Archived release notes

View as Markdown

Release notes prior to 2024

4.0.231222.1

2023-12-22

  • runZero no longer sets empty private IP ranges in place of the default values.
  • runZero now clears stale Azure scale set attributes.

4.0.231222.0

2023-12-22

  • CSV exports of site configurations no longer contain duplicate line items.
  • You can now dismiss most modal interfaces in the UI with the escape key.
  • MAC address assignment for certain HP servers with iLO devices has improved.
  • Fingerprint improvements.

4.0.231220.0

2023-12-20

  • Custom Integration assets can now include Service attribute data.
  • Correlation for Custom Integration assets has improved.
  • The service inventory table now shows the correct source icons.
  • Fingerprint improvements.

4.0.231218.0

2023-12-18

  • Third-party services now match existing runZero services correctly.
  • Fingerprint improvements.

4.0.231215.0

2023-12-15

  • Correlation for Tenable-sourced assets has improved.
  • Logging in no longer causes a redirect loop when the user hasn’t agreed to the latest terms and MFA is required but not set.
  • Self-hosted customJS now runs on all authorized pages.
  • Fingerprint improvements.

4.0.231213.0

2023-12-13

  • Explorer memory requirements now match the documentation.
  • The CVEs column of the Queries datagrid is no longer sortable.
  • Datagrid tables no longer become un-sortable when an overlay appears.
  • Fingerprint improvements.

4.0.231211.0

2023-12-11

  • Fingerprint improvements.

4.0.231208.0

2023-12-08

  • Datagrids now show the correct loading state when you interrupt a running search.
  • Fingerprint improvements.

4.0.231207.0

2023-12-07

  • Tasks no longer get stuck in “stopping” status.
  • Goals associated with vulnerability queries now report accurate progress.
  • Self-hosted customers can now load configuration items from multiple Secrets Manager keys by separating the keys with commas in the AWS_SECRET_ACCESS_KEY variable.
  • Accessibility improvements.
  • Fingerprint improvements.

4.0.231205.0

2023-12-05

  • runZero no longer marks successful tasks as stale.
  • Assets now indicate SNMPv3 authentication correctly.
  • Fingerprint improvements.

4.0.231201.1

2023-12-01

  • Datagrids now show their scrollbars.

4.0.231201.0

2023-12-01

  • You can now download the arm64 versions of the FreeBSD, NetBSD, and OpenBSD binaries.
  • The datagrid page selector has improved.
  • You can now manually resize datagrid columns beyond the visible width of the grid.

4.0.231130.0

2023-11-30

  • runZero can now discover assets using the S7 protocol.
  • Passive detection of RDP authentication methods has improved.
  • The inventory action buttons have a new design for a better user experience.
  • Inventory tables no longer display too many pages.
  • runZero now imports Azure AD users and groups correctly.
  • Fingerprint improvements.

4.0.231128.0

2023-11-28

  • Explorer memory usage has improved in some situations.
  • The task failure reason column now appears.
  • The scan progress label is now accurate.
  • The Custom Integrations SDK now measures strings with multi-byte unicode characters correctly.
  • The task summary view now shows an accurate asset changed count.
  • Fingerprint improvements.

4.0.231122.0

2023-11-22

  • runZero no longer omits the OS EOL for some Linux variants.
  • Detection of Fortinet devices has improved.
  • Fingerprint improvements.

4.0.231121.0

2023-11-21

  • Editing credentials now works.
  • The asset JSON export now includes extended ownership data under the ‘ownership’ field.
  • Fingerprinting of Cisco devices has improved.
  • Fingerprint improvements.

4.0.231120.0

2023-11-20

  • The Task Library datagrid now works correctly.
  • Some buttons now render properly.
  • The select-all button now works on the datagrids where it previously failed.
  • Self-hosted users can now override the S3 region and endpoint.
  • Fingerprints for Cisco small business devices have improved.
  • Fingerprint improvements.

4.0.231116.0

2023-11-16

  • The asset attribute report’s performance for third-party sources has improved.
  • Datagrid column widths now persist after you resize them manually.
  • You can now manage datagrid column width and visibility more granularly through two new dropdown menus on all datagrids.
  • Deleting an organization via the API now returns the proper “404” HTTP status code if the organization does not exist.
  • Fingerprint improvements.

4.0.231115.0

2023-11-15

  • Detection of bulk responses from Fortinet network filtering products has improved.
  • Asset matching now works in certain rare cases involving virtual IP addresses or heavy IP reuse.
  • The datagrid on the Monitor landing page now displays.
  • Action buttons on the task datagrids are no longer cut off at the top.
  • The SSO Group Mapping datagrid now loads.
  • Fingerprint improvements.

4.0.231114.0

2023-11-14

  • runZero no longer inadvertently deletes Explorer binaries.

4.0.231108.1

2023-11-08

  • The Azure AD integration can now filter inactive devices.
  • SSO group mapping rules can now use a DN containing commas.
  • The runZero Explorer can now clean up stale files in both the legacy Rumble and runZero install locations.

4.0.231108.0

2023-11-08

  • You can now configure private IP address ranges at the Account and Organization level.
  • runZero now detects the ThinPrint protocol.
  • runZero now supports the legacy ident protocol.
  • Scanning of OpenVMS systems has improved.
  • OS fingerprinting of data from custom integrations has improved.
  • Detection of embedded Linux devices has improved.
  • runZero now parses inventory queries with warnings on a best-effort basis.
  • The Asset and Service trend charts on the Dashboard now render.
  • Fingerprint improvements.

4.0.231102.0

2023-11-02

  • Tasks now process correctly for large customers.

4.0.231101.0

2023-11-01

  • Processing asset modification rules no longer consumes excessive memory.
  • The scanner now supports the IGEL thin client protocol.
  • Fingerprint improvements.

4.0.231031.2

2023-10-31

  • runZero now retries HTTP requests correctly.

4.0.231031.1

2023-10-31

  • Retry handling in third-party connectors has improved.

4.0.231031.0

2023-10-31

  • CrowdStrike connections no longer stall.

4.0.231030.0

2023-10-30

  • The scanner and passive engine now support the Kasa IoT protocol.
  • The scanner now reports the Shodan-compatible Murmur3 32-bit hash for favicon files.
  • Setting per-organization permissions for the primary organization now works.
  • Invalid action buttons no longer appear for External Users.
  • The External Users table no longer omits inactive users.
  • The External Users table now includes group permissions in the Org Access summary.
  • Performance improvements.
  • Fingerprint improvements.

4.0.231027.1

2023-10-27

  • runZero now records asset correlations correctly for some existing assets.

4.0.231027.0

2023-10-27

  • The API now has endpoints for setting asset criticality individually or in bulk.
  • You can now update asset criticality via CSV import.
  • A user’s browser no longer appears stuck in a refresh loop on login.
  • Correlation between Azure AD, Microsoft Intune, and Microsoft 365 Defender assets has improved.
  • Time-based filtering when requesting data from the Tenable Security Center API has improved.
  • The CrowdStrike connector is now more reliable.
  • The Microsoft Intune connector is now more reliable.
  • The asset details page now shows additional correlation information for attributes, including latest task details.
  • runZero can now fingerprint devices based on the SecuRemote protocol.
  • Probing of certain types of printers and print servers has improved.
  • Fingerprint improvements.

4.0.231023.0

2023-10-23

  • runZero no longer improperly clears query-reported vulnerabilities.
  • runZero no longer creates invalid Tenable Security Center assets.
  • Fingerprint improvements.

4.0.231019.0

2023-10-19

  • The CrowdStrike integration now handles vulnerability requests better.
  • Fingerprint improvements.

4.0.231018.0

2023-10-18

  • Performance improvements.
  • Fingerprint improvements.

4.0.231017.1

2023-10-17

  • Task search now processes the type keyword correctly.

4.0.231017.0

2023-10-17

  • The credentials list now has a button in each row’s actions column for deleting a single credential.
  • Merge accuracy for externally scanned AWS assets reported by third-party sources has improved.
  • Fingerprint improvements.

4.0.231013.0

2023-10-13

  • The asset inventory now shows the Site as the first column on the left.
  • Performance improvements.

4.0.231012.0

2023-10-12

  • Custom integrations can now include vulnerability and software data.
  • Merge accuracy for attribute-based matching and invalid TLS serial IDs has improved.
  • MAC vendor accuracy for AWS assets reported via CrowdStrike has improved.
  • The asset inventory now supports the attribute_count search term.
  • Events created by editing alert channels, rules, or templates now trigger the corresponding alert rules correctly.
  • runZero no longer displays an incorrect resource warning for Explorers.
  • TLS fingerprinting now covers new Go versions.
  • Performance improvements.

4.0.231011.0

2023-10-11

  • runZero no longer selects a random authorized organization on login.
  • Performance improvements.

4.0.231006.0

2023-10-06

  • runZero fixed a low-severity security issue with unsafe request binding.
  • mDNS processing no longer merges assets incorrectly.
  • Users no longer need to re-enter the “Authentication passphrase” and “Privacy passphrase” fields when editing an SNMPv3 credential.
  • The performance of third-party user and group imports has improved.
  • The Asset Details page now truncates long asset-level and service-level attribute values for display.
  • The self-hosted platform now supports Amazon Linux 2.
  • The npcap driver is now version 1.77.
  • Identification of devices using the Cisco Discovery Protocol has improved.
  • Detection of MAC addresses for CradlePoint devices has improved.
  • Fingerprint improvements.

4.0.231005.0

2023-10-05

  • runZero fixed a low-severity security issue with mass assignment.
  • Sorting recurring tasks no longer produces a “failed to parse query” error.

4.0.231002.0

2023-10-02

  • Merge accuracy for externally scanned AWS assets reported by third-party sources has improved.
  • Fingerprint improvements.

4.0.230928.0

2023-09-28

  • Detection of spurious and phantom services generated by some network devices during probing has improved.
  • Fingerprint improvements.

Important security fix:

  • Our annual third-party security assessment identified a SQL injection vulnerability, which is now fixed.

4.0.230927.0

2023-09-27

  • The Scan and Monitor landing pages now load faster.
  • runZero can now detect assets using the OMRON FINS protocol.
  • The self-hosted console now logs certain scan data download errors correctly.
  • Fingerprint improvements.

4.0.230925.0

2023-09-25

3.10.230921.0

2023-09-21

  • Logging in via SSO no longer causes a continuous page refresh.

3.10.230920.0

2023-09-20

  • runZero fixed a performance regression when processing third-party assets.
  • Merging of assets with NetBIOS or SMB services has improved.
  • The tasks CSV export now includes the template_name column.
  • The tasks JSON export and API responses now include the site_name, agent_name, and template_name columns.
  • Fingerprint improvements.

3.10.230918.0

2023-09-18

  • New SSO users can now authenticate correctly.
  • Fingerprint improvements.

3.10.230917.1

2023-09-17

  • Some Windows-based Explorers can now connect with the same ID.
  • Fingerprint improvements.

3.10.230917.0

2023-09-17

  • The Explorer now reads the .env configuration file correctly.
  • Tenable Security Center syncs now complete correctly.
  • Scans through FortiGate proxies no longer produce bogus assets.
  • runZero fixed several small parsing bugs in the protocol parsing engine.
  • Passive traffic sampling tasks now set source:sample instead of source:passive for assets.
  • The self-hosted console now uses the “runZero” brand (and runzeroctl command) by default.
  • The self-hosted console now defaults to PostgreSQL 15 and provides an install option to select a version.
  • The Explorer now uses the “runZero” brand by default (and matching filesystem/registry locations).
  • Fingerprint improvements.

3.10.230913.0

2023-09-13

  • runZero can now identify scanners using the eSCL uscan protocol.
  • Custom Integrations now support the “exclude unknown” option.
  • The Microsoft Intune integration now handles API request retries better.
  • Detection of spurious services when scanning certain firewalls has improved.
  • The Tenable integration is now less likely to hit asset and vulnerability export timeouts.
  • Invited users using Single Sign-On no longer encounter login errors.
  • Fingerprint improvements.

3.10.230911.0

2023-09-11

  • The Tenable integration is now less likely to hit vulnerability export timeouts.
  • Fingerprint improvements.

3.10.230908.01

2023-09-08

  • The console and Explorers now use a new versioning scheme, <major>.<minor>.<yymmdd>.<revision>.
  • runZero can now fingerprint devices with the Voice Services Discovery Protocol (VSDP).
  • Fingerprinting of devices using Spotify Connect has improved.
  • Detection of BACnet devices has improved.
  • Additional Fingerprint improvements.

3.10.25

2023-09-05

  • Scan tasks now record a warning when a host is ignored for responding on too many ports.
  • The Integrate page now shows active and suggested integrations for the current organization.
  • Fingerprint improvements.

3.10.24

2023-08-30

  • The dashboard no longer appears empty until a metrics recalculation is triggered.
  • Fingerprint improvements.

3.10.23

2023-08-29

  • runZero fixed an issue that could stall scans.

3.10.22

2023-08-29

  • The dashboard no longer appears empty when you select a single site.

3.10.21

2023-08-29

  • runZero can now discover devices using the MODBUS/TCP protocol.
  • The maximum number of ownership types has increased from 10 to 25.
  • Some sources no longer produce duplicate software entries.
  • Fingerprinting of devices that provide UPnP information has improved.
  • Additional Fingerprint improvements.

3.10.20

2023-08-25

  • SNMPv3 credentials now save correctly.

3.10.19

2023-08-23

  • The ts attribute is now correct for Azure AD, Google Workspace, and Microsoft Intune.
  • Fingerprinting of assets based on Microsoft Intune and Microsoft 365 Defender data has improved.
  • runZero can now discover assets via EtherNet/IP probing.
  • Fingerprint improvements.

3.10.18

2023-08-21

  • Event rules now support conditions for Explorer and task type, where relevant.
  • Recurring tasks now stop with an error if their task template was deleted.
  • The console and API now expose a rotation date for stored credentials via a new secret_updated_at field.
  • runZero no longer merges CrowdStrike and Azure AD assets that have a different globally unique ID. This may generate more offline assets if devices are frequently reimaged and given new GUIDs.
  • Users who were unable to manage their users’ group membership now can.
  • runZero fixed a bug in the user permissions display interface.
  • runZero no longer assigns foreign service attributes to the wrong source.
  • Fingerprint improvements.

3.10.17

2023-08-16

  • The scanner now supports the MQTT protocol.
  • The TCP SYN scanner is now friendlier to stateful firewalls in the network path.
  • The Processing section of the Tasks overview now includes tasks in the stopping state.
  • Users logging in for the first time with SSO now have access to organizations from the SSO group mappings.
  • runZero now fingerprints assets correctly based on Azure AD data.
  • runZero now completely filters bogus services from certain firewalls.
  • Fingerprint improvements.

3.10.16

2023-08-14

  • Tasks that are still stopping are no longer dismissible. Only failed and completely stopped tasks can be dismissed.
  • Pending new tasks are no longer editable. Only new tasks scheduled to start in the future can be modified.
  • The redesigned scanner page now displays download commands.
  • Importing data from Microsoft 365 Defender no longer fingerprints existing assets incorrectly.
  • runZero no longer incorrectly asserts Microsoft Defender for Endpoint in edr.name.
  • Error logging for the Shodan integration has improved.
  • Fingerprint improvements.

3.10.15

2023-08-10

  • The Explorer and scanner download pages have a new design with improved UX and performance.
  • The Tenable integration is now less likely to hit vulnerability export timeouts.
  • runZero no longer hides scan templates configured with invalid permissions.

3.10.14

2023-08-09

  • Alert templates now populate the scan.explorer_id value.
  • The “Find assets in this site” icon now works properly in cases where it previously did not.
  • Queries containing mixed-case search terms now return results.
  • Queries that previously failed to match Intune assets now match them correctly.
  • The scanner now supports a new syn-reset-sessions option, which can reduce session usage in middle boxes.
  • Fingerprint improvements.

3.10.13

2023-08-07

  • As a security improvement, runZero now clears password reset tokens after a password change or when link-based authentication is requested.
  • Intune assets now merge with other sources correctly.
  • Navigation for Explorer configuration editing is now consistent.
  • Fingerprint improvements.

3.10.12

2023-08-03

  • Password reset links now use the correct hostname.
  • The Explorer no longer leaks memory between stopped tasks.
  • The Nmap XML Export no longer has a zero start time.
  • Fingerprint improvements.

3.10.11

2023-07-31

  • Some long-running connection tasks no longer restart repeatedly.
  • Invalid Shodan credentials no longer pass validation.
  • Stale service removal on rescan now works properly.
  • Removing an Explorer no longer leaves orphaned tasks.
  • Fingerprint improvements.

3.10.10

2023-07-27

  • The user details page now displays permissions correctly.
  • runZero now calculates project expiration correctly.

3.10.9

2023-07-26

  • You can now modify the name and description of tasks created via file imports.
  • Automatic asset filtering for certain web proxy assets has improved.
  • Deleting large organizations, projects, or sites is now faster.
  • The Microsoft Intune and Azure AD integrations now use a longer request timeout.
  • Fingerprinting of SMB 1 endpoints has improved.
  • Connector tasks no longer show an unnecessary screenshot warning.
  • Additional Fingerprint improvements.

3.10.8

2023-07-24

  • Exports of task data now include timestamps that differentiate time spent acquiring data from time spent processing data.
  • Task processing times have improved.
  • App banners are now visible.
  • The api/v1.0/org/sites/{site_id}/import route now returns the proper 400 HTTP status code when the request body is empty, instead of a status code 500.

3.10.7

2023-07-21

  • In-scope, unscanned addresses on runZero assets are now cleared correctly.
  • The datepicker no longer closes when you navigate by year.

