Rumble 1.4.0 Concurrent Scans & Much More!

|
Updated

Version 1.4.0 of Rumble Network Discovery is now available with a host of changes. This release rolls up our post-1.3.0 work, including major updates to the command-line runZero Scanner and support for asset syncing in Splunk.

The Rumble user interface and API endpoints now support grouped queries using parenthesis in search terms. Grouped queries allow for complex filtering logic and can helpful when searching for specific types of misconfigurations.

Rumble Search Groups

These queries can be applied to the export functionality as well as the search interfaces for assets, services, screenshots, wireless networks, sites, and organizations.

The Rumble asset correlation engine now ignores "noisy" changes by default, including small changes to identified hostnames, domain names and reverse DNS entries. These improvements should reduce the number of alerts triggered after scans where reverse DNS becomes unavailable or is generally unreliable.

Network devices that intercept requests and forge network responses containing fake MAC addresses are now handled better. Prior to 1.4.0, Rumble could detect and avoid ARP proxies, and this release extends that support to devices that intercept and forge responses to protocols like NetBIOS and SNMP. This change prevents unrelated hosts from being correlated into the same asset.

For folks with busy scan schedules, this release has two major changes.

  • Scheduled scans that aren't able to find an available agent after four hours are now automatically canceled. Recurring scans will try again during their next scheduled scan period. This change prevents "surprise" scans when a particular job takes longer than expected.

  • Agents now support concurrent scans. To enable this feature, access the agent list and choose Configure Agent from the Manage menu. Concurrent scans allow powerful centralized systems to get more done at once and can reduce overall scan times.

Concurrent Scan Settings

The Rumble Agent has been updated with the latest version of npcap, upgrades more reliably in certain corner cases, and writes out a log file automatically on all platforms. This release also resolves occassional issues with lingering chrome.exe processes on Windows systems.

The runZero Scanner now supports multiple import files, can work from a previous assets.jsonl as a baseline, and can upload resuls to the Rumble platform automatically, creating new sites as needed. For folks who prefer to run their scans by hand or in response to network events, this a great way to populate the inventory on demand. Take a look at this post for additional information on the scanner changes.

Release Notes #

If you haven't had a chance to try runZero before, or would like to play with the new features, sign up for a free trial and let us know what you think!

Written by HD Moore

HD Moore is the founder and CEO of runZero. Previously, he founded the Metasploit Project and served as the main developer of the Metasploit Framework, which is the world's most widely used penetration testing framework.

More about HD Moore
Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.

Explore more runZero

Product
Announcing runZero 4.9: Unmask attack paths and segmentation gaps with advanced topology and deep OT device intelligence
With runZero 4.9, visualize attacker lateral movement, harden network choke points, gain deep OT telemetry to secure converged environments, and more.
Webcasts
runZero Hour, Ep. 30: Segmentation - stop assuming & start verifying with runZero 4.9
See runZero 4.9 in action! Join HD Moore and Tod Beardsley to learn how interactive attack path mapping and advanced OT intelligence expose hidden...
Product Videos
runZero 4.9: Advanced topology, attack path mapping, & deep OT intelligence
With runZero 4.9, visualize attacker lateral movement, harden network choke points, gain deep OT telemetry to secure converged environments, and more.
runZero Perspective
Dawn of the apex agentic adversary
When agentic AI can weaponize exploits in seconds, visibility is everything. Stop the predator with runZero’s exposure management for the AI-attack...
Webcasts
Beyond the Zero-Day: Mapping the network attackers actually see
Breaches are inevitable. Learn from HD Moore how attackers exploit the seams between IT, IoT, and OT networks — and how to fix the segmentation...
Podcasts
Risky Biz Interview: Navigating the AI vibe shift with HD Moore
runZero Founder and CEO HD Moore drops by in this week's Risky Biz sponsor interview to talk about the concerning AI vibe shift and what to do...
Podcasts
From two weeks to three days: The KEV deadline debate
Former CISA insider Todd Beardsley joins Greg to reveal what it takes to land on the KEV catalog and why ultra-short patching deadlines might...
Solution Briefs
runZero for NIS2 compliance
You can’t secure what you can’t see. runZero provides the complete asset visibility and continuous reporting you need to satisfy strict NIS2...

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.