How extensions get reported
SentinelOne® does not inventory browser extensions, so something has to go and look. That leaves you two decisions, and only the first one is required.
- 1
Who deploys the collector?
RequiredA script reads which extensions are installed on each endpoint and reports them back. Either you ship it like any other script, or we run it through RemoteOps - SentinelOne's script-execution add-on.
- 2
Do you also want our extension installed?
OptionalOptional, and off unless you ask for it. It adds per-profile detail and stops a blocked extension the moment someone installs it. You deploy it; we never push software to your fleet.
Decision 1: who deploys the collector
| You run it | We run it | |
|---|---|---|
| Credentials we hold | A Service User token on a least-privilege role (STAR Custom Rules only if you turn alerts on), plus a write-only key that can submit inventory for your org and nothing else | The same token, on a role that also carries RemoteOps upload and run |
| Worst case if we are breached | Someone posts false inventory to your dashboard | Someone executes a script on your fleet |
| RemoteOps add-on | Not needed | Required, and billable |
Decision 2: collector only, or our extension too
| Collector only | Plus our extension | |
|---|---|---|
| What you get | Every extension on every profile, with a verdict on each | The same, plus which profile has it, and a block that lands in about a minute rather than at your next collector run |
| What employees see | Nothing | An extension marked installed by your administrator, which they cannot remove |
Neither is needed to block an extension - blocking runs through browser policy either way. The extension only makes it faster.
What the collector does
Same script either way, and you get it as plain text, so read it before you run it. It installs nothing and leaves nothing running. It writes nothing either, unless you turn on enforcement - then it also writes the blocklist you set into local browser policy on that machine.
Everything else
- In - We read your agent list hourly, so endpoints with an agent but no extension visibility show up as a gap.
- Out - Extensions on your fleet we have flagged malicious or rated high or critical land in Threat Intelligence, tagged with our source so you can purge them in one filter.
- Never - The role holds the permissions you pick - Endpoints > View, Threat Intelligence View and Manage, and STAR Custom Rules View and Manage if you want alerts - plus Accounts > View, which SentinelOne grants every role automatically. Not one endpoint action: we cannot isolate, reboot, kill or quarantine anything.
Setup is a least-privilege role, a Service User on it, and pasting the token into the dashboard. Disconnect there and we forget it, or delete the Service User and it dies immediately without our involvement.
Whichever credentials you give us are encrypted at rest, on a database with no public network endpoint.
Hosting and the rest of our posture are on our security page. Anything else, ask an engineer.
SentinelOne®, Singularity™ and the SentinelOne logo are trademarks of SentinelOne, Inc. Used for identification only; this integration is built by Am I Being Pwned and is not endorsed by or affiliated with SentinelOne.