Rumble 1.15: Global Deployments, PostgreSQL, Crestron, and More!

January 12, 2021, by

HD Moore

Rumble v1.15

The 1.15 release improves global deployments, fingerprinting, and asset tracking. Rumble is still free for individuals and small businesses with less than 256 assets and is a great fit for security assessments using its temporary project feature.

Read on for the full list of changes since v1.14.

Global Deployment Support

For folks who need a local scanner in each broadcast domain, such as retail environments where each location has overlapping network ranges, the deployment process has become much easier. Site imports make it simple to generate and import a full list of sites and corresponding subnets from the web interface.

Mass-deployment of agents can be handled through just about any installer environment, either by running the standard agent executable with the UPDATER argument, or by using the MSI Installer to automatically install an agent from an arbitrary URL (with signature verification).

Mapping those agents to sites is easier than ever through the Automatically Assign Sites action in the Agents Manage menu. This feature automatically assigns each agent to the Site where a subnet matches the agent network interfaces. This saves quite a bit of time when deploying into hundreds of retail locations or micro-segmented environments

Finally, in order to manage hundreds of recurring scans, our team has provided an API example that can be used to configure recurring scans on every active site. You can find this example code in the rumble-api repository.

As always, if you run into a challenging deployment scenario, please reach out to our support team!

Screenshot of Rumble Automatic Agent to Site Assignment

Scanning Enhancements: Crestron & SolarWinds Orion

The Rumble scan engine now supports the Crestron UDP discovery protocol. This default probe provides substantially better fingerprinting for Crestron equipment and the various service attributes can be queried and reported via the inventory and attribute report.

The default TCP port list has been expanded to include additional services used by the SolarWinds Orion product. These additional ports improve detection of SolarWinds services and the Query Library now includes a pre-built query for finding Orion servers.

Rumble now negotiates TLS with PostgreSQL endpoints that support it. The stored fields include all of the standard TLS fields, including certificate expiration, TLS version, and chosen cipher.

Services where at least one virtual host has been identified (via TLS or DNS) will now merge the blank virtual host services into the first virtual host found. This reduces the number of unique services shown and makes the service attribute view less noisy without sacrificing accuracy.

SNMP fingerprints are now considered more reliable than SSH-based fingerprints in most cases. This improves identification of Cumulus Linux and other Linux-based switches.

Virtual MAC addresses used by PAN-OS as well as certain SonicWall VPNs are now ignored for the purpose of asset correlation, which in turn prevents inadvertent asset grouping.

On the Windows platform, the Rumble Agent and Rumble Scanner now bundle npcap 1.10, which includes a number of reliability and performance improvements.

Screenshot of Rumble Crestron Identification Screenshot of Rumble PostgreSQL TLS Attributes

Bug Fixes & Improvements

  • Proxy support for the Rumble Agent and Rumble Scanner is now handled consistently. The HTTPS_PROXY environment variable can be used to proxy communication between the host and the Rumble cloud and any environment-specified proxies are now ignored for the Chrome-based web screenshot functionality. In addition, the .env method of specifying a proxy is now used consistently regardless of the execution environment. These improvements apply to the Rumble Agent, Rumble Scanner, and Rumble MSI Installer.

  • Subtasks created by a recurring task now carry the “defaults” placeholders over as opposed to saving the expanded values. This results in the Copy action being more intuitive.

  • The tasks API now handles custom probe configurations correctly and the stopTask API documentation has been updated to indicate that it can be used to remove a recurring task.

  • The web screenshot probe now longer leaves zombie processes when running in container environments without a standard init(1) daemon.

  • A handful of small memory leaks in the Rumble scan engine have been resolved.

Release Notes

The complete release notes for v1.15.0 can be found in our documentation

If you haven’t had a chance to try Rumble before, or would like to play with the new features, sign up for a free trial and let us know what you think!

Create an Account

Similar Content

October 5, 2021

Rumble 2.7: New dashboard, multi-subscription Azure, AWS ELBs, Splunk add-on improvements, and faster discovery for Rumble Professional

What’s new with Rumble 2.7? User experience improvements Get insights, trends, and visualizations from your dashboard Easily navigate configuration pages for scans, imports, connections, and more Know when your connector credentials are invalid Integration …

Read More

September 8, 2021

Rumble 2.6: Integrate with Microsoft Azure Cloud, identify EOL assets, self-host in offline mode, and detect more protocols

What’s new with Rumble 2.6? Synchronize your Azure VM inventory with Rumble Identify assets running end-of-life OS versions Support for NFS, PPTP, and “r” services Updates to the CrowdStrike integration Install and update self-hosted Rumble in offline mode See new …

Read More

August 3, 2021

Rumble 2.5: Identify endpoint protection agents, detect wireless & mobile Internet, and scan all your EC2 accounts

What’s new with Rumble 2.5? Identify endpoint protection agents via integrations and unauthenticated scans Fingerprint wireless and mobile Internet on Windows without authentication Better fingerprinting for Windows 10 and 11, desktop/server, secondary IPs Discover …

Read More