<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: StoreDesktopExtension.exe - Again alerts are generated in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-again-alerts-are-generated/m-p/1252457#M9260</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/816619175"&gt;@S.Rembhotkar&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="147" data-start="0"&gt;The spike in alerts for &lt;STRONG data-end="53" data-start="24"&gt;StoreDesktopExtension.exe&lt;/STRONG&gt; is a known issue involving false positive detections by the Cortex XDR Local Analysis engine.&lt;/P&gt;
&lt;P data-end="147" data-start="0"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="173" data-start="149" data-section-id="1ohp9vo"&gt;Reason for the Spike:&lt;/H4&gt;
&lt;P data-end="358" data-start="175"&gt;&lt;STRONG data-end="208" data-start="175"&gt;Legitimate Microsoft Updates:&lt;/STRONG&gt;&lt;BR data-end="211" data-start="208" /&gt;StoreDesktopExtension.exe is a legitimate Microsoft Windows Store component. Microsoft frequently updates this binary, which changes its file hash.&lt;/P&gt;
&lt;P data-end="640" data-start="360"&gt;&lt;STRONG data-end="390" data-start="360"&gt;Local Analysis Heuristics:&lt;/STRONG&gt;&lt;BR data-end="393" data-start="390" /&gt;When a new version is released, the Local Analysis module (Component 55) may flag the binary as a "Suspicious executable" (CyveraStatus c0400055) based on its machine-learning model before a global WildFire verdict is synchronized to the endpoint.&lt;/P&gt;
&lt;P data-end="847" data-start="642"&gt;&lt;STRONG data-end="669" data-start="642"&gt;Communication Failures:&lt;/STRONG&gt;&lt;BR data-end="672" data-start="669" /&gt;If an endpoint cannot reach the WildFire cloud due to proxy timeouts, DNS issues, or SSL inspection (DPI), it defaults to the local analysis verdict, which may be "Malicious".&lt;/P&gt;
&lt;P data-end="1041" data-start="849"&gt;&lt;STRONG data-end="871" data-start="849"&gt;Stale Local Cache:&lt;/STRONG&gt;&lt;BR data-end="874" data-start="871" /&gt;Even after the verdict is updated to "Benign" in WildFire, endpoints may continue to alert if they are utilizing an outdated verdict stored in the agent's local cache.&lt;/P&gt;
&lt;P data-end="1041" data-start="849"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="1075" data-start="1048" data-section-id="1wkoezy"&gt;Recommended Resolutions:&lt;/H4&gt;
&lt;P data-end="1297" data-start="1077"&gt;&lt;STRONG data-end="1106" data-start="1077"&gt;1. Update Content Version&lt;/STRONG&gt;&lt;BR data-end="1109" data-start="1106" /&gt;A permanent fix for these Microsoft Store binaries was included in newer Content Updates. Ensure your endpoints are running Content Version 2130-30377 or later (preferably 2150 or higher).&lt;/P&gt;
&lt;P data-end="1297" data-start="1077"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1555" data-start="1299"&gt;&lt;STRONG data-end="1326" data-start="1299"&gt;2. Clear Agent Database&lt;/STRONG&gt;&lt;BR data-end="1329" data-start="1326" /&gt;To force the agent to refresh its local verdict cache and retrieve the updated "Benign" status from the cloud, perform a Clear Agent Database action from the XDR Console. Alternatively, restart the agent services using cytool:&lt;/P&gt;
&lt;P data-end="1555" data-start="1299"&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼ5 ͼj" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;cd "C:\Program Files\Palo Alto Networks\Traps"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;cytool runtime stop&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;cytool runtime start&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;&lt;STRONG style="font-family: inherit;" data-end="1681" data-start="1654"&gt;3. Path-Based Exclusion&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="1805" data-start="1654"&gt;You can add a wildcard path exclusion to your Malware Profile under the "Portable Executable and DLL Examination" module:&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼ5 ͼj" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;C:\Program Files\WindowsApps\Microsoft.WindowsStore_*\StoreDesktopExtension.exe&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;STRONG&gt;like&amp;nbsp;&lt;/STRONG&gt;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution"&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
    <pubDate>Fri, 17 Apr 2026 18:28:31 GMT</pubDate>
    <dc:creator>susekar</dc:creator>
    <dc:date>2026-04-17T18:28:31Z</dc:date>
    <item>
      <title>StoreDesktopExtension.exe - Again alerts are generated</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-again-alerts-are-generated/m-p/1252411#M9259</link>
      <description>&lt;P&gt;Hello Team ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Again we got a spike for similar&amp;nbsp;&lt;SPAN&gt;StoreDesktopExtension.exe alerts today , Any specific reason ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CGO : C:\Windows\System32\sihost.exe&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Initiator path : C:\Program Files\WindowsApps\Microsoft.WindowsStore_22603.1401.7.0_x64__8wekyb3d8bbwe\StoreDesktopExtension.exe&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2026 11:06:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-again-alerts-are-generated/m-p/1252411#M9259</guid>
      <dc:creator>S.Rembhotkar</dc:creator>