3.10.6

2023-07-19

  • Wireless networks now import correctly.

3.10.5

2023-07-19

  • The asset details screen now has pagination when viewing an asset with more than 30 services.
  • Modifying or copying existing scan tasks no longer enables SNMP credentials.
  • Fingerprint improvements.

3.10.4

2023-07-18

  • Columns now retain their custom ordering.
  • runZero fixed a bug that could limit the information gathered from NFS servers.
  • Fingerprint improvements.

3.10.3

2023-07-17

  • Copying a task no longer produces an incorrect discovery scope.

3.10.2

2023-07-17

  • On-screen text explaining the interaction between a user’s default organization role and the granted per-org role is now clearer.
  • runZero now applies license-based size limits to file imports.
  • The asset details page no longer loads very slowly.
  • Duplicate service warnings no longer appear.
  • Removing an Explorer no longer leaves orphaned tasks.
  • SYN and LAYER2 probes no longer get stuck in a perpetual error condition loop.
  • The User Details screen now displays the user permissions table.
  • Fingerprint improvements.

3.10.1

2023-07-12

  • The runZero Explorer now logs when the host operating system receives an interrupt or terminate signal, such as when the OS reboots.
  • Asset matching has improved for tasks that import both scan and third-party data sources.
  • Fingerprint improvements.

3.10.0

2023-07-10

  • runZero now has an integrations page that improves visibility and simplifies configuration.
  • The organization project status date no longer shows a discrepancy on tooltip hover.
  • Fingerprint improvements.

3.9.10

2023-07-06

  • The mDNS probe no longer panics in limited scenarios.

3.9.9

2023-07-06

  • The old Explorer details pages no longer appear.
  • Microsoft 365 Defender OAuth Client Credential tokens can now access Azure government environments.
  • Rapid7 assets no longer receive invalid Last Seen values.
  • runZero no longer leaves stale service entries.
  • Some goals no longer return an error.
  • Fingerprint improvements.

3.9.8

2023-07-05

  • Fingerprint improvements.

3.9.7

2023-07-03

  • Assets with hostnames starting with a numeric prefix can now merge.
  • Inventory searches using the organization keyword now warn that it cannot be used unless that specific organization, or the All Organizations option, is chosen from the drop-down in the upper right of the console.
  • Alert rule actions can now modify asset ownership based on software, service, or vulnerability query results.
  • Dynamic content now includes the Cache-Control: no-store header.
  • Fingerprint improvements.

3.9.6

2023-06-28

  • Detection of various printer models has improved.
  • The Explorer Details page has a new design.
  • Additional bugfixes and performance improvements.
  • Fingerprint improvements.

3.9.5

2023-06-27

  • Database performance for asset, site, and organization delete operations has improved.
  • Database performance for outlier and vulnerability processing has improved.
  • Database performance for concurrent integration processing has improved.
  • runZero now detects additional MAC addresses through SSDP and UPnP services.
  • Fingerprint improvements.

3.9.4

2023-06-26

  • Operating system and hardware fingerprinting of Palo Alto Networks devices has improved.
  • Trial accounts can now create Custom Integrations.
  • Discovery of SSDP services has improved.
  • Scans are no longer dropped with “explorer failed to queue task” when the Explorer is already handling the configured maximum number of simultaneous scans.
  • Fingerprint improvements.

3.9.3

2023-06-22

  • The scan start time no longer shows the task start time.
  • Creating new goals now works.
  • Viewing or modifying Asset Ownership now works for users with the ‘annotator’ role.
  • Fingerprint improvements.

3.9.2

2023-06-20

  • Handling of email send errors has improved.
  • Import of assets from Azure Active Directory has improved.
  • Asset correlation for switches with overlapping MAC addresses has improved.
  • Detection of AIX systems has improved.
  • OS fingerprinting now produces fewer false positives against assets with non-Microsoft SMB stacks.
  • Navigation to the Account settings page now works.
  • Adding or editing Google Workspace connector tasks no longer throws JavaScript errors.
  • Thumbprint validation for the LDAP integration now works correctly, and the related error messages have improved.
  • The query syntax help link no longer leads to a missing page.
  • runZero addressed a bug that prevented the Explorer interface and addresses from being populated.
  • Fingerprint improvements.

3.9.1

2023-06-14

  • Handling of login tokens has improved.

3.9.0

2023-06-13

  • runZero goals is now generally available. With runZero goals, users can create and monitor progress toward achieving security initiatives.
  • The goal progress chart now displays correctly at different browser sizes.
  • Goals now shows a pending calculation banner when goal metrics are not yet calculated.
  • The source_count and custom_integration_count fields are now searchable.
  • You can now create saved queries for tasks.
  • The task pages now support the recur_last_task_status search keyword.
  • Dashboard charts now display without partial rows, other than the last row, regardless of the number of charts displayed.
  • Fingerprinting of Fortinet device firmware has improved.
  • Database use is now more efficient, and performance has improved.
  • runZero no longer incorrectly merges Cisco 8xx Industrial Routers and Catalyst 94xx/95xx switches.
  • The autocomplete drop down now always appears on top of other elements.
  • Dashboard views now display integration sources as names instead of IDs.
  • Fingerprint improvements.

3.8.14

2023-06-06

  • Protocol feature extraction has improved for a range of protocols.
  • Data grid search text no longer propagates to other data grids.
  • Text inputs no longer display autocomplete where it was not intended.
  • Fingerprint improvements.

3.8.13

2023-05-31

  • You can now remove non-runZero asset sources from assets via the asset details or asset inventory pages.
  • runZero now accepts equivalent emails for email updates.
  • Dashboard cards for Asset Source and Custom Integrations should now show only the top 10 counts for each, with a new “View more” link.
  • runZero no longer allows AWS, Azure, and GCP assets to merge.
  • Scans no longer omit some SNMPv3 attributes.
  • Creating a project no longer returns a 404 error page in some cases.
  • The /org/metrics/{site_id} API endpoint now returns correct HTTP response codes.
  • Sorting the organizations table no longer clears the screen.
  • Vulnerabilities now sort correctly on CVSS columns.
  • Stopping scan tasks on hosted zones now works.
  • Fingerprint improvements.

3.8.12

2023-05-24

  • runZero now displays a warning if a Query is not attached to a Goal.
  • Users with “Viewer” permission can now see and use the “Sites” page.
  • Normalization of certain service attributes has improved.
  • Vulnerabilities now sort correctly on CVSS columns.
  • Fingerprint improvements.

3.8.11

2023-05-22

  • runZero fixed a bug that could cause excessive memory usage.

3.8.10

2023-05-22

  • SentinelOne matching has improved, which improves asset merging.
  • AWS credential validation now always shows the results for each service.
  • runZero no longer incorrectly merges certain models of Cisco routers.
  • AWS probes no longer fail when run outside of an AWS EC2 environment.
  • runZero addressed a bug that prevented IPv6 UDP SYN scans from working on FreeBSD and OpenBSD systems.
  • Autocomplete suggestions now update consistently.
  • The “download task button” no longer shows for tasks without a log.
  • Fingerprint improvements.

3.8.9

2023-05-19

  • The SNMP probe no longer panics in rare scenarios.

3.8.8

2023-05-19

  • Scans are now more reliable and should stall less frequently.
  • The SNMP probe no longer stalls scans in rare scenarios.

3.8.7

2023-05-19

  • The activation email should display properly in a broader range of email clients.
  • Scans no longer take longer than expected or stall in rare scenarios.

3.8.6

2023-05-18

  • The organization drop down is now clickable.

3.8.5

2023-05-17

  • The rpcbind probe now completes successfully.

3.8.4

2023-05-17

  • Copying some connector tasks now works correctly.
  • runZero no longer labels some connectors as scans.
  • Operating system fingerprinting via the SNMP Installed Software listing has improved.
  • The status indicator in the Explorer datagrid now has text describing the status.
  • Fingerprint improvements.

3.8.3

2023-05-15

  • The External Asset Report Include screenshots toggle now requires that Include asset details is checked.
  • The External Asset Report now hides the Top certificate authorities section if Include TLS certificate details is not checked.
  • The API /org/hosted-zones endpoint no longer returns an empty list of hosted zones.
  • runZero no longer creates invalid asset ownership assignments.
  • Fingerprinting of Brother scanners has improved.

3.8.2

2023-05-12

  • Outlier calculations now perform better and include the TLS stack.
  • Event rules that result in asset modifications now complete faster.
  • The npcap driver is now version 1.75.
  • runZero now supports legacy Internet time-distribution and traffic testing protocols.
  • A RUMBLE_CONSOLE override in the Explorer configuration now works.
  • Sites with more than 1000 subnets now save correctly.
  • Dashboard charts no longer behave oddly.
  • Self-hosted users no longer need to configure SMTP before setting up their initial account.
  • Some scan task errors no longer display twice.
  • Fingerprint improvements.

3.8.1

2023-05-11

  • Fingerprinting of devices using DLNA has improved.
  • Device type identification of Windows Server assets has improved.
  • runZero now completely filters bogus services from certain firewalls.
  • Asset queries for exact strings no longer perform a fuzzy search.
  • Auto-populated LDAP thumbprints for LDAP credentials are no longer malformed.
  • Credential validation errors now display after verification in the console.
  • Searching by clicking on a tag now returns the correct results.
  • runZero no longer incorrectly creates multiple subtasks for the same parent task.
  • runZero now retains filters when you import a Nessus scan configuration.
  • Copying some connector tasks now works correctly.
  • Links to the update page on some connector tasks now work.
  • Fingerprint improvements.

3.8.0

2023-05-09

  • You can now assign risk and criticality levels to assets through third-party integrations, the asset inventory, and custom rules.
  • runZero Preview Program: Goal tracking helps users with Professional and Enterprise licenses track progress toward completing their security initiatives. Use built-in goals for asset ownership coverage or system queries, or create goals with custom queries to fit your needs.
  • You can now use runZero system and custom queries to create vulnerability records.
  • Passwordless authentication is now available. Users can request one-time authentication links via email rather than storing a password, which provides a secure alternative when SSO cannot be configured.
  • runZero now supports Azure and Intune GCC, GCC High, and DoD environments.
  • Compatibility with WireGuard and Tailscale on macOS and *BSD has improved.
  • You can now search software attributes.
  • Alert channels now support more than one email address.
  • Asset limit warnings are now clearer about whether or not scans will be affected.
  • runZero now merges assets based on hostname if no other match method succeeds, as long as the hostname is from a trusted source (currently mDNS, NTLM, or NetBIOS).
  • Explorers reassigned to a previous organization now pick up their assigned tasks.
  • Software search links no longer navigate to a 404 page.
  • Task-failed events no longer ignore the site restriction.
  • The hostname override tag now updates the displayed hostname.
  • You can now clear Insights from the dashboard.
  • The copy scan button is no longer cut off in the recurring tasks tab.

3.7.11

2023-05-03

  • runZero fixed a bug that could cause a panic while performing a scan.
  • The API now creates valid scan tasks.
  • runZero fixed a bug that degraded fingerprinting via TLS certificates.
  • TLS negotiation no longer fails in some cases.

3.7.10

2023-05-02

  • Submitting Azure credentials for verification with a subscription ID now works correctly.

3.7.9

2023-05-02

  • You can now verify credentials only after completing all required fields.
  • The TCP LDAP probe and Active Directory integration no longer deadlock.
  • Clicking on site breadcrumbs no longer causes an infinite redirect.
  • Recurring tasks now sort correctly by start time on the tasks page.
  • “Verify & save” on the credentials update page no longer errors.
  • Dell laptops are no longer identified as desktops or servers.
  • TLS negotiation no longer fails in some cases.
  • runZero now parses imported queries properly.

3.7.8

2023-04-26

  • The default webhook Slack alert template now works correctly.
  • Deleting a scan template twice now shows an improved error message.
  • Fingerprinting of Brother scanners has improved.
  • Fingerprint improvements.

3.7.7

2023-04-24

  • A recent update to Explorer and CLI behavior that could inadvertently trigger CrowdStrike EDR detection is now disabled.

3.7.6

2023-04-24

  • You can now configure the grace period for tasks from the task template page.
  • Asset correlation for multi-source assets has improved.
  • runZero fixed a bug involving Intune rate limiting and intermittent failures.
  • Editing certain tasks now works.
  • Searching the asset inventory no longer erroneously returns results from unscanned runZero assets.
  • runZero no longer mistakenly marks assets “unscanned”.
  • Fingerprint improvements.

3.7.5

2023-04-20

  • Running the asset attribute report no longer returns a 500 error.
  • Miscellaneous bug fixes.

3.7.4

2023-04-19

  • The public API now has endpoints to view hosted zones.
  • The API endpoints for managing scan tasks now accept an argument to select a hosted zone.
  • Third-party vulnerability integrations now support a more granular risk filter.
  • Stored query validation now prevents saving queries with warnings or errors.
  • Custom integration results now merge into existing assets correctly.
  • Fingerprint improvements.

3.7.3

2023-04-17

  • The task details page now shows excerpts of task log messages for tasks in error status.
  • Datagrid warning and error messages now display more consistently.
  • The save button on the credential edit form no longer becomes disabled.
  • Fingerprint improvements.

3.7.2

2023-04-13

  • Asset processing has improved when FortiGuard endpoints with “Policy Override Authentication” enabled are present.
  • Self-hosted installs now support an option to disable TLS validation between Explorers and the console application.
  • Clicking links on the Query page of a self-hosted instance no longer returns a 500 error.
  • Clicking links in the Tasks column of the Credentials page no longer results in an error.
  • Paginated results now display Viewing 1 - N for the first page instead of Viewing 0 - N.

3.7.1

2023-04-12

  • Third-party integrations now support more granular vulnerability filters.
  • You can now disable HTTP security headers in self-hosted mode.
  • The CrowdStrike integration now uses Connection IP and Connection MAC for asset matching.
  • SNMP probes now support the max-repetitions and disable-bulk parameters.
  • The Task details pane now reports task failures.
  • You can now copy all queries, including runZero-provided system queries.
  • You can now modify the configuration for runZero-provided system queries.
  • runZero no longer creates duplicate offline assets.
  • CSV exports of assets now work when using free text search.
  • runZero no longer incorrectly sets the number of hops to zero when ARP is present as a service.
  • Searching assets using the task search key now works.

3.7.0

2023-04-10

  • Customers with a Platform license can now create custom integrations and import assets from any external asset data source using the runZero Python SDK.
  • The performance and reliability of metrics calculations have improved.
  • The performance of the vulnerabilities inventory has improved.
  • AWS permission errors are now more detailed to make troubleshooting easier.
  • You can now change the asset ownership tag successfully.
  • Email addresses are no longer case sensitive on sign in.
  • The “Create Organization” button no longer appears disabled when it is clickable.
  • The Asset Ownership goals toggle is now clickable.
  • Version 1.73 of the npcap driver is now included.
  • Fingerprint improvements.

3.6.19

2023-04-05

  • The performance of the organization details page has improved.
  • Updating asset owners now works.
  • Vulnerability counts for assets are now accurate.
  • Vulnerabilities for multi-source assets now save completely.
  • CrowdStrike integrations with large numbers of applications no longer error.
  • Fingerprint improvements.

3.6.18

2023-04-03

  • runZero addressed a bug where recurring tasks that are “Removed” still showed in the tasks page after the associated site is deleted.
  • Accessibility improvements.
  • Client-side timezone updates.
  • Fingerprint improvements.

3.6.17

2023-04-02

  • API requests to apply tags to one or more assets now complete much faster.
  • The scanner now supports the Steam In-Home Streaming discovery protocol.
  • Attribute reports now group unique values within a single key.
  • The View More link is now accessible for in-progress tasks.
  • Asset owner names now offer auto-complete suggestions.
  • The self-hosted installer now removes temporary files.
  • SNMP scans of specific Cisco switches are no longer slow.
  • Fingerprint improvements.

3.6.16

2023-03-29

  • Accessing runZero canned Queries now works.

3.6.15

2023-03-29

Important security fix:

  • Queries and their authors’ email addresses no longer show across tenants. This issue only applied to the cloud-hosted version of the runZero platform. The affected build was live for slightly more than two hours. Customers affected by this issue will receive a detailed notice at the email addresses associated with their superuser accounts.

3.6.14

2023-03-29

  • Updating assets with a large number of vulnerabilities no longer fails.
  • Fingerprint improvements.

3.6.13

2023-03-29

  • The Tenable integration is now more reliable.
  • Analysis queries for directory users and groups now run correctly. Match counts now display on the queries page.
  • You can now save queries for software, vulnerabilities, and screenshots.
  • Fingerprint improvements.

3.6.12

2023-03-28

  • You can now configure the maximum time for an SNMP walk.
  • The default maximum time for an SNMP walk is now 5 minutes instead of 1 minute.
  • An SNMP walk now returns up to 8k results instead of 4k.
  • The user details page now lists the assets a runZero user owns.
  • runZero attributes no longer disappear from Offline assets.
  • Subnet stats now export correctly.
  • The API response to a PUT request to /org/sites now includes the details of the new site.
  • The Reason column in the failed tasks table now stays hidden between page loads once you hide it.
  • Fingerprint improvements.

Note: The upgrade may take up to an hour for large self-hosted deployments.

3.6.11

2023-03-27

  • Asset correlation no longer produces inaccurate results.

3.6.10

2023-03-27

  • Hostname scan targets now validate correctly.
  • runZero now handles Cisco virtual MAC addresses more consistently.
  • The Tenable integration now uses longer timeouts.
  • CrowdStrike credential verification is now more reliable.
  • Datagrids across the UI now use the correct theme.
  • Task WLAN listing now enforces a timeout if the underlying utility is slow or unresponsive.
  • Fingerprint improvements.

