<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Suspicious executable detected Microsoft Store Purchase App in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspicious-executable-detected-microsoft-store-purchase-app/m-p/1255315#M9367</link>
    <description>&lt;P&gt;We were also suffering from this. I remember seeing it was addressed in a content pack update. We're only seeing this on endpoints without the current content pack now.&lt;/P&gt;</description>
    <pubDate>Wed, 03 Jun 2026 11:01:56 GMT</pubDate>
    <dc:creator>Karl-Foley</dc:creator>
    <dc:date>2026-06-03T11:01:56Z</dc:date>
    <item>
      <title>Suspicious executable detected Microsoft Store Purchase App</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspicious-executable-detected-microsoft-store-purchase-app/m-p/1254964#M9353</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello everyone,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Has anyone seen this process appear in Cortex XDR?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;C:\Program Files\WindowsApps\Microsoft.StorePurchaseApp_22603.1401.4.0_x64__8wekyb3d8bbwe\StoreExperienceHost.exe&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It’s showing up on an endpoint, but Cortex XDR isn’t providing any additional details, alerts, or related events. Before I dismiss it, I want to confirm whether this is expected behavior or if anyone has seen suspicious activity tied to this executable.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any insight is appreciated.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2026 19:16:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspicious-executable-detected-microsoft-store-purchase-app/m-p/1254964#M9353</guid>
      <dc:creator>Juliortega</dc:creator>
      <dc:date>2026-05-28T19:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious executable detected Microsoft Store Purchase App</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspicious-executable-detected-microsoft-store-purchase-app/m-p/1255118#M9354</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, we are having the same issue, and we are following with the support they recommended to add an exception. not yet added.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there are multiple processes related to Microsoft but without any signature, even though the process in it's correct path.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2026 09:39:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspicious-executable-detected-microsoft-store-purchase-app/m-p/1255118#M9354</guid>
      <dc:creator>sherefa</dc:creator>
      <dc:date>2026-06-01T09:39:56Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious executable detected Microsoft Store Purchase App</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspicious-executable-detected-microsoft-store-purchase-app/m-p/1255125#M9355</link>
      <description>&lt;P&gt;We also have the same issue. We saw 3 different hashes for "StoreExperienceHost.exe" over the past 6 weeks. It's always a Local Analysis Malware alert. The WildFire verdict is then benign, so no action is really needed, but still annoying to get these alerts.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2026 11:48:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspicious-executable-detected-microsoft-store-purchase-app/m-p/1255125#M9355</guid>
      <dc:creator>andreal</dc:creator>
      <dc:date>2026-06-01T11:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious executable detected Microsoft Store Purchase App</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspicious-executable-detected-microsoft-store-purchase-app/m-p/1255245#M9363</link>
      <description>&lt;P&gt;We are seeing the same exact thing here in our shop. Palo did eventually give us a SUEX file to quiet the noise. I'd prefer that they fix whatever is determining that file to be suspicious. This is not the first time we've had something similar happen with MS Store files.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2026 21:16:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspicious-executable-detected-microsoft-store-purchase-app/m-p/1255245#M9363</guid>
      <dc:creator>Joe_Carissimo</dc:creator>
      <dc:date>2026-06-02T21:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious executable detected Microsoft Store Purchase App</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspicious-executable-detected-microsoft-store-purchase-app/m-p/1255315#M9367</link>
      <description>&lt;P&gt;We were also suffering from this. I remember seeing it was addressed in a content pack update. We're only seeing this on endpoints without the current content pack now.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2026 11:01:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/suspicious-executable-detected-microsoft-store-purchase-app/m-p/1255315#M9367</guid>
      <dc:creator>Karl-Foley</dc:creator>
      <dc:date>2026-06-03T11:01:56Z</dc:date>
    </item>
  </channel>
</rss>

