6e84ad645a99cb34dcede97647&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 20 Jan 2026 12:20:31 GMT</pubDate>
    <dc:creator>LeticiaGalisteo</dc:creator>
    <dc:date>2026-01-20T12:20:31Z</dc:date>
    <item>
      <title>StoreDesktopExtension.exe As greyware</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-greyware/m-p/1246004#M9017</link>
      <description>&lt;P&gt;It was repported on the 13th that StoreDesktopExtension.exe was flagged as malicious by wildfire it is now being flagged as grayware and is flooding us with alerts anyone else experiencing the same?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2026 12:12:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-greyware/m-p/1246004#M9017</guid>
      <dc:creator>OliverStussi</dc:creator>
      <dc:date>2026-01-20T12:12:56Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe As greyware</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-greyware/m-p/1246005#M9018</link>
      <description>&lt;P&gt;Nos esta pasando lo mismo con&amp;nbsp;&lt;SPAN&gt;StoreDesktopExtension.exe actualmente, alguna respuesta desde Palo Alto?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;727d070460fa4764822b5286b1d9b8fbb5512b6e84ad645a99cb34dcede97647&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2026 12:20:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-greyware/m-p/1246005#M9018</guid>
      <dc:creator>LeticiaGalisteo</dc:creator>
      <dc:date>2026-01-20T12:20:31Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe As greyware</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-greyware/m-p/1246007#M9019</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/260476"&gt;@OliverStussi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This file was initially flagged by the Local Analysis module or WildFire but has since been reclassified as Benign globally.&lt;/P&gt;
&lt;P&gt;If the alerts persist despite the global verdict being Benign, the endpoint may have a stale verdict in its local cache. You can force the agent to re-fetch the correct verdict by clearing its local database.&lt;/P&gt;
&lt;P&gt;1) Open an administrative command prompt on the affected endpoint.&lt;/P&gt;
&lt;P&gt;2) Stop the agent services (requires the agent uninstall password):&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;"C:\Program Files\Palo Alto Networks\Traps\cytool.exe" protect disable&lt;BR /&gt;&amp;nbsp; &amp;nbsp;"C:\Program Files\Palo Alto Networks\Traps\cytool.exe" runtime stop&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;3) Navigate to C:\ProgramData\Cyvera\LocalSystem\Persistence3\&amp;nbsp; and delete the following files:&lt;/P&gt;
&lt;P&gt;wf_verdicts.db&lt;BR /&gt;wf_verdicts.db.lru&lt;BR /&gt;wf_retransmissions.db&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;4) Restart the agent services:&lt;/P&gt;
&lt;P&gt;"C:\Program Files\Palo Alto Networks\Traps\cytool.exe" runtime start&lt;/P&gt;
&lt;P&gt;"C:\Program Files\Palo Alto Networks\Traps\cytool.exe" protect enable&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me know if your query is answered, Thank you!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2026 12:23:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-greyware/m-p/1246007#M9019</guid>
      <dc:creator>mshamamulla</dc:creator>
      <dc:date>2026-01-20T12:23:52Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe As greyware</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-greyware/m-p/1246010#M9020</link>
      <description>&lt;P&gt;on our end it says the verdict changed today from benign to grayware. has it been changed back to benign since this?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OliverStussi_0-1768911966251.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70402iB4DF67C32E58EBB1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="OliverStussi_0-1768911966251.png" alt="OliverStussi_0-1768911966251.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2026 12:26:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-greyware/m-p/1246010#M9020</guid>
      <dc:creator>OliverStussi</dc:creator>
      <dc:date>2026-01-20T12:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe As greyware</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-greyware/m-p/1246011#M9021</link>
      <description>&lt;P&gt;It is now being flagged as benign for us&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2026 12:45:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-greyware/m-p/1246011#M9021</guid>
      <dc:creator>OliverStussi</dc:creator>
      <dc:date>2026-01-20T12:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe As greyware</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-greyware/m-p/1246015#M9022</link>
      <description>&lt;P&gt;Gracias por tu respuesta,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Por el momento las alertas cesaron, y en nuestra consola tambien fue marcado como Benign.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2026 14:12:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-greyware/m-p/1246015#M9022</guid>
      <dc:creator>LeticiaGalisteo</dc:creator>
      <dc:date>2026-01-20T14:12:28Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe As greyware</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-greyware/m-p/1246111#M9024</link>
      <description>&lt;P&gt;because the windows store is installed on almost every windows device, we get many incidents as well. even after the verdict was changed back to benign, we still receive multiple alerts of machines which did not retrieve the latest verdict yet. the same thing happened last week with similar files. are there plans for a solution which prevents these windows store executables false positives from popping up in the first place?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2026 08:39:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-greyware/m-p/1246111#M9024</guid>
      <dc:creator>andreal</dc:creator>
      <dc:date>2026-01-21T08:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe As greyware</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-greyware/m-p/1246126#M9025</link>
      <description>&lt;P&gt;Add the specific file hash to the&amp;nbsp;Allow List&amp;nbsp;in the Cortex XDR console. This will permit the file to run regardless of the WildFire verdict&amp;nbsp;.&lt;BR /&gt;1. Navigate to&amp;nbsp;Incident Response &amp;gt; Action Center &amp;gt; Allow List.&lt;BR /&gt;2. Click&amp;nbsp;+ New Action&amp;nbsp;and enter the SHA256 hash for&amp;nbsp;StoreDesktopExtension.exe.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2026 10:41:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-greyware/m-p/1246126#M9025</guid>
      <dc:creator>mshamamulla</dc:creator>
      <dc:date>2026-01-21T10:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe As greyware</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-greyware/m-p/1246442#M9044</link>
      <description>&lt;P&gt;The hash seems to change often. We need a long-term solution for this. The alerts are becoming unwelcome noise.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 15:50:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-as-greyware/m-p/1246442#M9044</guid>
      <dc:creator>D.Moore415468</dc:creator>
      <dc:date>2026-01-23T15:50:41Z</dc:date>
    </item>
  </channel>
</rss>

