Rumble 1.7.0 Reporting, Fingerprints, and More!

|
Updated

Overview #

Version 1.7.0 of Rumble Network Discovery is live with big updates to reporting. The Analysis Reports introduced in version 1.6.2 are now joined by a new Subnet Grid Report, linked off the main Subnets Report under the Explore menu.

The Query Library has been updated with small tweaks and new built-in query for finding expired TLS certificates, supported by improvements to the scan engine. The Rumble backend has been upgraded to support our larger customers as well as all of our new Starter Edition users.

The command-line runZero Scanner now generates its own Network Bridges and Switch Topology reports outside of the cloud platform. For folks who want to build their own fingerprints, the command-line scanner now supports custom Recog fingerprint stores using the --fingerprints argument and easy debugging by setting the --fingerprints-debug boolean flag.

Subnet Grid Report #

Rumble can now provide a birds-eye view of the network through the Subnet Grid Report. The backstory on this visualization needs its own blog post, but the short version is that treating the IP address space as a grid and applying color maps based on attributes can identify interesting network properties. The Subnet Grid Report can be found linked with a icon off of the main Subnets Report. The example below is the type color map of a public IPv4 network.

Rumble Subnet Grid Report

The runZero Scanner #

The command-line runZero Scanner now generates the Network Bridges and Switch Topology reports. These reports can help you understand the layer 2 topology and layer 3 segmentation of a network without having to upload the scans into the cloud platform.

runZero Scanner Topology Report

These report can also be generated using previous scan data. The --import option can be used multiple times to merge many raw scan files into a combined report.

$ runzero-scanner -o runzero-1.7.0 --import previous-scan/scan.rumble.gz
$ start runzero-1.7.0\bridges.html

runZero Scanner Bridges Report

More Enhancements #

Alert Rules can now be limited to a specific site or all sites, depending on your preference.

Recurring scans now show the day of the week abbreviation in the user interface.

The Rumble Agent and runZero Scanner now use version 0.9991 of npcap.

Dashboard statistics now only account for Live Assets.

The service timestamp fields ts, tls.notAfterTS, and tls.notBeforeTS can now be queried using time-based query operators.

Release Notes #

The complete release notes for v1.7.0 can be found in our documentation at the links below.

If you haven't had a chance to try runZero before, or would like to play with the new features, sign up for a free trial and let us know what you think!

Written by HD Moore

HD Moore is the founder and CEO of runZero. Previously, he founded the Metasploit Project and served as the main developer of the Metasploit Framework, which is the world's most widely used penetration testing framework.

More about HD Moore
Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.


Related Articles

runZero Insights
Taming the Typhoons: How runZero Keeps You Ahead of State-Sponsored Cyber Threats
China's Typhoon cyber attacks are evolving, but runZero helps you stay one step ahead with unmatched visibility and proactive defense.
runZero Insights
Ensure compliance with DORA’s ICT risk framework using runZero
Learn how to uncover unmanaged and unknown assets— including IT, OT, and IoT— to meet DORA's hidden risk requirements using runZero.
Life at runZero
Employee Spotlight: Doug Markiewicz
Doug Markiewicz is a strategic Customer Success Engineer with a passion for solving complex cybersecurity problems. Learn more about his journey as...
runZero Insights
Evolving from IT to IoT: Flax Typhoon preyed on the lesser knowns
A look at Flax Typhoon's latest operations, and how runZero’s unknown and IoT asset visibility can help calm the storm for security teams.

See Results in Minutes

Get complete visibility into IT, OT, & IoT — without agents, credentials, or hardware.

© Copyright 2024 runZero, Inc. All Rights Reserved