3.6.9

2023-03-26

  • Fingerprint improvements.

3.6.8

2023-03-23

  • The vulnerability inventory now includes an Exploit status that indicates whether the vulnerability is known to be exploitable. runZero populates the Exploit status only for vulnerabilities imported after this release.
  • The dashboard now loads correctly.
  • Exporting assets to CSV no longer misaligns values.
  • Assets no longer merge incorrectly.
  • Organizations with Parents set before 3.6 have their Parents reset in this release.
  • TLS stack fingerprinting has improved.
  • Fingerprint improvements.

3.6.7

2023-03-22

  • Alert rules now trigger asset modifications correctly.

3.6.6

2023-03-22

  • Alert rules now support software and vulnerability queries.
  • Asset ownership now supports references to runZero users and groups.

3.6.5

2023-03-22

Important security fix:

  • An organization admin can no longer see the names of other organizations in the tenant without explicit access.

In addition to the security improvement above, this release includes:

  • Asset queries can now surface overlapping asset names, IP addresses, and MAC addresses across the inventory.
  • Parent/child organization behavior has improved.
  • runZero addressed a change to Chrome that caused web screenshots to fail.
  • Fingerprint improvements.

3.6.4

2023-03-21

Important security fix:

  • runZero no longer exposes limited information about an organization to cross-tenant users. This issue could have allowed an attacker who guessed the v4 UUID of an organization to view its name, description, and top-level statistics (asset count, service count, task count, etc.) without appropriate authorization. The issue was first present in version 3.6.0.

3.6.3

2023-03-20

  • Attribute searches and reports are now faster in large organizations.
  • You can now download the task log for a failed scan.
  • Hosted scans no longer ignore responses from common firewalls.
  • Daily asset expiration now records an assets-expired event with the count.
  • The task-failed event now includes information about the associated Explorer.
  • Scans can now specify which probes to use for Subnet and Host pings.
  • Validation warnings for internal IPs in the LDAP and InsightVM integrations have improved.
  • Non-unique MAC address filtering now better supports Cisco virtual MAC addresses.
  • Fingerprint improvements.

3.6.2

2023-03-16

  • Exporting assets to CSV no longer misaligns values.
  • The SSO page no longer renders off screen.
  • Enterprise customers can now scan all ports and up to a /8 at a time using the hosted scan engines.
  • The AWS integration now supports the GovCloud partition for assumed roles.
  • Fingerprint improvements.

3.6.1

2023-03-15

  • The quality of errors reported by the CLI Scanner has improved.
  • The user experience of user management has improved.
  • The user experience of organization management has improved.
  • A race condition no longer occurs during self-hosted installation.
  • Some CrowdStrike software no longer fails to import.
  • The tasks preview now shows packets sent/received.
  • The Tenable connector no longer fails intermittently for some customers.
  • Task details now render on the task overview screen.
  • Creating new projects now works for organization administrators.
  • Fingerprint improvements.

3.6.0

2023-03-13

This release rolls up the 3.5.x updates and adds the following changes.

  • Organizational hierarchies are now available. Child organizations inherit permissions from an established parent.
  • Generation of operating system CPEs has significantly improved.
  • Fingerprinting of operating systems imported from the Active Directory and VMware integrations has significantly improved.
  • Asset rescans can now include or exclude extra addresses.
  • You can now hide license warnings by user role.
  • Credentials no longer require thumbprints.
  • Asset ownership detection for the Active Directory integration has improved.
  • Paused tasks no longer fail when unpaused.
  • Large Qualys imports no longer fail.
  • The credential edit screen no longer shows incorrect credential values.
  • Fingerprint improvements.

3.5.10

2023-03-10

  • runZero now works around a bug in the latest release of Chromium-based browsers on macOS that could crash the browser.

3.5.9

2023-03-08

  • CrowdStrike tasks no longer fail when software permissions are missing.
  • runZero now completely filters bogus services from certain firewalls.
  • Accessibility improvements.
  • Fingerprint improvements.

3.5.8

2023-03-07

  • The Services, Screenshots, and Software inventory pages now include the associated site subnet tags.
  • runZero now treats IP addresses reported by CrowdStrike as primary addresses and uses them for asset correlation.
  • CrowdStrike credential verification now runs separately for each service.
  • runZero now creates CrowdStrike assets whose software entries contain Unicode escape sequences.
  • Navigating and submitting the activation form now works in Chrome on Android.

3.5.7

2023-03-06

  • The CrowdStrike connector can now import software data through Falcon Discover.
  • Email address validation has improved when you set up an email alert channel.
  • Firewalls and similar devices that respond to many non-asset IP addresses during scanning no longer produce unexpected assets in the inventory.
  • The active scans dashboard widget now navigates to the associated task.
  • Site subnet tags now appear in the dashboard Asset tags widget.
  • Fingerprint improvements.

3.5.6

2023-03-01

  • The VMware connector task page now loads correctly.
  • Assets no longer receive duplicate MSDefender attributes.
  • Fingerprint improvements.

3.5.5

2023-02-28

  • VMware asset correlation stability and performance have improved.
  • runZero now merges VMware assets across sites.
  • runZero now tracks SNMP protocol versions at the asset level.
  • SNMP services now record how they authenticated and which protocols they used.
  • The Microsoft Intune integration now handles Intune API rate limiting better.
  • Hostname extraction from malformed subjectAlternativeNames on TLS certificates has improved.
  • Site scopes with subnets ending in /32 (for IPv4) and /128 (for IPv6) now appear as CIDR entries in the subnets list instead of single IPs.
  • runZero now creates VMware assets correctly.
  • Accessibility improvements.
  • Fingerprint improvements.

3.5.4

2023-02-22

  • The Organization Overview report now shows accurate asset counts.
  • Site imports no longer fail when optional fields are missing.
  • Fingerprint improvements.

3.5.3

2023-02-21

  • A new canned query finds OpenSSH 9.1 servers which contain a memory double-free vulnerability.
  • The Microsoft Active Directory (LDAP), Azure AD, and Google Workspace integrations now perform better.
  • runZero now treats IP addresses reported by Tenable as primary IP addresses, consistent with the Rapid7 and Qualys integrations.
  • Tooltips on the dashboard asset trends graph no longer appear away from the graph.
  • Task page inspection cards no longer collapse automatically.
  • Frequently recurring tasks no longer build up.
  • Extremely large tasks no longer remain queued for processing indefinitely.
  • Service attribute reports now export correctly.
  • License requirement indicators are no longer hidden on some pages.
  • Bad org-access settings no longer prevent saving credentials.
  • runZero now recalculates the next scheduled run time for a scan.
  • Fingerprint improvements.

3.5.2

2023-02-14

  • The scanner now identifies the RDP authentication methods, including legacy and NLA, that target hosts support.
  • The scanner can now decode ISAKMP/IKEv2 replies.
  • OS fingerprinting and information extraction over RDP now work.
  • Copying or editing connector and analysis tasks now works.
  • New recurring tasks now display the correct first run date.
  • The redesigned task page received several minor bug fixes and UX improvements.
  • The redesigned task library page received several minor bug fixes.

3.5.1

2023-02-13

  • Automatic metric calculations now complete.
  • runZero now removes stale assets automatically on subsequent task runs.
  • The redesigned task page received several minor bug fixes and UX improvements.

3.5.0

2023-02-13

This release rolls up the 3.4.x updates and adds the following changes.

  • The Asset Ownership feature lets you manage asset owners across your asset inventory.
  • The task page has a new design for a better user experience.
  • A new canned query finds VMware ESXi servers that could be targets of the ongoing ESXiArgs ransomware campaign.
  • The scanner now parses running processes and services from checkmk.
  • Third-party asset correlation stability and performance have improved.
  • Fingerprint improvements.

3.4.23

2023-02-07

  • A new canned query finds Lexmark printers which may be vulnerable to CVE-2023-23560.
  • The Qualys integration now handles Qualys API rate limiting better.
  • Dashboard performance has improved.
  • The Service attributes report now performs better.
  • runZero no longer removes Tenable assets early.
  • Attribute reports no longer export incorrect data.
  • The mDNS probe now completes.
  • The scanner now supports the CoAP protocol over UDP.
  • The scanner’s interface selection logic has improved.
  • Fingerprint improvements.

3.4.22

2023-02-01

  • The scanner now supports the Minecraft Bedrock protocol.
  • The public API now includes endpoints to export directory users and groups.
  • The Last checkin column on the Registered Explorers table is now named Online status.
  • Task details pages now include a Created by column.
  • Credential forms no longer accept an invalid URL.
  • Creating new self-hosted clients no longer fails.
  • The dashboard no longer returns a 500 error when you select a site with no existing metrics.
  • Fingerprint improvements.

3.4.21

2023-01-27

  • Matching based on asset attributes is now more consistent.
  • Telnet banner capture has improved.
  • Payment information now updates correctly.
  • Searching for tasks associated with deleted sites now works.
  • Qualys assets now report the correct match.probe.
  • Fingerprint improvements.

3.4.20

2023-01-25

  • Dashboard performance has improved.
  • The Qualys integration now handles Qualys API rate limiting better.
  • A new canned query surfaces cloud compute assets with GPU hardware.
  • The scanner now supports the NDMP protocol.
  • The console now displays the correct Explorer architecture.
  • Fingerprint improvements.

3.4.19

2023-01-18

  • The asset CSV export no longer fails for some users.

3.4.18

2023-01-18

  • runZero Preview Program: the Asset Ownership feature lets you manage asset owners across your asset inventory.
  • The scanner now supports the Munin protocol.
  • Fingerprint improvements.

3.4.17

2023-01-17

  • Scans of IPv6 endpoints with the mDNS probe enabled no longer intermittently fail to complete.

3.4.16

2023-01-11

  • Queries can now limit results to only live assets.
  • The asset details page now highlights outlier attributes.
  • Fingerprint improvements.

3.4.15

2023-01-10

  • The InsightVM connector now supports longer timeouts for large sites and slower consoles.
  • The CrowdStrike connector now avoids asset duplication when processing large datasets.
  • The CrowdStrike connector now handles larger datasets with lower resource usage.
  • Asset matching based on attributes is now more consistent across lossy networks.
  • runZero no longer matches excluded scan targets or marks them as offline.
  • Site imports now automatically trim trailing whitespace from CIDRs.
  • The scanner now supports the MySQL X protocol.
  • Fingerprint improvements.

3.4.14

2023-01-09

  • CrowdStrike imports no longer create duplicate assets.

3.4.13

2023-01-07

  • Very large CrowdStrike syncs now complete.

3.4.12

2023-01-05

  • runZero now creates new offline assets correctly.
  • Large InsightVM imports no longer fail.
  • Paused tasks no longer fail when unpaused.

3.4.11

2023-01-05

  • You can now edit credentials after saving them.
  • You can now verify credentials against services to surface upstream configuration issues.
  • The Subnet utilization report now performs better, includes subnets by site, and includes assets outside the scope of a defined site subnet.
  • Asset inventory searches with the mac keyword now support the Cisco MAC address format and additional delimiter characters.
  • Non-unique MAC address filtering has improved, including for Fortinet virtual adapters, Juniper switches, and Project Calico virtual interfaces.
  • CrowdStrike vulnerability imports no longer fail because of session expiration.
  • runZero no longer duplicates assets.
  • RDNS results no longer mark assets as online.
  • runZero now supports the L2TP, Dahua DHIP, KXNnet, Webmin, and Playstation UDP protocols.
  • Fingerprint improvements.

3.4.10

2022-12-23

  • Fingerprint improvements.

3.4.9

2022-12-22

  • The CrowdStrike connector no longer fails when Spotlight permissions are missing.
  • Fingerprint improvements.

3.4.8

2022-12-21

  • Manually merging some assets no longer fails.
  • runZero now shows correct project expiration information.
  • Fingerprinting of Huawei, Hikvision, Fortinet, and WatchGuard devices over SNMP has improved.
  • Fingerprint improvements.

3.4.7

2022-12-19

  • Service exports now include a service_id field.
  • Self-hosted installations no longer accumulate excess temporary files.
  • Asset attribute imports now report all results.
  • Fingerprint improvements.

3.4.6

2022-12-19

  • The dashboard now loads faster for customers with many sites and subnets.

3.4.5

2022-12-18

  • You can now save new scans and recurring scans even when the current license is exceeded.
  • Confirmation dialogs for removal actions are now more consistent across the product interface.
  • Modifying a recurring scan with a past start date no longer immediately launches a task.
  • The latest Windows Explorers now embed npcap.
  • Fingerprint improvements.

3.4.4

2022-12-16

  • Self-hosted installations of runZero can now include custom JavaScript in UI web pages.
  • Amazon Web Services account IDs now appear in a new per-asset attribute.
  • Importing Nessus files without vulnerability details now works better.
  • You can now filter the organization and client switching dropdown menus when there are more than 5 organizations or clients.
  • The scan setup page no longer scrolls to the right during the product tour.
  • Integrations using the Microsoft Graph API no longer have their token expire between paged responses.
  • mDNS service discovery has improved.
  • Fingerprint improvements.

3.4.3

2022-12-14

  • Importing from Tenable, InsightVM, and Qualys no longer duplicates assets.
  • Fingerprint improvements.

3.4.2

2022-12-13

  • Registered API clients now show the user that created them.
  • Microsoft 365 Defender tasks now report details on failed upstream API calls.
  • The help text on Google Workspace credentials has improved.
  • Dashboard category report formatting has improved.
  • Shodan imports no longer fail.
  • InsightVM connector options now persist correctly.
  • Fingerprint improvements.

3.4.1

2022-12-12

  • runZero now processes wireless entries correctly.
  • Fingerprint improvements.

3.4.0

2022-12-12

This release rolls up the 3.3.x updates and adds the following changes.

  • A new canned query finds Cisco 7800/8800 series IP phones which may be vulnerable to CVE-2022-20968.
  • The AWS integration now includes an option to automatically remove assets no longer reported by AWS.
  • You can now authenticate with runZero APIs using OAuth 2.0 client credentials.
  • The edr.name asset attribute now updates when a runZero scan no longer detects the EDR agent.
  • You can now stop tasks during the data gathering and processing phases.
  • The site import and export CSV format is now simpler.
  • Connector task processing now performs better.
  • Tables in the Site comparison report, analysis report results, and SSO group mappings now perform better.
  • Fingerprinting coverage of Google Workspace assets has improved.
  • Additional Fingerprint improvements.

3.3.8

2022-12-07

Important security fix:

  • The Your team > Current organization view no longer shows cross-tenant “no access” role users. This issue only applied to the cloud-hosted version of the runZero platform. The affected build was live for slightly more than two hours. Customers affected by this issue will receive a detailed notice at the email addresses associated with their superuser accounts.

3.3.7

2022-12-07

  • runZero fixed a bug that could prevent an Explorer from running scans with specific network configurations.

3.3.6

2022-12-07

  • The CrowdStrike integration now imports vulnerabilities when CrowdStrike Spotlight is enabled for the API key.
  • You can now disable the creation of new assets from third-party integrations.
  • The task overview page now loads faster.
  • Asset terminology is now more consistent.
  • The site import CSV format has improved.
  • Third-party integrations now merge assets more consistently.
  • The CLI Scanner now handles the --api-url parameter better.
  • The DELETE API method for bulk asset deletion is now deprecated.
  • The public API now includes an endpoint to check the platform health.
  • runZero now reports OS EOL dates for Windows 11.
  • Fingerprinting of HomeKit devices has improved.
  • A new canned query finds MegaRAC BMC firmware.
  • Recurring tasks no longer build up.
  • The Organization asset export API now works correctly.
  • Fingerprint improvements.

3.3.5

2022-11-30

  • Third-party data sources now import faster.
  • The License information page now displays the correct project asset count.

3.3.4

2022-11-28

  • Concurrent task processing is no longer delayed.

3.3.3

2022-11-28

  • The --ldap-thumbprints flag resolves an issue that could cause the command-line scanner to skip LDAP enumeration.
  • The scheduler now delays recurring tasks if the previously completed task has not yet started processing.
  • The backend now processes concurrent tasks for separate sites within the same organization when possible.
  • Self-hosted customers can now configure concurrent task processing with the RUNZERO_CRUNCHER_INSTANCES option.
  • Third-party integrations now merge more accurately when using IP addresses as the match key.
  • runZero now fingerprints Microsoft Intune and Azure Active Directory assets more accurately.
  • VMware ESXi instances now display OS end-of-life dates based on version.
  • Fingerprint improvements.

3.3.2

2022-11-21

  • Tag searches now complete when thousands of tags are in use.
  • The scanner now supports a configurable ToS/Traffic Class field in the advanced configuration.
  • The inventory view now includes additional operating system and hardware icons.
  • Explorer and CLI Scanner binaries are now approximately 5MB smaller.
  • New LDAP credentials now auto-populate the discovered port.
  • Printer detection has improved.
  • Fingerprint improvements.

3.3.1

2022-11-20

  • The Microsoft Defender integration now merges assets more completely.
  • The AWS EC2 integration now has an option to include Stopped instances.
  • GCP CloudSQL assets no longer import partially.
  • The “All Organizations” view now more accurately handles limited user permissions.
  • Searching and sorting by the asset first seen and last seen columns is now faster.
  • Restarting an import no longer duplicates vulnerabilities.
  • Fingerprint improvements.

3.3.0

2022-11-14

This release rolls up the 3.2.x updates and adds the following changes.

