New Update Download Sentinel improved functionality new versions

Web Extensions
98 Replies 12,899 Views
Thread details
Version 2.6.1 is avialable in the Chrome Web Store

What is changed?

Functionally nothing! Only implemented the checks and balances of uBlock Stripped (the automated test and verification tools).

@Shadowra publishes a test in the coming weeks, that is why I updated the tools (for testing) and pushed the programming standards application of UBS a bit further. This makes it easier to implement the feedback and tips of Shadowra based on his broad tests (@Sampei.Nihira did a lot of testing, but his feedback is already implemented in the version Shadowra will be testing).
 
@Sampei.Nihira and @Morro

Changes in version 2.6.2

Implemented the Levenshtein distance model for 100 wel known brands (regex had 30).

It's a classic algorithm from 1965 (Vladimir Levenshtein) that measures how many single-character edits — insertions, deletions, or substitutions — it takes to turn one string into another. "gooogle" → "google" is 1 edit (delete the extra o), so the Levenshtein distance is 1. It is used to detect sketchy URL's in a much advanced manner than I did with regex.


There is really no reason to NOT use Download Sentinel,
- it is inactive eating no CPU cycles when it is not triggered by Chrome (only jumps into action at on-download and file-write)
- it is nearly permission less (look at it in extension menu it needs no access to your webpages)
- it has heuristics which are engineered by a guy working for the Dutch National Cyber Security Agency

The reason I use it:
- it has privacy on top of mind
- it is open source
- adds a strong download protection layer (for me relevant on Linux with no AV)
 
Last edited:
This online ZIP file, which has been up for just over an hour, shows a 100% (Overall Risk Score) alert:

hxxps://urlhaus.abuse.ch/url/3914635/
 

Attachments

  • 1.png
    1.png
    100.8 KB · Views: 82
It would help “improve the lives” of those who use Windows + Firefox + MD.
Personally, I don't think I really need it, but there are more than 10 users out there (potential users,that word is all the rage these days :rolleyes:;)) who would actually benefit from this extension.;)
 
Version 3.0 pushed to Chrome webstore

Changes improved heuristics (just tested on the first https download on URL Haus - which was 2 hours old

2026-10-09 10:50:20hxxps://1rvrental.com/g.php
1791544127864.png


In detail
  1. Catches filenames reversed so “evil.exe” displays as “safe.jpg.”
  2. Spots filenames padded with spaces/dots to hide a dangerous extension.
  3. Flags lookalike domains like “arnazon.com” impersonating “amazon.com.”
  4. Treats link-shortened downloads as a mild extra warning sign.
  5. Checks if a download’s referring page looks unrelated to its actual source.
  6. Fixed a bug that wrongly penalized install scripts served as plain text.
  7. Fixed a bug that wrongly flagged legitimate “.js” files as mismatched.
  8. Weak signals now add up together instead of only the single worst one counting.
  9. Recognizes more disguised-as-document file types (e.g. OneNote, shortcut, search files).
  10. Flags suspicious-looking “staging” words and hidden encoded commands in links/filenames.

I really don't understand why so few people use this extension. I had expected a lot of Linux (and Ungoogled Chromium) users adding this
a) it applies best privacy it only sends download URL to VT, so not the download itself and only looks at risky extensions/file types.
b) applies advanced heuristics to compliment VT-score (and offers upload to hybrid sandbox when unknown at VT)
c) Shadowra tested Download Sentinel App Review - Download Sentinel Reviews
d) Requires minimal permissions (does not need access to pages your are viewing)
e) Eats no CPU (it is on standby and jumps into action when your Chromium browser triggers it_
 
Last edited:
Version 3.0 pushed to Chrome webstore

Changes improved heuristics (just tested on the first https download on URL Haus - which was 2 hours old

2026-10-09 10:50:20hxxps://1rvrental.com/g.php
View attachment 300573

In detail
  1. Catches filenames reversed so “evil.exe” displays as “safe.jpg.”
  2. Spots filenames padded with spaces/dots to hide a dangerous extension.
  3. Flags lookalike domains like “arnazon.com” impersonating “amazon.com.”
  4. Treats link-shortened downloads as a mild extra warning sign.
  5. Checks if a download’s referring page looks unrelated to its actual source.
  6. Fixed a bug that wrongly penalized install scripts served as plain text.
  7. Fixed a bug that wrongly flagged legitimate “.js” files as mismatched.
  8. Weak signals now add up together instead of only the single worst one counting.
  9. Recognizes more disguised-as-document file types (e.g. OneNote, shortcut, search files).
  10. Flags suspicious-looking “staging” words and hidden encoded commands in links/filenames.

I really don't understand why so few people use this extension. I had expected a lot of Linux users adding this
a) it applies best privacy it only sends download URL to VT, so not the download itself and only looks at risky extensions/file types.
b) applies advanced heuristics to compliment VT-score (and offers upload to hybrid sandbox when unknown at VT)
c) Shadowra tested Download Sentinel App Review - Download Sentinel Reviews
d) Requires minimal permissions (does not need access to pages your are viewing)
e) Eats no CPU (it is on standby and jumps into action when your Chromium browser triggers it_

WOW.

You're misunderstood.........;):D

But as far as I'm concerned, if I could, I'd nominate you for the Nobel Prize, simply because you created Download Sentinel.(y)
 
WOW.

You're misunderstood.........;):D

But as far as I'm concerned, if I could, I'd nominate you for the Nobel Prize, simply because you created Download Sentinel.(y)
I think, besides Morro and you no one is using it on this security forum :ROFLMAO:

What strikes me is that Sweden and the US are well represented in the user base of my three extensions

1791550742570.png
 
It is so weird that those other countries out use the users from the Netherlands. :unsure:
Yes and I had expected my former neigbour to promote it to his collegues of the NCSD (the Dutch National Cyber Security Service) to use it because he is the intellectual inspirator of the heuristics. That makes it awkward (I did not tell him about the low user adoption in the NL). I had expected more Dutch users also.

