Version 1.4.0 of Rumble Network Discovery is now available with a host of changes. This release rolls up our post-1.3.0 work, including major updates to the command-line Rumble Scanner and support for asset syncing in Splunk.

The Rumble user interface and API endpoints now support grouped queries using parenthesis in search terms. Grouped queries allow for complex filtering logic and can helpful when searching for specific types of misconfigurations.

Rumble Search Groups

These queries can be applied to the export functionality as well as the search interfaces for assets, services, screenshots, wireless networks, sites, and organizations.

The Rumble asset correlation engine now ignores “noisy” changes by default, including small changes to identified hostnames, domain names and reverse DNS entries. These improvements should reduce the number of alerts triggered after scans where reverse DNS becomes unavailable or is generally unreliable.

Network devices that intercept requests and forge network responses containing fake MAC addresses are now handled better. Prior to 1.4.0, Rumble could detect and avoid ARP proxies, and this release extends that support to devices that intercept and forge responses to protocols like NetBIOS and SNMP. This change prevents unrelated hosts from being correlated into the same asset.

For folks with busy scan schedules, this release has two major changes.

  • Scheduled scans that aren’t able to find an available agent after four hours are now automatically canceled. Recurring scans will try again during their next scheduled scan period. This change prevents “surprise” scans when a particular job takes longer than expected.

  • Agents now support concurrent scans. To enable this feature, access the agent list and choose Configure Agent from the Manage menu. Concurrent scans allow powerful centralized systems to get more done at once and can reduce overall scan times.

Concurrent Scan Settings

The Rumble Agent has been updated with the latest version of npcap, upgrades more reliably in certain corner cases, and writes out a log file automatically on all platforms. This release also resolves occassional issues with lingering chrome.exe processes on Windows systems.

The Rumble Scanner now supports multiple import files, can work from a previous assets.jsonl as a baseline, and can upload resuls to the Rumble platform automatically, creating new sites as needed. For folks who prefer to run their scans by hand or in response to network events, this a great way to populate the inventory on demand. Take a look at this post for additional information on the scanner changes.

Release Notes

If you haven’t had a chance to try Rumble before, or would like to play with the new features, sign up for a free trial and let us know what you think!

Similar Content

Overview Version 1.7.0 of Rumble Network Discovery is live with big updates to reporting. The Analysis Reports introduced in version 1.6.2 are now joined by a new Subnet Grid Report, linked off the main Subnets Report under the Explore menu. The Query Library has been updated with small tweaks and new built-in query for finding expired TLS certificates, supported by improvements to the scan engine. The Rumble backend has been upgraded to support our larger customers as well as all of our new Starter Edition users.
Overview Today’s update comes with two significant features: Analysis Reports and the Query Library. This work brings practical analytic capabilities to the inventory data and makes it easier than ever to create and share custom queries with your team and the wider community. Analysis Reports Analysis Reports are now accessible via the Explore link in the navigation menu. This section includes the three existing reports (Topology, Subnets, Bridges) and introduces two new ones.
Overview Version 1.6.0 of Rumble Network Discovery is live with support for configurable scan grace periods, data retention policies, additional protocol support, enhanced fingerprint coverage, new search keywords, and much more. Scan Grace Periods Starting with the 1.3.2 release, Rumble would automatically cancel a scheduled or recurring scan if the intended agent was not available after four hours. This fixed grace period prevented scans from stacking up in the case of a slow scan or offline agent, but it didn’t work for all use cases, and this is now configurable at the scan level.