  • runZero Professional and Enterprise customers can now sync assets from Google Workspace.
  • runZero Platform customers can now sync users and groups from Google Workspace.
  • The user interface tables for Organizations, Sites, Explorers, and Teams have a new design.
  • The “All Organizations” view is now available to restricted users with a filtered scope.
  • Qualys VMDR and InsightVM credentials no longer require live validation.
  • Fingerprint improvements.

3.2.11

2022-11-08

  • The subnet utilization report now supports filtering by site.
  • CSV export of assets now includes the same hostname information as the inventory view.
  • Up-to-date ARM64 builds of the standalone scanner are now available.
  • The account API endpoint for creating organizations now accepts the documented argument types.
  • Merging two assets now correctly updates the date of the newest MAC address for the resulting asset.
  • Disabling all scan probes now disables the SNMP probe.
  • Third-party credentials now work when using TLS thumbprints or the insecure connection option with a public URL.
  • Fingerprint improvements.

3.2.10

2022-11-04

  • Service Provider information now displays with a default domain before SSO settings are configured.
  • Scanning from macOS hosts that have certain EDR solutions installed now performs better.
  • GCP imports no longer fail to complete in some cases.
  • TLS fingerprinting has improved.
  • Fingerprint improvements.

3.2.9

2022-11-03

  • The AWS integration now includes an option to delete AWS-only assets that were not seen in the most recent import.
  • The Qualys integration now includes an option, disabled by default, to import unscanned assets.
  • Large Qualys imports now process faster.
  • The scan configuration and connector configuration pages now list Explorers alphabetically.
  • Service Inventory searches launched from the Asset details page now work correctly.
  • Tanium agent detection now sets the edr.name attribute.
  • Fingerprinting of OpenSSL, GnuTLS, and Windows TLS stacks has improved.

3.2.8

2022-11-01

  • TLS probes now complete.

3.2.7

2022-11-01

  • Assets and services now have a tls.stack attribute that tracks the TLS software provider and version.
  • A new canned query finds OpenSSL 3.0.x with client certificate authentication.
  • The Intune integration now performs better when importing a large number of users and devices.
  • runZero users who log in via SSO now see the terms and conditions acceptance dialogue.
  • Site metrics now update correctly.
  • Fingerprinting of OpenSSL versions has improved.
  • Apple ecosystem OS Fingerprint improvements.

3.2.6

2022-10-30

  • The scanner now reports OpenSSL versions via TLS fingerprinting.
  • The scanner now reports Tanium agent instances on the network.
  • The scanner now reports additional detail for SSLv3 services.
  • The Intune integration now completes long-running tasks.
  • The GCP integration now returns all assets.
  • A recurring integration no longer runs again before the previous task finishes.
  • Fingerprint improvements.

3.2.5

2022-10-26

  • You can now configure GCP credentials to import assets from multiple projects.
  • Importing assets from Microsoft Intune no longer fails.
  • Importing assets from Microsoft 365 Defender no longer fails.

3.2.4

2022-10-24

  • Scan tasks now process faster for SaaS and self-hosted customers.
  • Explorers now use less baseline memory.
  • Importing assets from Microsoft 365 Defender no longer fails.
  • Asset links no longer break.
  • Fingerprint improvements.

3.2.3

2022-10-20

  • Error handling of misconfigured fingerprints has improved, which reduces Explorer and scanner crashes.

3.2.2

2022-10-20

  • The Assets and Vulnerabilities inventory pages now support the has_os_eol and has_os_eol_extended search keywords.
  • Services with conflicting virtual hosts no longer have missing service data.
  • Imported directory groups now show accurate user counts.
  • Tooltips now display correctly.
  • Middle/right click “open in new tab” navigation now works.
  • Fingerprint improvements.

3.2.1

2022-10-18

  • The error message indicating that an AWS integration credential has insufficient permissions has improved.
  • The asset details page once again includes the “last seen” link to the most recent scan details.
  • Azure AD imports no longer fail.

3.2.0

2022-10-17

This release rolls up the 3.1.x updates and adds the following changes.

Important security fixes:

  • Our annual third-party security assessment identified three stored cross-site scripting vulnerabilities, which are now fixed.

In addition to the security improvement above, this release includes:

  • runZero Platform customers can now sync assets from Microsoft 365 Defender.
  • runZero Platform customers can now sync assets from Microsoft Intune.
  • The Azure AD integration now imports additional assets and no longer requires a Microsoft Intune license.
  • You can now configure the Azure AD integration to optionally import assets, users, and groups.
  • The Active Directory integration service options are now more consistent.
  • Custom queries can now include directory users and groups.
  • The Organization Overview report now contains summary information for directory users and groups when present.
  • SNMPv2 options now live on the Probes tab (now labeled Probes and SNMP).
  • The SNMP toggle switch now correctly reflects whether the “Use defaults” option on the Probes tab overrides it.
  • The asset details pages have a new design that performs better.
  • The asset details pages now include a “last loaded” time indicator and a way to refresh the page data.
  • The asset details page now includes recent users from Microsoft Intune, SentinelOne, and CrowdStrike.
  • runZero now sends alert notifications, user invitations, and password reset emails from the runzero.com domain name instead of rumble.run.
  • The rumblectl utility now has a diagnostics command that runs or saves a diagnostic script, so self-hosted customers can collect information for runZero support.
  • Repeated imports of task data that includes directory users and groups now work.
  • runZero no longer enables subnet sampling and screenshots for all scan tasks.
  • Fingerprint improvements.

3.1.13

2022-10-11

  • Inventory pages now have “all” and “none” column visibility options.
  • Fingerprint improvements for Fortinet products that may be affected by CVE-2022-40684.

3.1.12

2022-10-07

  • The Tenable.io integration now supports a configurable API URL.
  • The Active Directory integration now supports optional import of assets, users, and groups.
  • The minimum TLS version for new Active Directory credentials has increased from TLS 1.0 to TLS 1.2, with a configurable option to support older TLS versions.
  • Modifying the maximum concurrent scans setting now works.
  • The credentials page now shows an accurate task count.
  • Searching by credential on the tasks page now returns accurate results.
  • runZero now reports credential reuse accurately.
  • Certain browser extensions no longer prevent configuring scans.

3.1.11

2022-10-06

  • Reusing SNMP credentials for recurring scans now works.

3.1.10

2022-10-03

This release contains important security fixes:

  • The scan templates view no longer allows stored cross-site scripting. An authenticated but unprivileged user could have exploited this issue to take over the session of another authenticated user.
  • The SSO group mappings view no longer allows stored cross-site scripting. An authenticated superuser could have exploited this issue to take over the session of another authenticated user.

3.1.9

2022-09-30

  • Initializing a scan no longer fails in some cases.

3.1.8

2022-09-30

This release contains an important security fix:

  • The team view no longer allows stored cross-site scripting. An authenticated but unprivileged user could have exploited this issue to take over the session of another authenticated user.

In addition to the security improvement above, this release included a separate bug fix:

  • Recurring scans no longer fail to save in some cases.

3.1.7

2022-09-29

  • The Assets inventory now supports the os_eol_expired search keyword.
  • runZero now handles Qualys concurrency and rate limiting better.
  • Self-hosted deployments can now use the rumblectl command to configure additional superusers.
  • runZero now sets the first_seen timestamp.
  • Large Qualys imports no longer fail.
  • Azure AD users and groups now import without an active Intune license.
  • Azure AD users and groups no longer import partially.
  • The report.changed value now works in notification rule templates.
  • Authenticating to the API with client tokens now works.
  • Fingerprint improvements.

3.1.6

2022-09-27

  • Non-recurring Organization Overview reports now send email notifications.
  • Relative time searches now accept negative numbers.
  • Scan tasks and templates now allow empty SNMPv1 and SNMPv2 community strings.
  • Credential validation now prevents common misconfigurations.
  • Support for Explorer hosts running virtual machines has improved.
  • MAC vendors now display more consistently on inventory datagrids.
  • Tooltips on datatable icons have improved.
  • Insight queries for hosted zones no longer fail.
  • The Shodan integration asset-mode query now works correctly.
  • MAC vendor names are no longer cut off in datagrids.

3.1.5

2022-09-22

  • The task change report schema now supports changes to directory users and groups.
  • Error messages related to API tokens have improved.
  • Shodan services no longer go missing.
  • runZero no longer imports Active Directory Managed Service accounts as assets.
  • Fingerprint improvements.

3.1.4

2022-09-19

  • Asset exports with many subnets now perform better.
  • Asset exports now filter subnet results to those containing the assets’ addresses.
  • LDAP connector and probe logging has improved.
  • The Users search now supports the group_count keyword.
  • Connector forms now group their inputs better.
  • The Switch Topology report no longer omits switches in certain situations.
  • Exporting assets from sites with many assets and/or subnets no longer returns a 500 error.
  • UI elements no longer become unresponsive.
  • Fingerprint improvements.

3.1.3

2022-09-14

  • Some service values no longer fail to save.

3.1.2

2022-09-14

  • The directory groups inventory page now loads faster.
  • Exported assets no longer receive all subnet tags.
  • Shodan services no longer go missing.
  • Azure AD imports no longer fail for certain configurations.
  • Exports are no longer excessively large.
  • The task log no longer obscures task errors.
  • Fingerprint improvements.

3.1.1

2022-09-13

  • The inventory screens now load faster, including multi-page selection.
  • The Users page now supports the has_group search keyword.
  • Fingerprint improvements.

3.1.0

2022-09-12

This release rolls up the 3.0.x updates and adds the following changes.

  • runZero Platform customers can now sync assets from Shodan.
  • runZero Platform customers can now sync assets from Azure Active Directory.
  • runZero Platform customers can now sync assets from Microsoft Active Directory via LDAP.
  • Connector tasks can now optionally run from an Explorer on a customer’s network.
  • The Events datatable has a new design and now performs better.
  • The Qualys integration now returns a more descriptive error message when the Qualys API rate-limits it.
  • Network File System (NFS) protocol detection on TCP ports has improved.
  • Editing certain probe options now works when you configure a scan.
  • Fingerprint improvements.

3.0.24

2022-09-10

  • The browser no longer freezes when viewing assets with many attributes.
  • Fingerprint improvements.

3.0.23

2022-09-08

  • Web screenshots now use at most 16 concurrent processes.
  • Web screenshots now run concurrently on arm64 macOS systems.
  • The GCP integration now handles errors better.
  • Input hostname parsing has improved.
  • Dashboard insights now render correctly.

3.0.21

2022-09-07

  • Dashboard insights now show at most three rows.
  • Fingerprint improvements.

3.0.20

2022-09-07

  • runZero no longer skips minimal assets.

3.0.19

2022-09-07

  • The dashboard now shows the correct insight counts.
  • Fingerprint improvements.

3.0.18

2022-09-06

  • Attributes and screenshots no longer disappear from offline assets.
  • Fingerprint improvements.

3.0.17

2022-09-02

  • Fingerprint improvements.

3.0.16

2022-09-02

  • Fingerprint improvements.

3.0.15

2022-09-01

  • Certain organization and export tokens now work.
  • Fingerprint improvements.

3.0.14

2022-08-31

  • The CrowdStrike connector now has a new optional filter.
  • The Qualys connector now performs better.
  • Alert templates now include event details by default.
  • Password reset emails now include the token.
  • Fingerprint improvements.

3.0.12

2022-08-29

  • CSV exports now include task statistics for asset counts, which you can also use in task searches.
  • The new license-limit-exceeded event alerts when the live asset count exceeds an account’s license.
  • The new ldap.notes service attribute provides user-friendly representations of well-known discovered LDAP OIDs.
  • Queries no longer time out.
  • Large Qualys imports no longer time out.
  • Fingerprint improvements.

3.0.11

2022-08-24

  • Qualys data from large sites now imports fully.
  • runZero fixed a bug that slowed exports and job processing.
  • Fingerprint improvements.

3.0.10

2022-08-22

  • The Tenable integration now excludes terminated and deleted assets.
  • Formatting of _asset.match values is now correct.
  • Internal tasks for metrics calculation no longer generate scan-completed events.
  • Reports for specific asset attributes now work.

3.0.9

2022-08-19

  • Dashboard metrics now account for unscanned assets imported from third-party integrations.
  • Internal recurring tasks for metrics calculation no longer show in the recurring task count.
  • Fingerprint improvements.

3.0.8

2022-08-19

  • Asset attributes now export correctly.
  • Fingerprint improvements.

3.0.7

2022-08-17

  • CrowdStrike tasks now process correctly.

3.0.6

2022-08-17

  • Foreign asset data now processes faster.
  • Some asset attribute reports no longer fail to generate.
  • Fingerprint improvements, including AIX OS and vCenter, Avaya, and Proofpoint appliances.

3.0.5

2022-08-12

  • Offline self-hosted platform updates no longer fail.
  • The timeout for Qualys connection tasks is now 5 minutes instead of 60 seconds.
  • Fingerprint improvements.

3.0.4

2022-08-11

  • The MFA page now tells users that they can continue to use the old rumble.run domain until they re-enroll their authenticators for the new runzero.com domain.
  • Font rendering in Safari browsers now matches Firefox and Chrome.
  • The queries table received UI improvements.
  • Selected assets and asset search results now export correctly.
  • Setting up recurring tasks now works for starter accounts.
  • Organization selection now works correctly when a default organization is set.
  • SSH probes no longer occasionally deadlock.

3.0.3

2022-08-09

  • Fingerprint improvements.

3.0.2

2022-08-09

  • WebAuthn now registers correctly on console.runzero.com.
  • The topology on the asset details page is no longer mangled.

3.0.1

2022-08-08

  • Inventory searches now support “runZero” as an asset source type.
  • The default probes selector now works correctly.

3.0.0

2022-08-08

This release rolls up the 2.15.x updates and adds the following changes.

  • Rumble is now runZero, and the product UX has changed to match.
  • runZero Platform customers can now sync asset and vulnerability data from Qualys VMDR.
  • The redesigned Queries datatable now performs better.
  • The Software and Vulnerabilities datatables now have a “view more details” button.
  • Users can now specify a Default Organization in the profile settings page.
  • Outlier calculations and insight queries now run automatically as daily analysis tasks.
  • You can regenerate outlier calculations and insight queries on demand from the Metrics menu on the Tasks overview page.
  • Merging assets with foreign attributes from the same source now retains all sets of foreign attributes.
  • Software entries imported from SentinelOne and Tenable now report their service addresses.
  • runZero now includes a custom query that finds DrayTek Vigor routers.
  • You can now filter the Asset and Service attributes reports by Site.
  • The Organization API now supports asset merging.
  • The services view is now up to 40% faster for organizations with large numbers of assets.
  • The “Lambda instances” option in the AWS Configuration UI now persists.
  • runZero now directs external users to their main SSO login page correctly.
  • Operating system fingerprinting for cloud assets (AWS, Azure, and GCP) has improved.
  • Fingerprint improvements.

2.15.11

2022-08-01

  • Stale software entries are no longer retained.
  • The Insights table no longer renders oversized buttons.
  • Hostname-based merging for Rapid7 imports has improved.
  • Fingerprint improvements for some FortiNet, FrontRow, and Synology assets.

2.15.10

2022-07-29

  • API keys are now hidden by default, and you can copy them to the clipboard with a click.
  • The Route Pathing report now performs better and aborts early in out-of-memory scenarios.
  • The users endpoint of the organization API no longer returns a 500 error.
  • Tooltips no longer persist on the screen.
  • Printer detection has improved.
  • Fingerprint improvements.

2.15.9

2022-07-28

  • The vulnerabilities table no longer appears empty when sorted by the details column.
  • The scanner now fingerprints and reports a much wider range of ePO/McAfee Agent services.
  • Fingerprint improvements.

2.15.8

2022-07-26

  • The HTTP probe no longer aborts early.

2.15.7

2022-07-26

  • Processing of very large Rapid7 imports has improved.
  • Rapid7 imports now populate software.
  • OS fingerprinting now uses Rapid7 fingerprints when Rapid7 is the only data source.
  • Rapid7 foreign attributes are now clearer.
  • Censys data now populates services.
  • Vulnerability details are now available on the Vulnerability Inventory screen.
  • Extraction of Microsoft Windows information from web services has improved.
  • Extraction of information from NetBIOS has improved, including new detection of Domain Controller roles.
  • Hosted Zone scan limits are now higher.
  • The runZero Explorer now logs configuration file loading and reports any syntax errors.
  • The asset tag update and bulk asset tag update APIs now work as documented.
  • All org admins can now delete other users.
  • The User Last Activity date now shows the correct date.
  • Fingerprint improvements.

2.15.6

2022-07-21

  • Large Nexpose and Tenable imports now process faster.
  • Hostname identification from LDAP responses has improved.
  • Filtering of non-unique MAC addresses has improved.
  • SNMP data handling is now more consistent for some classes of devices.
  • Connector tasks can now run in parallel while connecting to third-party APIs.
  • Organization administrators can now delete other users.
  • Inventory multi-select operations now work correctly.
  • Inventory column selection now works.
  • Tasks no longer stall indefinitely.
  • Fingerprint improvements.

2.15.5

2022-07-18

  • Processing of very large scans has improved.
  • The software and vulnerabilities tables now perform better.
  • Fingerprint improvements.

Note: The upgrade may take up to an hour for large self-hosted deployments.

2.15.4

2022-07-14

  • The API now returns all attributes, sources, and subnets for a single asset.
  • The runZero Explorer now runs as a delayed auto start process on Windows, which makes it more reliable after reboots.
  • The Organization Overview report now includes navigation links back to the top of the report.
  • License warning banners now work correctly.
  • macOS Explorer upgrades on M1 systems now work correctly.
  • Importing VMware assets now works.
  • Fingerprint improvements.