      <dc:date>2026-04-17T11:06:03Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe - Again alerts are generated</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-again-alerts-are-generated/m-p/1252457#M9260</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/816619175"&gt;@S.Rembhotkar&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="147" data-start="0"&gt;The spike in alerts for &lt;STRONG data-end="53" data-start="24"&gt;StoreDesktopExtension.exe&lt;/STRONG&gt; is a known issue involving false positive detections by the Cortex XDR Local Analysis engine.&lt;/P&gt;
&lt;P data-end="147" data-start="0"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="173" data-start="149" data-section-id="1ohp9vo"&gt;Reason for the Spike:&lt;/H4&gt;
&lt;P data-end="358" data-start="175"&gt;&lt;STRONG data-end="208" data-start="175"&gt;Legitimate Microsoft Updates:&lt;/STRONG&gt;&lt;BR data-end="211" data-start="208" /&gt;StoreDesktopExtension.exe is a legitimate Microsoft Windows Store component. Microsoft frequently updates this binary, which changes its file hash.&lt;/P&gt;
&lt;P data-end="640" data-start="360"&gt;&lt;STRONG data-end="390" data-start="360"&gt;Local Analysis Heuristics:&lt;/STRONG&gt;&lt;BR data-end="393" data-start="390" /&gt;When a new version is released, the Local Analysis module (Component 55) may flag the binary as a "Suspicious executable" (CyveraStatus c0400055) based on its machine-learning model before a global WildFire verdict is synchronized to the endpoint.&lt;/P&gt;
&lt;P data-end="847" data-start="642"&gt;&lt;STRONG data-end="669" data-start="642"&gt;Communication Failures:&lt;/STRONG&gt;&lt;BR data-end="672" data-start="669" /&gt;If an endpoint cannot reach the WildFire cloud due to proxy timeouts, DNS issues, or SSL inspection (DPI), it defaults to the local analysis verdict, which may be "Malicious".&lt;/P&gt;
&lt;P data-end="1041" data-start="849"&gt;&lt;STRONG data-end="871" data-start="849"&gt;Stale Local Cache:&lt;/STRONG&gt;&lt;BR data-end="874" data-start="871" /&gt;Even after the verdict is updated to "Benign" in WildFire, endpoints may continue to alert if they are utilizing an outdated verdict stored in the agent's local cache.&lt;/P&gt;
&lt;P data-end="1041" data-start="849"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="1075" data-start="1048" data-section-id="1wkoezy"&gt;Recommended Resolutions:&lt;/H4&gt;
&lt;P data-end="1297" data-start="1077"&gt;&lt;STRONG data-end="1106" data-start="1077"&gt;1. Update Content Version&lt;/STRONG&gt;&lt;BR data-end="1109" data-start="1106" /&gt;A permanent fix for these Microsoft Store binaries was included in newer Content Updates. Ensure your endpoints are running Content Version 2130-30377 or later (preferably 2150 or higher).&lt;/P&gt;
&lt;P data-end="1297" data-start="1077"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1555" data-start="1299"&gt;&lt;STRONG data-end="1326" data-start="1299"&gt;2. Clear Agent Database&lt;/STRONG&gt;&lt;BR data-end="1329" data-start="1326" /&gt;To force the agent to refresh its local verdict cache and retrieve the updated "Benign" status from the cloud, perform a Clear Agent Database action from the XDR Console. Alternatively, restart the agent services using cytool:&lt;/P&gt;
&lt;P data-end="1555" data-start="1299"&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼ5 ͼj" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;cd "C:\Program Files\Palo Alto Networks\Traps"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;cytool runtime stop&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;cytool runtime start&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;&lt;STRONG style="font-family: inherit;" data-end="1681" data-start="1654"&gt;3. Path-Based Exclusion&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="1805" data-start="1654"&gt;You can add a wildcard path exclusion to your Malware Profile under the "Portable Executable and DLL Examination" module:&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼ5 ͼj" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;C:\Program Files\WindowsApps\Microsoft.WindowsStore_*\StoreDesktopExtension.exe&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking&amp;nbsp;&lt;STRONG&gt;like&amp;nbsp;&lt;/STRONG&gt;and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution"&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2026 18:28:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-again-alerts-are-generated/m-p/1252457#M9260</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-04-17T18:28:31Z</dc:date>
    </item>
    <item>
      <title>Re: StoreDesktopExtension.exe - Again alerts are generated</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-again-alerts-are-generated/m-p/1252514#M9264</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;This is a known False Positive. StoreDesktopExtension.exe is a legitimate Microsoft Store component, and sihost.exe (Shell Infrastructure Host) as the CGO is completely normal Windows behavior.&lt;/P&gt;
&lt;P&gt;To stop the alerts, you can add a file exception in the Cortex XDR console:&lt;/P&gt;
&lt;P&gt;Endpoint Security &amp;gt; Exceptions &amp;gt; Add Exception&lt;BR /&gt;- Path: C:\Program Files\WindowsApps\Microsoft.WindowsStore_**\StoreDesktopExtension.exe&lt;BR /&gt;(using wildcard ** covers future Store version updates as well)&lt;/P&gt;
&lt;P&gt;Alternatively, you can add the SHA256 hash of the file directly to your Allow List:&lt;BR /&gt;Incident Response &amp;gt; Action Center &amp;gt; Allow List &amp;gt; New Action&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2026 08:20:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/storedesktopextension-exe-again-alerts-are-generated/m-p/1252514#M9264</guid>
      <dc:creator>N.Majidova</dc:creator>
      <dc:date>2026-04-20T08:20:11Z</dc:date>
    </item>
  </channel>
</rss>

