← SentinelOne integration
SentinelOneIntegration brief

How extensions get reported

SentinelOne® does not inventory browser extensions, so something has to go and look. That leaves you two decisions, and only the first one is required.

  1. 1

    Who deploys the collector?

    Required

    A script reads which extensions are installed on each endpoint and reports them back. Either you ship it like any other script, or we run it through RemoteOps - SentinelOne's script-execution add-on.

  2. 2

    Do you also want our extension installed?

    Optional

    Optional, and off unless you ask for it. It adds per-profile detail and stops a blocked extension the moment someone installs it. You deploy it; we never push software to your fleet.

Decision 1: who deploys the collector

You run itWe run it
Credentials we holdA Service User token on a least-privilege role (STAR Custom Rules only if you turn alerts on), plus a write-only key that can submit inventory for your org and nothing elseThe same token, on a role that also carries RemoteOps upload and run
Worst case if we are breachedSomeone posts false inventory to your dashboardSomeone executes a script on your fleet
RemoteOps add-onNot neededRequired, and billable

Decision 2: collector only, or our extension too

Collector onlyPlus our extension
What you getEvery extension on every profile, with a verdict on eachThe same, plus which profile has it, and a block that lands in about a minute rather than at your next collector run
What employees seeNothingAn extension marked installed by your administrator, which they cannot remove

Neither is needed to block an extension - blocking runs through browser policy either way. The extension only makes it faster.

What the collector does

Same script either way, and you get it as plain text, so read it before you run it. It installs nothing and leaves nothing running. It writes nothing either, unless you turn on enforcement - then it also writes the blocklist you set into local browser policy on that machine.

Everything else

  • In - We read your agent list hourly, so endpoints with an agent but no extension visibility show up as a gap.
  • Out - Extensions on your fleet we have flagged malicious or rated high or critical land in Threat Intelligence, tagged with our source so you can purge them in one filter.
  • Never - The role holds the permissions you pick - Endpoints > View, Threat Intelligence View and Manage, and STAR Custom Rules View and Manage if you want alerts - plus Accounts > View, which SentinelOne grants every role automatically. Not one endpoint action: we cannot isolate, reboot, kill or quarantine anything.

Setup is a least-privilege role, a Service User on it, and pasting the token into the dashboard. Disconnect there and we forget it, or delete the Service User and it dies immediately without our involvement.

Whichever credentials you give us are encrypted at rest, on a database with no public network endpoint.

Hosting and the rest of our posture are on our security page. Anything else, ask an engineer.

SentinelOne®, Singularity™ and the SentinelOne logo are trademarks of SentinelOne, Inc. Used for identification only; this integration is built by Am I Being Pwned and is not endorsed by or affiliated with SentinelOne.