2.15.3

2022-07-13

  • The InsightVM integration now supports larger imports.
  • When a templated task fails because an Explorer is unavailable, copying the failed task now keeps its link to the template.
  • The Overview report no longer shows blank addresses for Unscanned assets.
  • Scan copies are no longer assigned to a different site.
  • OS icons now show on inventory tables.

2.15.2

2022-07-12

  • Click-to-copy works again for MAC addresses displayed on inventory pages.
  • Asset export query errors now return an HTTP 400 status code with a descriptive body.
  • Copying and updating Nessus connector tasks now works.
  • Fingerprint improvements.

2.15.1

2022-07-12

  • The External Asset Report no longer errors when no assets are present.
  • The Export API now returns a 400 instead of a 500 for invalid queries.
  • Some Explorer updates no longer fail on Windows.

2.15.0

2022-07-11

This release rolls up the 2.14.x updates and adds the following changes.

  • Rumble Enterprise customers can now sync asset and vulnerability data from the InsightVM API and upload data from Nexpose XML Export files.
  • Rumble Enterprise customers can now sync asset, software, and vulnerability data from the Nessus Professional API.
  • Rumble Enterprise customers can now generate an External Asset report.
  • You can now populate scan scopes with external domains and IP addresses.
  • All inventory tables now have a new design and perform better when displaying a large number of assets.
  • Integration tasks are now called “Connector” tasks instead of “Import” tasks, and they can run in parallel while connecting to third-party APIs.
  • New reports for software and vulnerabilities are now available.
  • You can now configure the self-hosted platform’s web server HTTP timeouts with environment variables.
  • JSON exports of task information now work correctly.
  • Fingerprint improvements.

2.14.11

2022-07-06

  • Many vulnerability records no longer delay task processing.

2.14.10

2022-07-01

  • The API now includes an endpoint for Nessus imports.
  • The scan engine now sets additional attributes for TLS certificates.
  • The site edit page is now much faster for sites with large numbers of subnets.
  • Nessus file imports now include assets that are missing certain date/time fields.
  • Changing the start time of a recurring task now saves successfully and queues an immediate run if appropriate.
  • Date range queries now work on Tenable/Nessus attributes. (This requires re-importing the relevant data.)
  • Boolean search terms now work with the Vulnerabilities table.
  • Importing assets from SentinelOne no longer fails for some customers.
  • File imports now process Censys Search data correctly.
  • Fingerprint improvements for KVMs, routers, IP cameras, and other network management equipment.
  • Links to the query language documentation are now up to date throughout the product.

2.14.9

2022-06-27

  • Merging of AWS, Azure, and GCP assets imported from Tenable.io has improved.
  • SentinelOne credential creation now works correctly.
  • Tasks updated via the API no longer receive an incorrect agent ID or template ID.
  • The asset route pathing report now renders the source name properly in the report heading.

2.14.8

2022-06-24

  • Customer address information is now validated correctly.
  • SSO settings now update correctly.

2.14.7

2022-06-24

  • The self-hosted platform install now supports Rocky Linux.
  • The scan engine no longer causes unexpected printer output.
  • The e-commerce checkout now works with non-US addresses.
  • Fingerprint improvements for Nokia SR OS and Cisco RV routers.

2.14.6

2022-06-23

  • The Account API now supports scan template management.
  • The scan engine now discovers additional services, including Elasticsearch, Logstash, and Prometheus.
  • Fingerprint improvements for several operating systems and for products by Aruba Networks, Axis, MikroTik, and Nokia.
  • Query “address” keywords now support CIDR notation.

2.14.5

2022-06-16

  • The scan engine now sets additional attributes for TLS certificates.
  • SSO configuration now skips IdP-provided encryption certificates during setup.
  • Explorers now initialize faster.
  • The Explorer service no longer times out on startup.
  • Explorers deployed on macOS now transfer between organizations successfully.
  • Deleting a site no longer occasionally creates an unnecessary site.
  • User last activity dates now appear in the same time zone as the account creation date.
  • Fingerprint improvements.

2.14.4

2022-06-15

  • The Tenable integration now includes an option to import unscanned assets, which is disabled by default.
  • Merging of Tenable/Nessus assets into the Rumble inventory has improved.
  • Nessus imports now set first_seen and last_seen dates more accurately.
  • The Tenable integration now gives more informative error messages when a task fails because of invalid API keys or missing permissions.
  • New software and vulnerabilities reports are now available.
  • Hovering over the Click To Copy button on the Asset details page now shows a preview of software and vulnerability attributes.
  • The vulnerabilities table now performs better.
  • The scan engine now flags TLS services with self-signed certificates and untrusted CAs.
  • CSV exports of asset information now include OS EOL and extended OS EOL dates.
  • An administrator without access to specific organizations can no longer create credentials limited to those organizations.
  • Fingerprinting of Tenable/Nessus assets imported with a severity setting of low or higher has improved.
  • Fingerprint improvements.

2.14.3

2022-06-10

  • Rumble Enterprise customers can now search inventory by hosted zone.
  • A new fingerprint for the Cockpit application includes additional Linux OS fingerprinting capability.
  • Fingerprint improvements for several operating systems and for products by 2N, Grandstream, Huawei, and Wago.
  • Manually merging assets no longer ignores software and vulnerabilities.
  • Task configuration now shows the list of available Explorers.
  • Contacting support through the console no longer fails.
  • Some Fortinet Web Filter replies that previously escaped filtering are now filtered.
  • Additional Fingerprint improvements.

2.14.2

2022-06-07

  • Hosted scans now include additional validation for scan targets.
  • Tenable.io credentials now receive additional validation.
  • Asset inventory column selection and ordering now persist between queries.
  • Connector tasks now obey the start time set when they are created.
  • Hosted scans no longer time out after an hour.
  • You can now view third-party attributes for assets without Rumble attributes.
  • First seen and last seen dates for assets imported from Tenable.io and Nessus are now correct.
  • Copying a task no longer carries over the task’s error message.
  • Fingerprint improvements.

2.14.1

2022-06-06

  • The Tenable connector no longer fails to import large sites.

2.14.0

2022-06-06

This release rolls up the 2.13.x updates and adds the following changes.

  • Rumble Enterprise customers can now run scans using Rumble-hosted Explorers.
  • Rumble Enterprise customers can now sync asset, software, and vulnerability data from the Tenable.io API and upload data from Nessus scan files.
  • The Azure integration can now import Azure Function Apps.
  • The ServiceNow integration can now export asset subnet tags.
  • Fingerprint improvements.

2.13.7

2022-05-27

  • The size limit for cloud-hosted scans is now 10GiB, up from 6GiB.
  • Searching software by version now works.
  • Input fields for unselected credential types no longer appear.
  • Fingerprint improvements.

2.13.6

2022-05-24

  • Scan and site scope and exclusion fields now accept asn4:<id> and country4:<2-letter ISO code>.
  • Bogus results caused by firewall interference are now automatically ignored in more cases.
  • Single organization administrators can now manage non-global credentials for their organization.
  • The Organization Overview report now includes asset tags when available.
  • Fingerprint improvements.

2.13.5

2022-05-19

  • The self-hosted installer now completes successfully.

2.13.4

2022-05-19

  • The Censys integration now reports the observed_at, extended_service_name, perspective_id, and source_ip for all services.
  • Fingerprint improvements.

2.13.3

2022-05-13

  • The size limit for cloud-hosted scans is now 6GiB, up from 4GiB.
  • Fingerprint improvements.

2.13.2

2022-05-11

  • Scan templates no longer ignore the scan configuration for some users.
  • The “TLS serial numbers” report now runs properly.
  • Fingerprint improvements.

2.13.1

2022-05-09

  • Event processing no longer terminates early.

2.13.0

2022-05-09

This release rolls up the 2.12.x updates and adds the following changes.

  • You can now view asset information in aggregate across all organizations in the dashboard and asset inventory.
  • The AWS integration now imports Lambda instances.
  • The Azure integration now imports load balancers and AzureSQL instances.
  • The GCP integration now imports load balancers and CloudSQL instances.
  • Self-hosted installations now use an in-process task scheduler instead of system cronjobs for maintenance tasks.
  • Fingerprint improvements.

2.12.12

2022-05-03

  • The service no longer reloads during task processing.
  • Fingerprint improvements.

2.12.11

2022-05-02

  • The Rumble inventory now tracks software associated with assets.
  • Rumble Enterprise customers can now sync asset and software data from the SentinelOne API.
  • The AWS integration now imports RDS instances.
  • The Azure integration now imports scale set virtual machines.
  • AWS credentials for STS assume role workflows now require only a role name.
  • When creating a credential, you can now toggle whether all organizations can access it.
  • External invitation emails no longer intermittently omit their activation codes.
  • The credentials page now loads faster.
  • An organization’s users page now displays group members correctly.
  • Fingerprint improvements.

2.12.10

2022-04-19

  • You can now apply, update, and delete tags in bulk using the API.
  • The RFC 1918 Coverage Report is now much faster.
  • Fingerprint improvements.

2.12.9

2022-04-18

  • Assets with external IP addresses now receive tags for their geographic location and ASN when available.
  • The CrowdStrike and Miradore integrations can now run as scan probes from the console and scanner CLI.
  • Deleting services from the services inventory no longer fails.
  • Certain analysis tasks no longer error when an asset-query-results rule is enabled.
  • Fingerprint improvements.

2.12.8

2022-04-14

  • New CrowdStrike credentials now save correctly.

2.12.7

2022-04-14

  • You can now generate the Organization Overview report and email it to chosen recipients on a recurring schedule.
  • The organization users table now displays effective access for each user.
  • Adding users to groups no longer fails.
  • Fingerprint improvements.

2.12.6

2022-04-12

  • VMware instances with non-unique UUIDs are now handled correctly.
  • Primary addresses no longer come from IPs outside the scan scope.
  • Windows OSes are now reported correctly for VMware.
  • The CrowdStrike integration now generates downloadable task data that you can use to import CrowdStrike assets.
  • You can now truncate syslog to a specified line length.
  • Fingerprint improvements.

2.12.5

2022-04-08

  • The scan configuration site scope warning now accurately reflects the site default scope.
  • Searching for bssid wireless values now works.
  • Fingerprint improvements.

2.12.4

2022-04-07

  • The Scan menu now provides an option to run a new scan using an existing template.
  • The Alert Rules form now handles very long queries in the Test Query action.
  • Dashboard stats for multi-site organizations are now correct.
  • Reports for certain AWS attributes no longer show empty results.
  • Stale SNMP credentials no longer stay associated with an asset.
  • The self-hosted rumblectl update command now also applies content updates.
  • Fingerprint improvements.

2.12.3

2022-04-06

  • The AWS connector now tags each instance with the associated AWS account email.
  • The CrowdStrike connector now handles API service outages more gracefully.
  • The Organization Overview report is now visible in Rumble Professional.
  • The scan engine no longer logs a debug message related to LDAP.
  • The asset details screen no longer shows visual errors.
  • Fingerprint improvements.

2.12.2

2022-04-05

  • The Scan menu now links to Scan Template selection with a search interface.
  • The individual probe options in the Scan Config screen are now consistently sorted.
  • The dashboard no longer shows partial stats for multi-site organizations.
  • Self-hosted content updates no longer fail when /opt is on a different file system from /tmp.
  • Duplicate pre-built queries no longer appear in self-hosted installations.
  • Fingerprint improvements.

2.12.1

2022-04-05

  • Saving scan templates no longer fails.
  • Fingerprint improvements.

2.12.0

2022-04-04

This release rolls up the 2.11.x updates and adds the following changes.

  • A new print-friendly Organization Overview report is now available.
  • A new integration with the Google Cloud Platform is now available.
  • You can now invite external users to the cloud console.
  • Scan templates are now available.
  • Self-hosted instances now sync pre-built queries from the cloud.
  • The scan engine now supports the Kerberos and LDAP protocols.
  • Fingerprint improvements.

2.11.16

2022-03-29

  • Exact = attribute matches now work.

2.11.15

2022-03-28

  • The self-hosted platform now supports scan imports larger than 4GiB.

2.11.14

2022-03-28

  • The inventory search now supports a wider range of UTF-8 input for search patterns.
  • The API now handles temporary maintenance-related errors more consistently.
  • Fingerprint improvements.

2.11.13

2022-03-25

  • Long-running export requests for large organizations now time out after 90 minutes instead of 30 minutes.
  • Fingerprint improvements.

2.11.12

2022-03-22

  • Fingerprint improvements.

2.11.11

2022-03-20

  • The update process for Explorers on the Windows platform is now more resilient to EDR/AV interference.

2.11.10

2022-03-19

  • Fingerprint improvements.

2.11.9

2022-03-17

  • Some metric queries no longer time out.

2.11.8

2022-03-17

  • Tasks in the same organization no longer process concurrently.
  • Fingerprint improvements.

2.11.7

2022-03-16

  • Large CrowdStrike imports no longer time out.

2.11.6

2022-03-16

  • Fingerprint improvements.

2.11.5

2022-03-15

  • The self-hosted CLI now supports setting the superuser role and resetting MFA.
  • The scan engine now detects the Veeam Distribution Service API.
  • You can now use {{organization.name}} in certain organization alert templates.
  • Login events now display in the Events view.
  • sso-login events are now recorded even when the connection terminates mid-event.
  • Update requests no longer interrupt scans.
  • Outlier search result links are now correct.

2.11.4

2022-03-11

  • Alert rule queries now account for assets found through integrations.
  • The console now correctly filters bogus ARP replies over a reasonable threshold.

2.11.3

2022-03-11

  • The self-hosted rumblectl set-role command now also supports setting the superuser role.
  • The self-hosted rumblectl reset command now also resets the MFA token.
  • The Asset CSV import now supports cell widths of up to 16,384 characters (from 1,024).
  • The self-hosted server now restarts in out-of-memory conditions.
  • The Network Switch report no longer shows a 500 error in some cases.
  • Fingerprint improvements.

2.11.2

2022-03-10

  • The API now responds faster when exporting assets.
  • The Asset inventory now displays subnet tag descriptions when you hover over subnet tags.
  • You can now launch the Network Switch report from the reports page.
  • Search keywords now autocomplete for Sites and Queries.
  • The SNMP probe no longer defaults to the community strings “public,private” when no communities are provided.
  • Some third-party connectors no longer fail to record a task-completed event.
  • Self-hosted Explorer and CLI offline updates no longer fail.
  • Fingerprint improvements.

2.11.1

2022-03-08

  • The SSO group mapping form now displays a relevant error when the groups list is empty or no group is selected.
  • The group column in the user table is no longer sortable; it was never meant to be.
  • The group mappings tab no longer shows when a user has SSO disabled.
  • The service_ports_tcp and service_ports_udp search keywords now work as intended.
  • The dashboard now displays a tooltip icon on the RTT latency chart that defines certain terms and metrics.
  • The VMware connector works correctly again after a regression.
  • Fingerprint improvements.

2.11.0

2022-03-07

This release rolls up the 2.10.x updates and adds the following changes.

  • The dashboard now shows both the most and least seen values for most stats.
  • The dashboard now has CSV exports for all stats and links to deeper views of each stat.
  • The AWS and Azure integrations are now available to Professional Edition customers.
  • The Azure integration can now run from the console, Explorer, or scanner as a probe.
  • The Azure integration now identifies VM operating system information using disk image fingerprints.
  • The Azure integration now tracks the clientID, tenantID, and subscriptionID as attributes for each asset.
  • The Azure integration now creates a site per subscription ID.
  • The AWS integration now creates a site per account in addition to the existing site per VPC capability.
  • The AWS integration now supports using a provided session token.
  • The AWS integration now tracks the account name as an attribute for each asset.
  • The Account API now supports group management.
  • Asset outliers are now tracked in the inventory and within the asset details page.
  • Enterprise Edition customers can now access the Outlier Summary and Specific Outlier reports.
  • Enterprise Edition customers can now map users to groups based on SAML attribute rules.
  • You can now set the Explorer console URL through the RUMBLE_CONSOLE environment variable.
  • The web console now flags under-resourced Explorers in the Deploy view.
  • Admins can now force user logouts from the Team page in the web console.
  • Limited administrators can now view users and create new projects in the web console.
  • The scan engine now spends less time on per-VLAN SNMP enumeration when the device does not support it.
  • The scan engine now supports full SNMP v1 enumeration using non-bulk lookups, if necessary.
  • The scan engine is now much more conservative on a wider range of ICS ports.
  • The scan engine is now much more friendly to fragile Lantronix devices.
  • The scan engine now supports the Lantronix device discovery protocol.
  • The scan engine now detects the Java Debug Wire Protocol (JDWP).
  • The scan engine now detects and uses Qualys Cloud Agent correlation IDs.
  • The scan engine now reports more information from NTP services.
  • The self-hosted platform now supports a generate-certificate command.
  • Stale asset attributes no longer remain across scans.
  • The host-ping feature no longer misses hosts.
  • The task details page no longer has broken search links.
  • Fingerprint improvements.

2.10.6

2022-02-24

  • Scans now use CIDR addresses in the default scan scope of a Site.
  • Fingerprint improvements.

2.10.5

2022-02-22

  • Asset correlation now handles more corner cases, including Cisco Nexus switches.
  • Stale IPv6 addresses and UDP services no longer remain between scans.
  • Single-org admins can now see users on the team page.
  • Fingerprint improvements.

2.10.4

2022-02-17

  • OS EOL dates are now reported for Red Hat Enterprise Linux, Fedora, and CentOS.
  • Fingerprint improvements.

2.10.3

2022-02-15

  • The asset route pathing report is out of beta.
  • Fingerprint improvements.

