Get real visibility over the extensions installed across your fleet.
SentinelOne covers the endpoint. It does not cover browser extensions - trusted code inside a signed browser, reading every page your staff open, with no process to kill and no file to quarantine.
AIBP closes that gap across the same fleet your agents already manage: a read-only Service User for the endpoint list, a read-only collector for the extension census, and every malicious extension we find written straight back into your Threat Intelligence store.
You keep SentinelOne as the endpoint control plane. We become the browser layer feeding it.
Connecting deploys nothing - read-only, account-scoped, revocable in one click
The gap
Your endpoint layer is owned. Your browser layer might not be.
Extensions provide value and risk
What SentinelOne already stops
What a browser extension does instead
The analysis
A permission list is not a verdict.
“Can read all sites” describes almost every useful extension. So we do not score permissions - we take the exact bundle running on your fleet apart, then run it and watch what it actually does.
We analyse the exact version your fleet is running, not whatever the store ships today.
- Packed bundles normalised before anything is judged
- Declared permissions checked against the APIs actually called
- Page content and cookies traced through to network sinks
Static analysis cannot see what a loader fetches at runtime, so we install the extension in an instrumented browser and drive it.
- An agent drives it like a person: webmail, admin console, banking
- Every DOM read, cookie access and outbound request recorded
- Region, delay and domain varied to surface conditional payloads
Proof
Findings we published
MultiPassword
A password manager with over a million users leaking usernames, passwords and TOTP codes. CVSS 8.3. The manifest was clean.
Read the breakdownUrban VPN
Taking commands from any website through an unvalidated postMessage handler.
Read the breakdownStylish
Two million users, exfiltrating every URL visited and the contents of AI chats.
Read the breakdownOur founder is on the Centre for Cybersecurity Belgium's Wall of Fame for coordinated disclosure. Read more.
What changes for you
Four things you can do on Monday that you cannot do today.
Answer any extension question in seconds
“Is this on our fleet? Who has it? Since when?” - resolved from a search box instead of a three-day thread with IT and a half-trusted spreadsheet.
Hand the auditor an artefact, not a dashboard
One click freezes the fleet: every extension, its verdict, the policy in force. Timestamped, signed off by name, and never rewritten - the evidence you currently write “N/A” against.
Feed Singularity what it cannot see
Confirmed malicious, high and critical extensions land in your Threat Intelligence store hourly, each linked back to the full breakdown. Medium stays out: that is a policy review, not an indicator.
Catch the silent update, not just the install
Same name, same icon, new bundle. We diff every sync and re-analyse the change - including the extensions that fetch their real instructions from a server after install.
Setup
Two ways to integrate.
The same read-only collector either way, so the same analysis and the same findings. Most teams deploy it themselves through tooling they already run; if you would rather not, we drive it through RemoteOps.
Manual collector
DefaultA read-only PowerShell and bash collector with a write-only ingest key baked in. Plain text, short enough to read before you ship it, writes nothing to the endpoint. Deploy it like any other script: RemoteOps, Intune, Jamf, GPO or any RMM.
Automatic via RemoteOps
Hands-offIf you would rather not own the deployment, we upload the same read-only collector to your RemoteOps script library and run it fleet-wide once a day, collecting results as agents come online. Requires the Singularity RemoteOps add-on.
FAQ
Questions we get asked first.
Find out what is actually installed.
Connecting takes twenty minutes and deploys nothing. Inventory and indicators land on the next hourly sync.
SentinelOne, Singularity and the SentinelOne logo are trademarks of SentinelOne, Inc. Used for identification only; this integration is built by Am I Being Pwned.




