Rumble 2.1 Notification Templates, AWS EC2 Enrichment, and Cisco SNTC Exports

|
Updated

Rumble Network Discovery 2.1 #

Rumble 2.1 is now live with support for custom notification templates, AWS EC2 scan enrichment, Cisco serial number exports for SNTC, faster exports, more flexible imports, an updated Splunk Addon, and much more!

Custom notification emails and Slack posts #

The Rules Engine added in Rumble 2.0 now supports custom notification templates in plain text, HTML, and JSON formats. These templates support the Mustache syntax and can include the results from search queries and post-scan asset changes. HTML templates can make for pretty automated reports, while custom JSON templates power fancy Slack notifications.

Email Notification Templates

Webhook notifications now also support custom HTTP headers for endpoints that require bearer token or basic authentication.

Webhook Notification Templates

Enrich your AWS VPC discovery data #

The runZero Explorer now detects and uses the AWS API to automatically enrich VPC scans with instance details. VPC scans will now show the internal IPs, external IPs, MAC addresses, and instance attributes for any EC2 instances in the scan scope, automatically. AWS instance tags are also applied to your Rumble assets. To enable this feature, make sure the instance running the Explorer is configured with ec2:DescribeInstances permission (via IAM instance role or via awscli configure). Explorers with EC2 enrichment support will show a new cloud icon in the capabilities column of the Explorers list. Big thanks to Dustin for making this suggestion!

AWS EC2 scan enrichment

Easily track Cisco warranties with Smart Net Total Care (SNTC) export #

Looking for an easy way to upload all router and switch serial numbers to the Cisco Smart Net Total Care (SMTC) platform for warranty tracking? Rumble now supports this specific export format, simplifying the process of checking support coverage of all deployed Cisco equipment. This feature is available for Rumble Enterprise users.

Cisco SNTC Export

The Inventory can be used to apply tags in bulk and now it supports tag removal too. Specify a tag with a minus sign prefix and that tag will be removed from all selected assets. Subnet tags now use the same search syntax as asset tags and these can be used interchangeably in search queries.

Bulk Tag Removal

Import, Export, and the Splunk Addon #

Inventory exports via the web console and API are now faster, especially when used with complex search queries. The Recurring and Search tabs of the task view now provide the option to export into CSV and JSON formats. The CSV export includes the schedule of each recurring task and the estimated runtime. The Splunk Addon now syncs faster and now supports proxies. Imported asset CSV files now ignore extra records.

Export Recurring Tasks

SNMP v2 Community Indexing #

This release adds automatic support for community indexing when using SNMP v2 to enumerate Cisco Catalyst switches. This leads to full port enumeration across all VLANs with no additional configuration. A reasonable timeout is enforced for systems with extreme VLAN configurations.

Release Notes #

Read the release notes to view all the updates and improvements in Rumble 2.1.

Don't have access to Rumble yet? Sign up for a free trial to try out these new capabilities.

Written by HD Moore

HD Moore is the founder and CEO of runZero. Previously, he founded the Metasploit Project and served as the main developer of the Metasploit Framework, which is the world's most widely used penetration testing framework.

More about HD Moore
Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.

Explore more runZero

Product
Announcing runZero 4.9: Unmask attack paths and segmentation gaps with advanced topology and deep OT device intelligence
With runZero 4.9, visualize attacker lateral movement, harden network choke points, gain deep OT telemetry to secure converged environments, and more.
Webcasts
runZero Hour, Ep. 30: Segmentation - stop assuming & start verifying with runZero 4.9
See runZero 4.9 in action! Join HD Moore and Tod Beardsley to learn how interactive attack path mapping and advanced OT intelligence expose hidden...
Product Videos
runZero 4.9: Advanced topology, attack path mapping, & deep OT intelligence
With runZero 4.9, visualize attacker lateral movement, harden network choke points, gain deep OT telemetry to secure converged environments, and more.
runZero Perspective
Dawn of the apex agentic adversary
When agentic AI can weaponize exploits in seconds, visibility is everything. Stop the predator with runZero’s exposure management for the AI-attack...
Webcasts
Defending in the shadow era: when the CVE feed goes dark
HD Moore walks through the three eras of vulnerability management: the predictable cycles era, the triage ara of AI-scale discovery, and now the...
Webcasts
runZero Hour, Ep. 31: The New Rules of Risk: EPSS v5 and Agentic Adversaries
In this episode, learn how your security team can use EPSS v5 to inform daily risk decisions in a world increasingly targeted by the apex agentic...
Webcasts
Beyond the Zero-Day: Mapping the network attackers actually see
Breaches are inevitable. Learn from HD Moore how attackers exploit the seams between IT, IoT, and OT networks — and how to fix the segmentation...
Podcasts
Risky Biz Interview: Navigating the AI vibe shift with HD Moore
runZero Founder and CEO HD Moore drops by in this week's Risky Biz sponsor interview to talk about the concerning AI vibe shift and what to do...

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.