Is SentinelOne safe?
SentinelOne forwards every browser navigation URL and HTTP method to the local SentinelOne EDR agent in real time.
The extension registers a webRequest listener on all URLs and, for each top-level or iframe navigation, sends the URL, HTTP method, and browser type over a native messaging port to the SentinelOne EDR host process (com.sentinelone.browser.extension.host). This is the designed behavior of an enterprise endpoint-detection product: the local EDR agent uses the stream to monitor browsing activity for threat detection. No data is transmitted to remote servers by the extension itself.
Who publishes itSentinelOne, Inc - no other listings under this identity
SentinelOne, Inc - no other listings under this identity
What this publisher told the store about itself, and the other listings that told it the same thing.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
What it can do
Permissions this extension asks for, as declared in version 0.2.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
*://*/*
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
Watch every request your browser makes
webRequest
Schedule its own background tasks
alarms
Where it sends data
Destinations our analysis observed SentinelOne contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- com.sentinelone.browser.extension.host (local native host)
SentinelOne sends data to com.sentinelone.browser.extension.host (local native host). Named as a recipient in this extension's own analysis.