2.10.2

2022-02-11

  • The Account API now supports group management through new endpoints.
  • Asset and service search now supports new keywords for matching primary and secondary addresses.
  • The dashboard now tracks how many assets were seen in the last 30 days across all sources.
  • The AWS integration now supports using a provided session token.
  • The asset route pathing report is now more accurate.
  • Some AWS asset attributes now populate correctly.
  • E-mail notifications no longer mangle UTF-8 characters in the subject and message body.
  • Fingerprint improvements.

2.10.1

2022-02-07

  • The HTTP scanner now captures images correctly.

2.10.0

2022-02-07

This release contains an important security fix:

  • A security issue in the SSO SAML handler, found during internal review, is now fixed. An unauthenticated attacker could have abused it to trigger a denial of service or a limited leak of application internal data.

This release rolls up the 2.9.x updates and adds the following changes.

  • The team page now supports user groups, which give you more options for managing permissions/roles across your users.
  • IPv6 support now includes link-local asset discovery and PTR lookups for the DNS/mDNS probes.
  • You can now sync AWS assets from the standalone scanner or as a scan probe in the console, or import them from previous AWS connector tasks.
  • Invited users no longer skip the initial SSO login when joining an organization that requires SSO.
  • Public IP addresses now populate an AWS asset’s IPv4 attribute.
  • Stale reverse DNS attributes no longer persist on rescanned assets.
  • The services in an asset view are now sorted properly.
  • The queries page now displays an Updated column with the last-modified date and time for each query.
  • The queries page now supports query execution across all assets, regardless of alive status.
  • JSON and XML asset exports now include asset subnet tags.
  • Fingerprint improvements.

2.9.14

2022-01-28

  • HP iLOs no longer merge into their host assets when they share a MAC address.
  • Services now display after a third-party import.
  • Asset Modify rules can now update the HW field.
  • The CLI scanner no longer stack traces.
  • The CLI censys-db sub-command now requires less memory.
  • Fingerprint improvements.

2.9.13

2022-01-27

  • You can now convert Censys Avro files to a database for faster lookups.
  • Fingerprint improvements.

2.9.12

2022-01-25

  • Login errors no longer occur after bulk permission updates; a regression had caused them.
  • Service names are back on the asset details page after a regression removed them.
  • The asset name list now includes AWS internal hostnames.
  • Fingerprint improvements.

2.9.11

2022-01-24

  • Nmap XML exports are now much faster.
  • Fingerprint improvements.

2.9.10

2022-01-20

  • The scan engine now limits the SNMP enumeration speed to the Max Host Rate, reducing CPU usage on older switches.
  • The scan engine now ignores additional cases of FortiGate HTTP interception.
  • Fingerprint improvements.

2.9.9

2022-01-18

  • The scan engine now accepts IPv6 addresses and resolves AAAA records for hostnames.
  • The scan engine now skips protocol probes on TCP port 9106.
  • Uploading very large scans now works.
  • Fingerprint improvements.

2.9.8

2022-01-14

  • You can now export only the selected assets, services, or wireless.
  • Recurring tasks now have an “Every N Hours” frequency option.
  • Search keywords now autocomplete for Organizations, Tasks, and Events.
  • AWS and Azure connectors no longer set asset alive status and no longer count as offline or back online in the change report.
  • Rules now show when they were last processed, whether they triggered their action, and any error that occurred as a result.
  • You can now filter the coverage report by site.
  • Duplicate CrowdStrike assets no longer appear after an import. The next CrowdStrike task run removes any existing duplicates.
  • Rule processing no longer stalls.
  • Importing operating system information from CrowdStrike no longer fails for some Linux devices.
  • Scanning some Lexmark printers no longer interferes with the printer’s job queue.
  • Fingerprint improvements.

2.9.7

2022-01-10

  • The scanner now lets you configure reverse DNS timeouts and the SSH username.
  • Scan import tasks now accept scan tags.
  • JSON exports no longer include the closedPortsMap field.
  • CrowdStrike connector tasks now move preexisting CrowdStrike-sourced assets into matching scanned assets across sites.
  • Task progress (on hover) no longer exceeds 100%.
  • The Azure integration no longer occasionally skips public IPs.
  • CrowdStrike connector tasks no longer send API requests that exceed length limits in specific instances.
  • Fingerprint improvements.

2.9.6

2021-12-23

  • Some events are no longer processed incorrectly.
  • Event templates now truncate results correctly.

2.9.5

2021-12-22

  • The scan engine no longer triggers an “invalid exclusions” error.

2.9.4

2021-12-21

  • The Query search now supports result count selection and remembers the setting between views.
  • The scan engine now correctly excludes broadcast addresses from the scan scope.
  • The Azure connector now ignores canceled subscriptions automatically.
  • Hostname selection for Canon printers has improved.
  • The Explorer service now starts up slightly faster on Windows.
  • The Censys AVRO importer is now 4 to 8 times faster.
  • Fingerprint improvements.

2.9.3

2021-12-15

  • The CrowdStrike integration now correlates better with existing assets.

2.9.2

2021-12-13

  • STS AssumeRole no longer fails for some AWS organizations.
  • Service products no longer persist after asset changes.
  • The Task Change Report is no longer hidden.
  • Product detection for Logstash and Neo4J has improved.
  • Fingerprint improvements.

2.9.1

2021-12-08

  • The CrowdStrike integration now uses the Scroll API to better support large organizations.

2.9.0

2021-12-06

This release rolls up the 2.8.x updates and adds the following changes.

  • The new Site Comparison report shows differences in assets between two sites, which can be in different organizations.
  • The team page now supports bulk user import and bulk permission management.
  • The layer 2 topology report now has a search filter, a site filter, and visual improvements.
  • The network bridges report now has a site filter and visual improvements.
  • The has_public search filter no longer flags certain IPv6 addresses.
  • Deleting a project no longer creates new, blank organizations.
  • Censys imports no longer mark other assets as offline.
  • The bundled npcap version is now 1.60.
  • Fingerprint improvements.

2.8.14

2021-12-03

  • Scans now run when non-loopback 127.x networks are present.

2.8.13

2021-11-24

  • TLS version enumeration works correctly again after a regression.
  • Teredo addresses are no longer considered public IPs.
  • Detection of Chromebooks and ChromeOS has improved.
  • Fingerprint improvements.

2.8.12

2021-11-21

  • The self-hosted platform now supports internal proxies for external API connections.
  • The self-hosted platform now supports internal webhook destinations for alerts.

2.8.11

2021-11-19

  • The annotator role is now available.
  • Fingerprint improvements.

2.8.10

2021-11-18

  • The Azure connector now works in self-hosted mode.
  • The last hop calculation for the TCP traceroute is now more accurate.
  • Fingerprint improvements.

2.8.9

2021-11-16

  • You can now configure credentials for single IP addresses and IP ranges in addition to CIDRs.
  • The scan engine now performs a light traceroute when an open TCP port is found.
  • The scan engine now tests for IP forwarding during scans of link-local targets.
  • The scan engine now includes Rumble/2 in HTTP user-agent strings.
  • The scan engine now limits ARP traffic to the Max Host Rate.
  • Windows Server 2019 (1809) now has an updated OS EOL date.
  • Fingerprint improvements.

2.8.8

2021-11-12

  • The self-hosted platform now supports custom CSP headers for external resources.
  • Tags with the case-insensitive key of “name” are now treated as additional hostnames.
  • Tags containing spaces now consistently convert the spaces to underscores.
  • Meraki DNS interception is now ignored in more configurations.
  • The CrowdStrike integration now tracks the last 10 recent logins per asset.
  • The Apple macOS end of life calculation works correctly again after a regression.
  • A few missing icons are back in the inventory view.
  • The FreeBSD scan processing chain no longer panics.
  • Direct print services on 9002 are no longer fingerprinted.
  • TLS versions now have consistent formatting.
  • Fingerprint improvements.

2.8.7

2021-11-07

  • Daily scans now schedule correctly in UTC forward time zones.
  • The self-hosted platform now respects proxy settings for external data sources (CrowdStrike, etc.).
  • Fingerprint improvements for tvOS and Crestron.
  • Additional UPnP fingerprints.

2.8.6

2021-11-06

  • Fingerprint improvements for tvOS, homepodOS, and bridgeOS.

2.8.5

2021-11-06

  • The self-hosted installer now supports manual database configuration.
  • The self-hosted platform now includes a database verify subcommand.
  • iOS device identification has improved.
  • Fingerprint improvements.

2.8.4

2021-11-05

  • The VMware probe now handles vCenter instances configured with multiple datacenters.
  • A race condition no longer causes Explorer updates mid-scan.
  • The RDP TLS fingerprint no longer breaks matching during asset correlation.
  • Stopped scans now indicate which user stopped them in the error message.
  • Active probes are now disabled for some Lantronix and Rockwell PLC ports.
  • Fingerprint improvements.

2.8.3

2021-11-04

  • SAML SSO now specifies that the required NameID Format is unspecified, for Azure AD compatibility.
  • Failed S3 storage operations are now retried.
  • Azure credential validation now works correctly.
  • The field help on the scan form now includes additional detail.

2.8.2

2021-11-02

  • Recurring tasks no longer schedule jobs when the previous job is still queued.
  • VMware-based OS detection no longer fails.
  • Fingerprint improvements.

2.8.1

2021-11-02

  • Scans no longer mark out-of-scope assets as offline.

2.8.0

2021-11-01

This release rolls up the 2.7.x updates and adds the following changes.

  • Censys Search API and Censys Data imports are now available (Enterprise).
  • Fingerprint improvements.

2.7.11

2021-10-27

  • Explorer updates on Windows now work correctly.

2.7.10

2021-10-24

  • Restrictive umasks no longer cause issues on the self-hosted platform.
  • VMware vCenter/ESXi virtual machine discovery is now available (Enterprise).
  • Asset merging from third-party data sources has improved.
  • TLS fingerprints are now reported as SHA256 hashes (base64).
  • You can now manage credentials for SNMP v2/v3 and VMware globally.
  • Serial numbers from A10 devices are now collected via SNMP.
  • The SNMP v3 probe now supports multiple credentials.
  • Scan configuration now has a Credentials tab.
  • You can now download detailed task logs.
  • Light UX improvements and bug fixes.
  • Fingerprint improvements.

2.7.9

2021-10-21

  • Permissions on the self-hosted platform now work correctly.

2.7.8

2021-10-15

  • The runZero Explorer on Windows now explicitly sets the service to automatic start.
  • You can now launch RFC 1918 scans from the main Scan menu.
  • Fingerprint improvements.

2.7.7

2021-10-15

  • Credential validation issues with Azure now log detailed errors.
  • The self-hosted platform now supports Debian 9.
  • Fingerprint improvements.

2.7.6

2021-10-13

  • Azure connector configuration no longer produces an application error.
  • Fingerprint improvements.

2.7.5

2021-10-13

  • Certain AWS and Azure assets now import correctly.
  • Fingerprint improvements.

2.7.4

2021-10-08

  • The self-hosted platform now supports Oracle Linux 7 and 8.
  • Fingerprint improvements.

2.7.3

2021-10-07

  • The AWS integration is now much faster for large numbers of accounts.

2.7.2

2021-10-06

  • You can now update existing Azure tasks without difficulty.

2.7.1

2021-10-05

  • The date picker now shows arrow icons.
  • You can now update existing AWS tasks without difficulty.
  • The sidebar is now collapsible using the chevron icon at the top.
  • The “Processing” link states are now handled more consistently.

2.7.0

2021-10-05

This release rolls up the 2.6.x updates and adds the following changes.

Integrations

  • The Azure VM connector now supports multi-subscription and multi-directory access.
  • The AWS EC2 connector now supports ELB load balancers as importable assets.
  • Connector credentials are now validated automatically on save.
  • The Splunk add-on now supports self-hosted console endpoints.
  • The Splunk add-on now optionally imports asset services.
  • The Splunk add-on now uses jQuery 3.5.0.
  • CrowdStrike asset merging has improved.

Self-hosting

  • The self-hosted installer now includes the Explorer and scanner binaries.
  • The self-hosted console now supports detailed TLS configuration.
  • The self-hosted console now runs as an isolated subprocess.
  • The self-hosted console no longer enforces API rate limits.

User experience

  • The dashboard now shows asset and service trends.
  • The Scan configuration view has a new, simpler design.
  • The RFC 1918 coverage report now tracks imported scans.
  • The Services inventory now supports new address-related search keywords.
  • The Assets and Services inventories now support wildcard searches of hostnames with anchored patterns.
  • The Screenshot inventory is now faster and shows the correct total count.
  • The RFC 1918 coverage report no longer skips IPs.

Authentication

  • Standard accounts that authenticate using SSO now become SSO-only accounts.
  • SSO now supports multiple domains using IdP or SP initiated authentication.
  • The MFA challenge now provides a Retry button for browsers that require user interaction (Safari).
  • MFA enrollment now supports token and platform authentication modes as separate options.
  • Admin users can now set the first and last names of other users.
  • The Explorers, scanners, MSI wrapper, and verifier are now signed with a new EV certificate.

Scanner and fingerprinting

  • The Professional tier now includes subnet ping and host ping.
  • OS EOL tracking now covers Windows 10 and APC firmware.
  • Windows 10 and Server 2019 OS versions are now tracked by range.
  • The Explorer and CLI scanner now detect and report an error when run within the WSL/WSL2 environments.
  • The CLI scanner upgrade now supports the –force option.
  • The scan engine now detects Bitdefender remotely.
  • The ARP probe works again on newer Windows builds.
  • Fingerprint improvements

2.6.4

2021-09-16

  • The scan engine now detects Azure’s OMI WSMAN implementation.
  • Fingerprint improvements.

2.6.3

2021-09-16

  • The scan engine now detects WSMAN, ADB, and InfluxDB services.
  • Fingerprint improvements.

2.6.2

2021-09-14

  • SMB v1 detection works again.
  • Fingerprint improvements.

2.6.1

2021-09-08

  • Some Azure VMs no longer fail to import.

2.6.0

2021-09-07

  • Rumble Enterprise customers can now sync virtual machine inventory from the Microsoft Azure cloud.
  • The CrowdStrike connector has a new design that improves asset merging and avoids duplicates.
  • OS end-of-life dates for Windows, macOS, Ubuntu, Debian, and iLO assets are now tracked.
  • The self-hosted version of Rumble now supports offline mode and offline updates.
  • The self-hosted version of Rumble now supports RHEL 7 in offline mode.
  • The scan engine now surfaces NFS exports via discovered mountd services.
  • The scan engine now returns details for discovered PPTP services.
  • The dashboard loads faster for large organizations.
  • The UI now includes new, custom icons.
  • Fingerprint improvements.

2.5.8

2021-08-30

  • Stale asset expiration now applies to third-party sourced assets.
  • The scan engine now reports PPTP services.
  • Fingerprint improvements.

2.5.7

2021-08-27

  • The CrowdStrike connector has a new design that improves merging and avoids duplicates.
  • The scan engine now reports NFS exports.
  • Fingerprint improvements.

2.5.6

2021-08-23

  • The scan engine now implements the Cisco layer 2 traceroute protocol thanks to Chris Marget’s cisco-l2t project.
  • TCP port 1720 is no longer included in the defaults. The port may be re-enabled once H.323 is fully implemented.
  • The scan engine now handles mangled SNMP responses better.
  • The HTTP/2 protocol is now reported at the asset level.
  • Fingerprint improvements.

2.5.5

2021-08-19

  • The service attribute report works again.
  • The scan engine now reports additional SSH attributes.

2.5.4

2021-08-19

  • The Explorer and scanner now support the Windows arm64 platform.
  • The scan engine no longer hangs in the DCERPC probe.
  • Fingerprint improvements

2.5.3

2021-08-18

  • All exports now include third-party data source attributes.
  • Third-party attributes now use the @source.type syntax for search.
  • The Merge feature in the asset inventory is now more consistent.
  • Sites and scans now support large target exclusion lists.
  • Unresolvable hostname excludes are now ignored automatically.
  • The scan engine now records more information from McAfee ePO agents.
  • Fingerprint improvements

2.5.2

2021-08-12

  • Automatic queries are now available to Professional users as well as Enterprise.
  • Some Windows desktops no longer receive the wrong asset type.
  • CrowdStrike assets are now matched more accurately against Rumble assets.
  • The scanner now skips active protocol detection on port 9999.
  • Fingerprint improvements

2.5.1

2021-08-05

  • The default TCP port list now includes more SolarWinds products as well as port 7676 for JMS/IMBroker.
  • The estimated scan runtime now accounts for the TCP port list (and excludes).
  • Juniper switch fingerprinting now uses a Juniper-specific OID instead of sysDesc.
  • The runZero CLI now ignores additional bogus SIP ALG services.
  • Offline-agent events are no longer skipped in certain situations.
  • Explorers now reconnect properly after an update.
  • The task view now shows the correct bandwidth calculation.
  • CSV exports of mixed-source assets no longer fail with an error.
  • Fingerprint improvements.

2.5.0

2021-08-03

  • Rumble Enterprise customers can now sync AWS EC2 assets across accounts using STS roles.
  • Rumble Enterprise customers can now sync asset data from the CrowdStrike Falcon API.
  • The scan engine now better differentiates between Windows workstation and server variants.
  • The scan engine now uses DCERPC to detect a range of asset attributes and services.
  • The scan engine now detects multi-homed assets using DCERPC.
  • The dashboard can now show stats across all sites or just a specific site.
  • The new Unmapped MAC report shows unscanned assets by switch port.
  • The Reports page now has a new layout and inline search.
  • The Queries tab now appears under a new navigation item.
  • Fingerprint improvements.

2.4.4

2021-07-26

  • The superuser role is now available as a default permission for SSO users.
  • The scan engine now gathers data from the Windows DCERPC endpoint mapper.
  • Fingerprint improvements.