Whenever he suggests new checks, I feed them to Co-pilot (work), ChatGPT (free) and Claude (paid private) and AI always agree with his suggestions.

this means that Download Sentinel not only automates checks at VT, but also performs checks a security expert would do manually without delay or getting in the way (download is always allowed, warning is showed when file is dropped). For people using "hard" download protection extensions: your extension may block downloads but probably misses the advanced evasion techniques, so better move to Download Sentinel. (shameless self promotion :-) )
 
You should add the 1p-download protection feature which depends on the TLD which can be enabled on request if you're concerned about permissions.

In my opinion, if you good promote this protection,which, as far as I know, is unmatched by any other extension I'm aware of (unless we consider the Firefox-specific “Power-Tools-for-Adblockers”),you should be able to increase the number of users who use DS.

I've never left a review on CWS.

But if you add the downloads block based on a list of TLDs, I'll give it a try,even though, as I've often written, I've never been a very good employee,using my wife's account.;)
 
@LinuxFan58
Some suggestions, sorry this automatically translate with crow translate on debian, my english is ok/good but not stronger than lot's of members, this is why i am not posting regulary, so hope you're understand this :
Separate risk level from confidence level :
Could the warning distinguish between the estimated risk and the reliability of the available evidence? For example, an unknown download with insufficient reputation data should be treated differently from a download supported by several independent malicious indicators.

Explain the most influential signals :
An optional “Why am I seeing this warning?” section could identify the two or three most important factors behind the assessment. This would make the extension more transparent without cluttering the default interface.

Detect conflicting signals :
It might be useful to identify cases where a reassuring signal, such as a reputable hosting domain, conflicts with suspicious download characteristics or an unusual redirect chain. Care would be needed to avoid double-counting correlated signals.

Make the freshness of reputation data more visible :
Distinguishing between a well-established reputation, a recent observation and an unknown result could help users interpret the warning more accurately.

Preserve privacy when collecting feedback :
An optional diagnostic report, with sensitive URLs and other potentially identifying information removed by default, could help investigate false positives and improve regression testing.
Prioritize the distinction between risk and confidence, followed by clearer explanations of the warning signals. Both seem compatible with your existing principles of minimal permissions, low overhead and privacy by design.

PS : V3.0.0 ON CWS
 
Last edited:
@LinuxFan58
Some suggestions, sorry this automatically translate with crow translate on debian, my english is ok/good but not stronger than lot's of members, this is why i am not posting regulary, so hope you're understand this :
1. Separate risk level from confidence level :
Could the warning distinguish between the estimated risk and the reliability of the available evidence? For example, an unknown download with insufficient reputation data should be treated differently from a download supported by several independent malicious indicators.

2. Explain the most influential signals :
An optional “Why am I seeing this warning?” section could identify the two or three most important factors behind the assessment. This would make the extension more transparent without cluttering the default interface.

3. Detect conflicting signals :
It might be useful to identify cases where a reassuring signal, such as a reputable hosting domain, conflicts with suspicious download characteristics or an unusual redirect chain. Care would be needed to avoid double-counting correlated signals.

4. Make the freshness of reputation data more visible :
Distinguishing between a well-established reputation, a recent observation and an unknown result could help users interpret the warning more accurately.

5. Preserve privacy when collecting feedback :
An optional diagnostic report, with sensitive URLs and other potentially identifying information removed by default, could help investigate false positives and improve regression testing.
Prioritize the distinction between risk and confidence, followed by clearer explanations of the warning signals. Both seem compatible with your existing principles of minimal permissions, low overhead and privacy by design.

PS : V3.0.0 ON CWS
Remark 1
Confidence level: that is already included in the risk score, higher confidence gets higher risk for the same observation
Reliability level: the FP reduction slider determines what engines are used. I will add a tooltip explaining the levels.
At high only very reputable AV-companies are used, on Medium only reputable, on Low only well-known and on None all are used.
1791613664524.png


Remark 4
The freshness of the VT- results are always shown (¨First submitted to VT)
1791613844294.png

The age of the website from which is only shown when it is considered a risk factor in the heuristics
(I could always show the age of the website from which the download comes)

The formula behind it has two dimension: recent observations result in higher riskscores and older observation result in higher confidence level.

Remark 2
Each observation has recency, authority and severeness as inflencing factor. As shown by the explanation above, The heuristics only shows the relvant signals.
So it is very hard to explain more (how the formula behind works), because it is a rules based scoring system where every rule has it own observation (some have 2, most have 3 and some have 4 or more data points for an observation and about a third of the rules use multiple observations). I will try to make the lines more self explaining in the heuristics and add the age of the website hosting the download link, even when it is not a risk signal (sames as with VT-info)
1791614591725.png


In the VT-score I will add an explanation beneath the result table (e.g. "The number of suspicious and/or malicious detections triggered a warning")

Remark 5
Download Sentinel does not keep records. Submission to VT only invoke the download URL, not the download itself.
When you obtained a free API key from VT you also accepted their conditions (they distribute received URL's to the member AV-companies).


Addendum: list of AV-used at what different FP levels. You will see some duplicates because some AV's use a different name for URL detection and File detection.
1791615817066.png


Note this is an old list, Panda has changed owners and I think also AV-engine. in AV-Test Panda scored OK in FP's in more recent tests of AV-C it scored above average. So Panda is on the watch list. :-) Also AV-vendors use different techniques at VT than in their flagship products, so Panda at VT could still be a reliable source.
 
Last edited:

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top