Rumble 2.1 Notification Templates, AWS EC2 Enrichment, and Cisco SNTC Exports

Updated

Rumble Network Discovery 2.1 #

Rumble 2.1 is now live with support for custom notification templates, AWS EC2 scan enrichment, Cisco serial number exports for SNTC, faster exports, more flexible imports, an updated Splunk Addon, and much more!

Custom notification emails and Slack posts #

The Rules Engine added in Rumble 2.0 now supports custom notification templates in plain text, HTML, and JSON formats. These templates support the Mustache syntax and can include the results from search queries and post-scan asset changes. HTML templates can make for pretty automated reports, while custom JSON templates power fancy Slack notifications.

Email Notification Templates

Webhook notifications now also support custom HTTP headers for endpoints that require bearer token or basic authentication.

Webhook Notification Templates

Enrich your AWS VPC discovery data #

The runZero Explorer now detects and uses the AWS API to automatically enrich VPC scans with instance details. VPC scans will now show the internal IPs, external IPs, MAC addresses, and instance attributes for any EC2 instances in the scan scope, automatically. AWS instance tags are also applied to your Rumble assets. To enable this feature, make sure the instance running the Explorer is configured with ec2:DescribeInstances permission (via IAM instance role or via awscli configure). Explorers with EC2 enrichment support will show a new cloud icon in the capabilities column of the Explorers list. Big thanks to Dustin for making this suggestion!

AWS EC2 scan enrichment

Easily track Cisco warranties with Smart Net Total Care (SNTC) export #

Looking for an easy way to upload all router and switch serial numbers to the Cisco Smart Net Total Care (SMTC) platform for warranty tracking? Rumble now supports this specific export format, simplifying the process of checking support coverage of all deployed Cisco equipment. This feature is available for Rumble Enterprise users.

Cisco SNTC Export

The Inventory can be used to apply tags in bulk and now it supports tag removal too. Specify a tag with a minus sign prefix and that tag will be removed from all selected assets. Subnet tags now use the same search syntax as asset tags and these can be used interchangeably in search queries.

Bulk Tag Removal

Import, Export, and the Splunk Addon #

Inventory exports via the web console and API are now faster, especially when used with complex search queries. The Recurring and Search tabs of the task view now provide the option to export into CSV and JSON formats. The CSV export includes the schedule of each recurring task and the estimated runtime. The Splunk Addon now syncs faster and now supports proxies. Imported asset CSV files now ignore extra records.

Export Recurring Tasks

SNMP v2 Community Indexing #

This release adds automatic support for community indexing when using SNMP v2 to enumerate Cisco Catalyst switches. This leads to full port enumeration across all VLANs with no additional configuration. A reasonable timeout is enforced for systems with extreme VLAN configurations.

Release Notes #

Read the release notes to view all the updates and improvements in Rumble 2.1.

Don't have access to Rumble yet? Sign up for a free trial to try out these new capabilities.

Written by HD Moore

HD Moore is the co-founder and CEO of runZero. Previously, he founded the Metasploit Project and served as the main developer of the Metasploit Framework, which is the world's most widely used penetration testing framework.
More about HD Moore
Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.


Related Articles

runZero Research
Active Asset Discovery in OT networks: runZero and the NREL/CECA Report
The Cohort 2 report describes how runZero safely discovers devices in a large, complex OT/ICS environment. Learn more about runZero's discovery...
runZero Research
AI in CAASM: The Risks of LLM Data in Security-Critical Workflows
Current generation AI tools provide appealing answers but struggle with a crucial challenge: knowing the truth, which poses great security risks.
runZero Research
SSHamble: Unexpected exposures in the Secure Shell
We conducted a deep dive into the SSH ecosystem and identified vulnerabilities across a wide range of implementations. During the research process,...
runZero Research
Attack Surface Challenges with OT/ICS and Cloud Environments
Learn why successfully navigating changes to operational technology and cloud attack surfaces is critical for successful asset security.

See Results in Minutes

Get complete visibility into IT, OT, & IoT — without agents, credentials, or hardware.

© Copyright 2024 runZero, Inc. All Rights Reserved