2.4.3

2021-07-18

  • Fingerprint improvements.

2.4.2

2021-07-14

  • Limited layer-2 topology graphs derived from ARP data are now available for environments using Fortinet switches.
  • You can now export the Topology and Network Bridges graphs as PNG images.

2.4.1

2021-07-13

  • This build fixes a bug in the Go runtime that could allow a remote attacker to cause a recoverable panic in the Rumble services and scan engine (CVE-2021-34558).

2.4.0

2021-07-13

  • Rumble Enterprise customers can now sync asset data from Amazon Web Services EC2 and Miradore MDM data sources.
  • Rumble Enterprise customers can now self-host the platform on RHEL and CentOS distributions.
  • Credentials are now managed at the account level with per-organization access.
  • The Rumble self-hosted CLI now has new features and a better user experience.
  • Fingerprint improvements.

2.3.5

2021-07-04

  • Explorer upgrades and scan stop requests now process while a scan is active.
  • Subnet ping mode no longer misses subnets during large scans.
  • Explorers no longer show as offline unexpectedly.
  • Fingerprint improvements.

2.3.4

2021-06-26

  • The Screenshots inventory tab works again.
  • Fingerprint improvements.

2.3.3

2021-06-24

  • Tabs, fonts, and styles received a light update.
  • This release fixes a number of small UX bugs.
  • Fingerprint improvements.

2.3.2

2021-06-16

  • The RFC 1918 coverage report now supports a starting date to exclude older scans.
  • The Your team page is now searchable and sortable, and it supports bulk user actions.
  • Fingerprint improvements.

2.3.1

2021-06-09

  • Single-organization users can now view sites and tasks.
  • Offline assets are now marked as offline.
  • Cisco Catalyst switches are now fully enumerated.
  • Fingerprint improvements.

2.3.0

2021-06-08

  • The new RFC 1918 coverage report shows unscanned address space and hinted ranges.
  • SNMP v3 enumeration of Cisco Catalyst switches now handles per-vlan port mappings.
  • Fingerprint improvements.

2.2.5

2021-05-29

  • Tags now always display with = instead of : to match the search engine syntax.
  • The Subnet Ping and Host Ping modes are now more reliable on large scans.
  • Fingerprint improvements.

2.2.4

2021-05-26

  • The rumblectl command no longer produces a stack trace in self-hosted mode.
  • Fingerprint improvements.

2.2.3

2021-05-17

  • The self-hosted platform now removes older scanner/Explorer binaries during updates.
  • The scan engine now pulls layer-2 information from Force-10 switches.
  • The scan engine now ignores CheckPoint SMTP and SIP interception.
  • The scan engine now extracts hostnames from Zyxel switches.
  • An invalid fingerprint for Cisco IP phones is now fixed.
  • Multiple notifications can now trigger from a single event.
  • The scan-started event now includes agent fields.
  • Fingerprint improvements.

2.2.2

2021-05-16

  • The scan engine now extracts additional information from Zyxel switches.
  • The Explorers page now supports sorting, searching, and tagging.
  • Fingerprint improvements.

2.2.1

2021-05-14

  • The scan confirmation dialog now warns when the scope mixes public and private IPs.
  • The SNMP v3 probe now supports sha224, sha256, sha384, and sha512 authentication.
  • The SNMP v3 probe now supports aes192, aes256, aes192c, and aes256c encryption.
  • The self-hosted platform now includes a CLI to manage user accounts.
  • Fingerprint improvements.

2.2.0

2021-05-11

Rumble 2.2.0 rolls up the previous 2.1.x releases and adds the following changes and features.

Web console

  • Enterprise customers can now export an HP iLO report with serial numbers, physical hardware information, and other fields useful for warranty tracking and server inventory.
  • Virtual machines now show the virtualization vendor in the asset hardware field, and you can search and filter them by vendor.
  • Virtual machines now have an icon in the asset view, and router icons now appear with the other icons.
  • Age calculation no longer uses virtual machine and legacy MAC prefixes, which gave inaccurate results.
  • A new report shows virtual machine vendors.
  • The NDAA Section 889 report now includes Aztech and its subsidiaries as vendors.
  • You can now use the Name tag to set a preferred hostname for any asset.
  • You can now click tags in inventory views to search the inventory.
  • Alert notification templates can now include the name and internal IP address of the Explorer that ran the scan.
  • The alert rules list now shows which rules are enabled.
  • Confirmation dialogs now require a typed response for destructive actions.
  • Page layout now works better for browser window widths between 920 and 1200 pixels.
  • When a scan produces too many changes to list in the task report, the report now says so.
  • Progress bars now use standard meter elements for smoother updating and better accessibility.
  • Icons and screenshots now lazy-load to speed up initial page rendering.
  • Task duration now rounds up to the nearest minute.

Explorer and scan engine

  • A better hostname is now chosen for each asset by default.
  • VLANs are now tracked on each asset where possible.
  • Minecraft servers are now identified on the network.
  • HP iLO scans now return additional information.
  • Virtual machine hardware is now reported when no better fingerprint is available.
  • Pulse Secure VPN devices running newer firmware are now identified correctly.
  • You can now set additional CA roots with the RUMBLE_TLS_ADDITIONAL_ROOTCA variable.
  • Fingerprint improvements.

Self-hosted platform

  • Self-hosted installations now sync license changes during updates.
  • Email validation is now more relaxed on the self-hosted platform.
  • Install instructions now use curl instead of wget for better reliability.

Bug fixes

  • The asset last seen date now updates only when the asset has at least one open port and is therefore “alive”.
  • Estimated scan times in recurring task exports are now accurate for tasks that use the default ports.
  • Password reset requests now work for accounts with no last name.
  • Endpoint software on macOS no longer causes scans to stall.
  • The runZero Explorer no longer leaks memory and CPU.
  • User name validation now works correctly when you edit user preferences.
  • User invitations for SSO accounts now work correctly.

2.1.7

2021-05-03

  • The web console now includes a new HP iLO CSV export for warranty tracking (Enterprise).
  • Age calculation no longer uses virtual machine and legacy MAC address prefixes.
  • Self-hosted installations now sync license changes during updates.
  • Virtual machines now appear in the asset HW field.
  • VLANs are now tracked on each asset, where possible.
  • Tags are now clickable and open inventory searches.
  • Fingerprint improvements.

2.1.6

2021-04-28

  • Rumble scans on macOS no longer stall when endpoint software blocks ICMP scans.
  • The web console now better supports browser widths between 920 and 1200 pixels.
  • User invitations from an SSO account now work correctly.

2.1.5

2021-04-27

  • The runZero Explorer and runZero CLI now collect additional information from HP iLO nodes.
  • Fingerprint improvements.

2.1.4

2021-04-26

  • The runZero Explorer and runZero CLI no longer leak memory and goroutines.
  • Fingerprint improvements.

2.1.3

2021-04-23

  • The runZero Explorer and runZero CLI now avoid probes on vendor-specific SunRPC services.
  • The latest Pulse Secure VPN firmware is now fingerprinted correctly again.
  • Confirmation dialogs now work correctly on Chrome.
  • The dashboard now defines next steps for new organizations.
  • The bundled npcap version is now 1.31.
  • Fingerprint improvements.

2.1.2

2021-04-19

  • The runZero Explorer and runZero CLI now detect the Minecraft service.
  • Confirmation dialogs now require a typed response for permanent actions.
  • This release fixes small bugs in the default notification templates.
  • Fingerprint improvements.

2.1.1

2021-04-14

  • This update disables automatic npcap upgrades while we investigate a stall issue.

2.1.0

2021-04-13

Rumble 2.1.0 rolls up the previous 2.0.x releases and adds the following changes and features.

Web console

  • Custom notification templates are now available in Text, HTML, and JSON formats.
  • Webhook notification channels can now include arbitrary HTTP headers for authentication.
  • You can now export tasks as CSV and JSON from the Recurring and Search tabs of the task view.
  • You can now remove tags in bulk by specifying -tag in the inventory Tag dialog.
  • Asset CSV bulk imports now tolerate records with extra fields.
  • You can now exclude specific TCP ports in the scan configuration.
  • You can now copy user invitation links to the clipboard.
  • UX tooltips are now easier to read across all platforms.
  • Alert management is no longer organization-specific.
  • Exports with complex queries are now much faster.

Integrations

  • You can now export device serial numbers in Cisco Smart Net Total Care format for warranty checks.
  • The Splunk add-on now supports proxy server configuration in version 1.0.11.

Explorer

  • The Explorer now rejects scan tasks when free disk space is too low to hold the scan results.
  • The Explorer now falls back to the install directory for temporary files if needed.
  • The Explorer now tries to upgrade the npcap driver automatically on Windows.

Scanner

  • The scanner now enriches scan results with AWS EC2 metadata when the ec2:DescribeInstances permission is available.
  • SNMP v2 enumeration of ports and vlan membership now uses community indexing automatically.
  • Web screenshots no longer use Chromium installations from Snap packages.
  • The mDNS fingerprint for LG webOS is no longer overly aggressive.
  • EC2 instances now report the instance type as the hardware field.
  • The scanner now ignores additional bogus SIP helper responses.
  • LPD fingerprinting now uses only a status request.
  • Fingerprint improvements.

Events

  • A single event now triggers only one notification per unique notification channel.
  • All web console agent removal actions now generate the agent-removed event.
  • The offline-agent event no longer includes recently removed or forgotten agents.
  • The task-failed event now includes the full organization and site name in the details.
  • Agent restarts and timeouts now generate the task-failed event.

Self-hosted platform

  • SMTP configuration now supports additional TLS settings.
  • SMTP errors now log to syslog correctly.
  • Initial auto configuration is now more complete.

2.0.14

2021-04-06

  • The runZero Explorer and runZero CLI now gather AWS EC2 instance metadata where possible.
  • Fingerprint improvements.

2.0.13

2021-04-05

  • The runZero Explorer now falls back to the install directory for temporary files.
  • Fingerprint improvements.

2.0.12

2021-04-03

  • Exports are now faster across the board, with major speedups for deep search queries.
  • The Rumble Verifier now supports 2.x macOS binaries.
  • This release fixes several bugs in the new tooltip implementation.
  • Screenshots no longer use Chromium when it is installed via Snap.
  • Additional bogus SIP helper responses are now automatically ignored.
  • Self-hosted installs now log SMTP-related errors.
  • Fingerprint improvements.

2.0.11

2021-04-01

  • Fingerprint improvements.

2.0.10

2021-03-30

  • The runZero Explorer and runZero CLI now collect additional Cisco-specific SNMP OIDs.
  • The Cisco Serial Number export is now available for all licensed clients.
  • Fingerprint improvements.

2.0.9

2021-03-30

  • The runZero Explorer and runZero CLI no longer stall in a rare case when enumerating SNMP endpoints.
  • Fingerprint improvements.

2.0.8

2021-03-29

  • The runZero Explorer now automatically cleans temporary files left by interrupted scans.
  • The runZero Explorer now prepends “rumble-” to all temporary files.

2.0.7

2021-03-28

  • The runZero Explorer’s out of disk space error is now easier to read.

2.0.6

2021-03-28

  • The runZero Explorer now performs a disk space check before running a new scan.
  • The runZero Explorer now reports disk related errors more reliably.
  • Asset CSV imports now accept records with extra fields.
  • Fingerprint improvements.

2.0.5

2021-03-26

  • The runZero Explorer and runZero CLI now better support enumeration of Catalyst switches.
  • Administrators can now copy the invite link to share directly with team members.
  • Image links now work correctly on the self-hosted version.

2.0.4

2021-03-26

  • The runZero Explorer and runZero CLI now handle the LPD protocol more carefully.
  • Fingerprint improvements.

2.0.3

2021-03-23

  • The runZero Explorer no longer reports an intermittent “no child processes” message on installation.
  • The runZero Explorer and runZero CLI now always return wireless results when iwlist is present.
  • The web console now generates agent-removed events for each agent, including for bulk actions.
  • The web console now generates task-failed events for agent restarts and timeouts.

2.0.2

2021-03-21

  • The runZero Explorer now logs connectivity issues with the websocket protocol in more detail.
  • The self-hosted Rumble platform now supports better automatic configuration.
  • Fingerprint improvements.

2.0.1

2021-03-20

  • Deleted event rules are no longer processed.
  • Scans no longer stall in Subnet Ping mode.
  • Fingerprint improvements.

2.0.0

2021-03-16

Rumble 2.0 is a roll-up of the 1.16.x releases, along with the following changes:

Web console

  • The new Rules Engine supports advanced alerts and automated asset updates.
  • Organization-level Alerts are now managed at the global level.
  • The Explore menu item is now named Reports.
  • The interface received light cosmetic updates.

Deployment

  • runZero Explorers are now runZero Explorers to better indicate their function.
  • runZero Explorers and runZero CLIs now appear under the Deploy menu.
  • You can now self-host the full platform.

REST API

  • The Account API now provides organization, user, and event management.
  • Three new API endpoints support the ServiceNow ® ITOM integration.

Scan engine

  • Microsoft Exchange and Outlook Web Access detection has improved.
  • The subnet and host ping modes no longer stall.
  • The scan engine now reports the number of bogus results it ignored.
  • The npcap driver is now v1.20.
  • Fingerprint improvements.

1.16.6

2021-03-06

  • Layer-2 topology reports now display only the best matching port, rather than every port where an asset was seen.
  • The runZero Explorer and runZero CLI now handle subnet and host ping modes faster and more accurately.
  • The runZero CLI now processes gzip-compressed imports faster.
  • Fingerprint improvements.

1.16.5

2021-02-27

  • Assets that were previously identified through a TCP RST, but otherwise had no services, have been removed from the platform.
  • The runZero Explorer and runZero CLI now collect more data about exposed SSH authentication methods.
  • Asset tracking based on the TCP/IP fingerprint works again.
  • Fingerprint improvements.

1.16.4

2021-02-26

  • The Rumble scan engine now ignores assets where all TCP ports are closed and no other services are available. This reduces the reporting of bogus hosts when scanning through certain firewalls.
  • The task summary and task details now report how many assets were ignored for having no valid services. This shows how much network interference may be present.
  • The macOS binaries now use a new code signing process. macOS agents that were offline for some time may need a manual update.
  • The live asset count and project asset count are now calculated correctly for users with deleted organizations.
  • Search queries that match strings against <% and %> now work as expected.
  • Fingerprint improvements.

1.16.3

2021-02-25

  • Fingerprint improvements.

1.16.2

2021-02-24

  • You can now tag runZero Explorers in the per-agent settings page.
  • Events are now regularly generated for offline agents.
  • Fingerprint improvements.

1.16.1

2021-02-21

  • The Rumble scan engine now supports a maximum TTL for all scan traffic.
  • The Rumble scan engine now supports subnet ping and host ping modes.
  • The Rumble scan engine now distributes scan traffic more evenly across subnets.
  • The Rumble scan engine now reports and tracks closed TCP ports.
  • The Rumble scan engine now reports additional ICMP fields.
  • The Rumble scan engine now auto-scales the group size.
  • Apple macOS is now partially supported on ARM systems.
  • Fingerprint improvements.

1.16.0

2021-02-09

  • This release rolls up all 1.15.x point releases.
  • VMware ESXi versions are now reported correctly.
  • Fingerprint improvements.

1.15.6

2021-01-31

  • The Inventory Search, Exports, and Reports are now significantly faster for large organizations.
  • Fingerprint improvements.

1.15.5

2021-01-28

  • The Agents page now flags any Windows Agents with an obsolete version of Npcap installed.
  • Fingerprint improvements.

1.15.4

2021-01-26

  • Fingerprint improvements.

1.15.3

2021-01-23

  • The runZero CLI and runZero Explorer now gather serial numbers from SNMP devices.
  • Scan result processing no longer ignores the 169.254.0.0/16 subnet.
  • The runZero CLI and runZero Explorer now detect the TeamViewer protocol.
  • Partial site scans now consider ARP cache data from the entire site.
  • The runZero CLI now supports importing gzip-compressed scan data.
  • The runZero CLI and runZero Explorer now detect the CheckMK service.
  • Fingerprint improvements.

1.15.2

2021-01-19

  • The dashboard now links to the top 5,000 results for asset types and service details.
  • You can now save Rumble-provided queries as per-account copies and modify them.
  • Partial site scans now use ARP cache entries from the rest of the site.
  • Fingerprint improvements.

1.15.1

2021-01-16

  • The Crestron probe no longer causes concurrent scans on the same agent to hang.
  • Fingerprint improvements.

1.15.0

2021-01-12

  • This release rolls up all 1.14.x point releases.
  • Fingerprint improvements.

1.14.9

2021-01-10

  • The runZero Explorer and runZero CLI now support the Crestron discovery protocol.
  • The runZero Explorer and runZero CLI now capture TLS fields from PostgreSQL services.
  • Fingerprint improvements.

1.14.8

2021-01-06

  • The runZero Explorer now handles additional proxy corner cases.
  • Fingerprint improvements.

1.14.7

2021-01-05

  • runZero Explorer and runZero CLI updates now use any proxies configured in the environment.
  • Web screenshots now ignore any proxies configured in the environment.
  • Fingerprint improvements.

1.14.6

2021-01-04

  • The HTTP2 probe in the runZero Explorer and runZero CLI no longer has a minor memory leak.
  • Web screenshots now ignore any proxy configured for the runZero Explorer communication.
  • Web screenshots no longer leave zombies in additional environments.
  • Fingerprint improvements.

1.14.5

2020-12-28

  • The runZero Explorer and runZero CLI no longer leak memory.
  • Web screenshots no longer leave zombies in environments without init.
  • Fingerprint improvements.

