- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-27-2026 08:36 AM
Can someone explain the Local Analysis Malware and WildFire Malware alerts. The WildFire alerts seem straightforward for a file that it deems malware. On the other hand, the local analysis malware alerts trigger for a bunch of files but in the alert it has a wildfire report and verdict that says benign.
Moving into suppressing these alerts, the module in the alert is listed as Local File Analysis and Wildfire. When adding the file to an exception, neither of those are a module choice to whitelist from. Under the assumption it was scanning based on the alert, I have tried adding it to the endpoint scanning and the PE and DLL examination modules but the alerts still trigger. Any help or explanation would be appreciated!
01-28-2026 06:31 AM
Hello @clairamore ,
Greetings for the day.
Are you referring to the Local Analysis detections for the Microsoft binary StoreDesktopExtension.exe? If so, please find the responses below. If your question is more general, kindly let me know.
Indicators:
The main issue to investigate is why the endpoint is not reaching the WildFire cloud.
The following reasons have been observed so far due to the customer environment:
-One is temporary, and will work for this specific file as long as the hash doesn't change for any reason.
-The permanent fix is to ensure the XDR Agent can reach the WildFire cloud in order to obtain the latest verdicts.
Both require an agent check-in as a final step to refresh the local databases.
The temporary workaround for this specific hash is to add it to the Allow List:
-------------------------------------------------------
For a permanent fix, the root cause of the XDR Agent not reaching WildFire must be investigated and corrected.
cc-<xsiam-tenant>.traps.paloaltonetworks.com If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".
Happy New year!!
Thanks & Regards,
S. Subashkar Sekar
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

