Rumble 2.2 HP iLO Analysis, Virtual Machine Fingerprinting, and VLAN Tracking

|
Updated

Rumble Network Discovery 2.2 #

Rumble 2.2 is available with improved analysis capabilities for HP iLOs, virtual machine fingerprinting support, automatic VLAN membership tracking through switch enumeration, and much more.

Track HP iLO warranties and find outdated firmware #

The Rumble scan engine now enumerates detailed information from HP Integrated Lights-Out (iLO) modules and includes a new iLO-specific CSV export that allows enterprise customers to track warranties across the environment.

The inventory now includes detailed information for HP iLOs, including host names, MAC addresses, detailed hardware model information, iLO firmware version, and health status. The HP iLO CSV export includes everything necessary for warranty tracking as well as additional fields including:

  • The configured Insight Remote Support server
  • The health status of the module
  • All active MAC addresses
  • Authentication methods

In addition to the inventory, there are also three new asset attribute reports to help you find HP iLOs based on the server model, firmware version, and iLO model. You can use the firmware version report to quickly find outdated iLOs across the organization.

HP iLO Inventory

Virtual machine fingerprinting #

This release includes first-class reporting of virtual machine vendors and virtual hardware fields. A new asset attribute, virtual, identifies the virtual machine vendor of each asset in your environment. You can use this attribute to query vendor-specific virtual machines, like VMware or VirtualBox. To list all virtual machines, you can use a query like alive:t AND has:virtual. A new icon in the asset inventory indicates that a system is a virtual machine. Please note that these changes only take affect after your next scan completes.

For a quick breakdown by vendor, you can use the new virtual asset attribute report.

Virtual Machine Inventory

Virtual LAN tracking #

The new VLAN Membership Report breaks down all identified virtual LANs and the number of assets associated with each. Rumble reports VLAN associations for assets connected to a managed switch where SNMP credentials are available.

To help assess gaps, you can query has:vlan to show all assets with a VLAN, or a query like not has:vlan, to find assets where switch VLAN data is not available. You can also use a query like vlan:40 to find all assets associated with a specific VLAN.

VLAN Membership Report

Find Exim servers on your network #

The Rumble Query Library helps you find things fast, which is particularly useful when a vulnerability disclosure requires immediate action. Recently, the Qualys research reported 21 new vulnerabilities in the Exim mail server software. Security updates are available, but getting a comprehensive list of affected systems can be tricky. You can use our pre-built query to find all Exim servers in your environment, fast.

Exim Email Server Query

Release Notes #

This release includes a ton of other changes, including bug fixes, user experience tweaks, and other small udpates. Read the full changelog to see all improvements in Rumble 2.2.

Don't have access to Rumble yet? Sign up for a free trial to try out these new capabilities.

Written by runZero Team

Great research and development is a team effort! Multiple runZero team members collaborated on this post. Go team!

More about runZero Team
Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.

Explore more runZero

Product
Announcing runZero 4.9: Unmask attack paths and segmentation gaps with advanced topology and deep OT device intelligence
With runZero 4.9, visualize attacker lateral movement, harden network choke points, gain deep OT telemetry to secure converged environments, and more.
Webcasts
runZero Hour, Ep. 30: Segmentation - stop assuming & start verifying with runZero 4.9
See runZero 4.9 in action! Join HD Moore and Tod Beardsley to learn how interactive attack path mapping and advanced OT intelligence expose hidden...
Product Videos
runZero 4.9: Advanced topology, attack path mapping, & deep OT intelligence
With runZero 4.9, visualize attacker lateral movement, harden network choke points, gain deep OT telemetry to secure converged environments, and more.
runZero Perspective
Dawn of the apex agentic adversary
When agentic AI can weaponize exploits in seconds, visibility is everything. Stop the predator with runZero’s exposure management for the AI-attack...
Podcasts
From two weeks to three days: The KEV deadline debate
Former CISA insider Todd Beardsley joins Greg to reveal what it takes to land on the KEV catalog and why ultra-short patching deadlines might...
Solution Briefs
runZero for NIS2 compliance
You can’t secure what you can’t see. runZero provides the complete asset visibility and continuous reporting you need to satisfy strict NIS2...
Webcasts
Hardening attack surfaces against AI-powered exploits
Learn to find rogue IoT, multi-homed devices, and hidden attack paths. HD Moore shares a blueprint for total attack surface management in the age...
Podcasts
OT asset exposures & mitigations
Rob King joins the Nexus Podcast to discuss the security risks and exposures introduced by digital transformation to operational technology...

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.