1.14.4

2020-12-24

  • Services with empty virtual hosts now consolidate into the first non-empty virtual host service where applicable.
  • Subtasks created by a recurring scan now carry the “defaults” parameters forward.
  • Fingerprint improvements.

1.14.3

2020-12-19

  • The runZero Explorer and runZero CLI no longer leak memory.

1.14.2

2020-12-17

  • The runZero Explorer and runZero CLI now use an upgraded runtime.
  • The runZero Explorer and runZero CLI now use npcap 1.10.
  • The site scan API now handles custom probe configurations.
  • This release updates the task stop API documentation.
  • Fingerprint improvements.

1.14.1

2020-12-14

  • You can now assign agents to their connected sites automatically from the Manage menu.
  • Scan tasks configured through the API now handle the probes parameter correctly.
  • Asset correlation now ignores PAN-OS virtual MACs.
  • Scan task parameters are now normalized consistently.
  • Fingerprint improvements.

1.14.0

2020-12-08

  • SNMP System Description fingerprints now take precedence over SSH-based OS matches.
  • Fingerprint improvements.

1.13.11

2020-12-02

  • Certain API calls now return a 400 instead of a 500 error when called with a non-JSON content type.
  • Bogus services caused by captive portals, honeypots, and certain firewalls are now automatically ignored.
  • Fingerprint improvements.

1.13.10

2020-12-01

  • Agent to cloud communication now uses only the console.rumble.run hostname.
  • Breadcrumbs are now navigable across the product user interface.
  • Fingerprint improvements.

1.13.9

2020-11-25

  • Inventory search boxes now autocomplete search keywords (name:, hardware: and so on). You can trigger completion with the keyboard (tab, enter) or mouse.
  • This release updates and cleans up the search query documentation.
  • Tag editing dialogs now autocomplete from your top 50 most used tags.
  • Some search keywords are now more consistent.

1.13.8

2020-11-23

  • Fingerprint improvements.

1.13.7

2020-11-20

  • The fingerprinting engine now supports more precise device detection.
  • New mDNS fingerprints are now supported, including for M1-based Apple devices.
  • This release includes several security fixes for findings from an ongoing audit.
  • Fingerprint improvements.

1.13.6

2020-11-19

  • The task details page now shows the scan speed in the upper left section.
  • Fingerprint improvements.

1.13.5

2020-11-13

  • The runZero Explorer and CLI now work with macOS Big Sur.

1.13.4

2020-11-12

  • The runZero Explorer, CLI, and Console now use the latest Go runtime.
  • Fingerprint improvements.

1.13.3

2020-11-10

  • Fingerprinting is now more consistent for assets with both SMB v1 and v2 enabled.
  • The BACnet probe now supports multiple ports per scan.
  • Fingerprint improvements.

1.13.2

2020-11-08

  • You can now configure session and login timeouts from the Account Settings page.
  • The Subnet Grid report is now faster and supports RTT, TTL, and Age color modes.
  • Fingerprint improvements.

1.13.1

2020-11-05

  • The new Account Settings page lets you enforce MFA and block Support access.
  • Fingerprint improvements.

1.13.0

2020-11-03

  • This release rolls up all 1.12.x point releases.
  • Fingerprint improvements.

1.12.9

2020-10-25

  • The runZero CLI and runZero Explorer now decompress non-negotiated gzip responses from HTTP services.
  • Fingerprint improvements.

1.12.8

2020-10-25

  • The Subnet Utilization report now sorts networks by density more accurately.
  • The Subnet Grid report is now slightly faster with large networks.
  • Asset correlation now ignores bogus replies for SMB and RDP.
  • Fingerprint improvements.

1.12.7

2020-10-24

  • The Team page now contains a tab showing which users have access to the active organization.
  • Users with per-organization admin roles can now manage user accounts.
  • Fingerprint improvements.

1.12.6

2020-10-22

  • Users with the “No Access” permission can now manage their own account settings.
  • Users can now have a Billing role limited to license and entity management.

1.12.5

2020-10-21

  • Inventory searches with the haspublic keyword now handle multi-homed systems correctly.
  • Inventory searches now treat full and partial IPv4 addresses as host queries.
  • The Subnet Utilization percentage is now calculated correctly for sites with non-default masks.
  • Asset tags set from the Inventory page are now additive and merge into existing tags.
  • The overview page now shows asset tags.
  • The Task Search page has small improvements.

1.12.4

2020-10-21

  • The runZero CLI and runZero Explorer now handle an even wider range of SNMP devices when polling the ARP cache.
  • Fingerprint improvements.

1.12.3

2020-10-20

  • The runZero CLI and runZero Explorer now handle a wider range of SNMP devices when polling the ARP cache.
  • Fingerprint improvements.

1.12.2

2020-10-17

  • The runZero CLI terminal UI is now cleaner and more polished.
  • Fingerprint improvements.

1.12.1

2020-10-15

  • The runZero CLI and runZero Explorer now deduplicate overlapping target network ranges.
  • Fingerprint improvements.

1.12.0

2020-10-13

  • This release rolls up all 1.11.x point releases.

1.11.9

2020-10-11

  • The runZero CLI now updates itself when run with the upgrade argument.
  • You can now install the runZero Explorer with a static MSI wrapper.
  • Fingerprint improvements.

1.11.8

2020-10-04

  • The scan engine is now more consistent because it retries UDP and pre-warms the ARP cache for each target group.
  • Fingerprint improvements.

1.11.7

2020-09-28

  • The runZero Explorer and runZero CLI now include npcap version 1.0.
  • Fingerprint improvements.

1.11.6

2020-09-23

  • Users with the Viewer role can now access only the Dashboard, Inventory, Explore, and Agents screens.
  • Fingerprint improvements.

1.11.5

2020-09-21

  • License expiration tracking in the runZero CLI works again.
  • Fingerprint improvements.

1.11.4

2020-09-18

  • Fingerprint improvements.

1.11.3

2020-09-13

  • Fingerprint improvements.

1.11.2

2020-09-11

  • You can now convert Organizations to Projects from the settings page.
  • This release updates the top-level organization navigation.

1.11.1

2020-09-09

  • Accounts with a default organization role of “user” but a per-organization role of “none” are no longer inadvertently blocked from certain features.
  • The runZero Explorer no longer crashes intermittently.

1.11.0

2020-09-09

  • This release rolls up all 1.10.x point releases.

1.10.8

2020-09-08

  • Projects are now available as temporary, self-deleting organizations. They are useful for one-off scans and exploring historical data.
  • Web screenshots now try additional Chrome locations on the Windows platform.
  • This release adds over 10,000 new SNMP fingerprints.
  • This release includes small bug fixes and cosmetic improvements.
  • Additional Fingerprint improvements.

1.10.7

2020-09-01

  • Web screenshots now retry on timeouts and choose the best quality image automatically.
  • Web screenshots now use more concurrent Chrome processes on x86 systems, based on available memory.
  • The runZero Explorer and runZero CLI now track CPU and memory usage across the life of a scan.
  • Fingerprint improvements.

1.10.6

2020-08-22

  • The runZero Explorer, runZero CLI, and runZero Console now compress raw scan data by default. The scan.rumble output from the scanner is now named scan.rumble.gz. The web console and API can import both compressed and uncompressed versions of this data. Existing scan data migrates to the compressed form automatically. This change reduces agent bandwidth usage and speeds up large imports over the network.
  • The Tasks view now links to the inventory search for each associated site.
  • The status of agent-run scans now updates more frequently.

1.10.5

2020-08-21

  • The completed task list now shows the task runtime in the information column.
  • The task views now also link to the inventory view of each site.
  • Fingerprint improvements.

1.10.4

2020-08-17

  • API uploads from the runZero CLI work again.
  • Fingerprint improvements.

1.10.3

2020-08-14

  • This release includes small bug fixes and dependency updates across the platform.
  • Fingerprint improvements.

1.10.2

2020-08-12

  • Site exports and imports now include the registered subnets.
  • You can now update assets in bulk by importing a modified CSV export from the Inventory screen.

1.10.1

2020-08-11

  • Subnet tags with multiple subnets per tag are now easier to query.
  • Fingerprint improvements.

1.10.0

2020-08-04

  • The console user interface received a light update around colors and styles.
  • Event logs are now available in the console.
  • Fingerprint improvements.

1.9.10

2020-08-03

  • The Scan Configuration form now shows Scan Tags.
  • The DNS and mDNS probes now always report the protocol, even for error responses.
  • Fingerprint improvements.

1.9.9

2020-08-02

  • Site scopes now automatically convert CIDR input into registered subnets.
  • You can now pin a scan task’s Scope and Excludes to its associated site using the string “defaults”.
  • You can now pin scan tasks to the default TCP service list using the string “defaults”.
  • Non-Windows SMB-enabled services are no longer identified as Windows.
  • SMB v1 is no longer reported incorrectly.
  • Fingerprint improvements.

1.9.8

2020-07-29

  • The Delete and Merge buttons in the Service Inventory toolbar now work.
  • The FTP Service Attribute report now shows the correct title.
  • Fingerprint improvements.

1.9.7

2020-07-22

  • The Inventory Import action now recognizes valid scan data.
  • The runZero Explorer and runZero CLI are now much more reliable for lossy network environments.

1.9.6

2020-07-21

  • The TCP probes are now less bursty, so scans consisting of mostly HTTP services no longer time out and lose valid responses.
  • The TCP fingerprinter now handles unexpected termination more gracefully. This improves the reliability of AWS ELB scans and should help with reliability across a range of services.

1.9.5

2020-07-20

  • All paid plans now support Continuous recurring scans. These scans run back-to-back and can simplify continuous monitoring. An agent running continuous scans runs additional scans only if the Concurrency setting is above 1.
  • Out-of-date agents now upgrade before new scans run. For the few agents where upgrades are impossible (read-only partitions, network filters, etc), this can delay each scheduled scan by up to five minutes.

1.9.4

2020-07-18

1.9.3

2020-07-16

  • The web screenshot feature now tries even harder to prevent orphaned Chrome.exe processes.
  • The runZero Explorer now removes all agent-related files on uninstall.
  • You can now reassign runZero Explorers to other organizations.

1.9.2

2020-07-12

  • The Export API now supports an optional fields parameter that selects which fields appear in JSON/JSONL exports. The fields parameter works for Assets, Services, Wireless, and Sites.

1.9.1

2020-07-09

  • Scans no longer hang when probing unresponsive SSH daemons.
  • The scan engine no longer reports SMBv1 erroneously on some NAS devices.

1.9.0

2020-07-06

  • The TFTP probe no longer misses results in some cases.
  • The SNMP probe now gathers the route table from many types of switches and routers.
  • TCP SYN scans of non-local targets now try harder when there is congestion.
  • Fingerprint matches that include a hardware version now take priority.
  • Fingerprint matches for SSH daemons now support more platforms.
  • You can now delete and recreate the permanent organization and permanent site.
  • The Scan Configuration page now shows a notice when input validation fails.
  • The Scan Configuration form now shows SNMP parameters at the top.
  • The Network Bridges report now links all external IPs to an internet cloud.
  • The Network Bridges report now uses subnet masks from Sites.
  • The Subnet Utilization report now provides a Scan link for each network.
  • The Subnet Utilization report now uses subnet masks from Sites.
  • The Subnet Grid report now handles errors more gracefully.
  • Login no longer fails for some users.
  • Search queries are now slightly faster across assets and services.

1.8.14

2020-07-02

  • Tasks are now searchable and sortable via the Search tab.
  • Numerical search queries work again.

1.8.13

2020-07-01

  • The Scan Configuration page now provides an estimated runtime through a confirmation dialog.
  • Trial accounts are no longer limited to scanning a /16 and can now scan a full /8.
  • The runZero Explorer now supports log configuration using the environment. See the documentation for details.
  • The runZero Explorer and runZero CLI now collect SSH pre-auth banners and host keys.
  • Bogus service responses from Fortigate helpers on ports 80 and 8008 are now ignored.
  • Fingerprint improvements.

1.8.12

2020-06-24

  • The runZero Explorer and runZero CLI now handle a wider range of ppp-based link types on Linux and macOS.
  • Bogus service responses from Fortigate helpers on ports 21, 25, 80, 110, 143, 8008, 8010, and 8020 are now ignored.
  • Fingerprint improvements.

1.8.11

2020-06-22

  • Bogus service responses from Cisco H.323 helpers on port 1720 are now ignored.
  • The runZero Explorer now stores additional diagnostics in the raw task data.
  • Fingerprint improvements.

1.8.10

2020-06-21

  • Bogus service responses from Fortigate SIP ALG helpers on ports 2000 and 5060 are now ignored.
  • HTTP handling of redirects and TLS+HTTP headers works again.
  • Fingerprint improvements.

1.8.9

2020-06-20

  • The runZero Explorer and runZero CLI now handle malformed HTTP responses and redirects better.
  • Fingerprint improvements.

1.8.8

2020-06-18

  • ICMP Echo probes now record the IP header information from the response (useful for Ripple20/Treck detection).
  • Rumble contributed its favicon.ico MD5 fingerprint database to the Recog project.

1.8.7

2020-06-16

  • The runZero Explorer and runZero CLI now support “cooked” interface types (ppp-based VPNs).
  • The scan engine now extracts additional information from Netgear routers.
  • Fingerprint coverage for Netgear routers has improved.

1.8.6

2020-06-15

  • Fingerprint improvements.

1.8.5

2020-06-15

  • Fingerprint improvements.

1.8.4

2020-06-15

  • Fingerprint improvements.

1.8.3

2020-06-14

  • Asset Inventory and Search Inventory performance has improved.
  • The bundled npcap driver in the runZero Explorer and runZero CLI for Windows is now version 0.9994.
  • Fingerprint improvements.

1.8.2

2020-06-09

  • The runZero CLI CSV output now includes populated UUID values.
  • The runZero CLI now creates a standalone bridges.json file for third-party processing.
  • Fingerprint improvements.

1.8.1

2020-06-09

  • Agent uninstalls no longer crash on BSD platforms.

1.8.0

2020-06-09

  • This release rolls up the 1.7.x changes listed below.

1.7.13

2020-06-08

  • Sites now support registered subnets. You can query assets via the associated Site subnet tags.
  • You can now set tags with empty values and query them more precisely through the Inventory search.
  • runZero now fingerprints assets via favicon.ico hashes.
  • The runZero CLI now creates a standalone topology.json file for third-party processing.
  • Assets now store the MAC-to-IP relationship in the hidden _macs.ipmap attribute.
  • The runZero Explorer and runZero CLI now support OpenBSD on x86 (64-bit).
  • Fingerprint improvements.

1.7.12

2020-06-05

  • The runZero Explorer no longer fails to restart automatically after an update on some Debian-based distributions.
  • Fingerprint improvements.

1.7.11

2020-06-04

  • A reliability bug in the runZero Explorer and runZero CLI for BSD-based platforms (macOS, FreeBSD, NetBSD, DragonFly BSD) no longer causes missing scan results in the TCP SYN and ARP probe responses.
  • The bundled npcap driver in the runZero Explorer and runZero CLI for Windows is now version 0.9992.

1.7.10

2020-06-02

  • The runZero Explorer and runZero CLI now support FreeBSD, NetBSD, and DragonFly BSD. FreeBSD and NetBSD support covers x86 (64-bit, 32-bit), ARM v5, ARM v6, and ARM v7. DragonFly BSD support covers x86 (64-bit).
  • The runZero Explorer and runZero CLI now support additional Linux architectures. These include x86 (64-bit, 32-bit), ARM v5, ARM v6, ARM v7, ARM 64-bit (aarch64), MIPS (BE/LE), MIPS64 (BE/LE), PowerPC64 (LE), and s390x (IBM Z).
  • The runZero Explorer now runs in standalone mode when it detects no supported services backend.
  • The runZero Explorer now supports automatic updates in standalone mode on non-Windows platforms.
  • The runZero Explorer binary now supports command-line flags (-h, -v, -l) and displays usage.

1.7.9

2020-05-27

  • MAC address fingerprints are now live. The initial set covers devices manufactured by Amazon, Google, Honeywell, August, SimpliSafe, TRENDnet, FLIR, Microsoft, Belkin, Meross, LG, Logitech, Hunter, Lutron, Orbit, Arlo, Panasonic, Sony, Vizio, Chameleon, iRobot, SharkNinja, Netatmo, Nintendo, HP, Intel, Lenovo, Dell, and PC Engines. runZero uses MAC fingerprints as a fallback when more precise fingerprinting is not available.
  • runZero now maps Microsoft SQL Server versions obtained from the network to specific releases and patch levels, so you can query for end-of-life versions and missing patches.
  • Chromecast devices now return additional service attributes, including information about the wireless network they connect to. Fingerprinting of older Chromecast models (Gen 1) has improved. MAC addresses and additional IP addresses from the Chromecast web endpoint now apply to the asset.
  • MySQL and MariaDB version detection now also applies the appropriate OS fingerprint, if known.
  • HTTP services that return JSON responses now camelCase the attribute names and support more data types. This affects JSON-based HTTP interfaces such as ElasticSearch and Riak HTTP.
  • OS and Hardware matching is now more precise after adjustments to the weighting and priorities. runZero should always choose the most precise and most confident fingerprint.
  • The asset-level match.score attribute now reports the confidence of the OS match. We may rename it to match.os.score in the future as we accommodate more granular hardware weights.
  • NTLMSSP-based OS matching now disqualifies systems that are obviously not Windows (BSD-based stacks, etc).
  • Brother printers now use distinct hardware and firmware (OS) fingerprints. This should address cases where the firmware version overrode the hardware model by mistake.
  • Release notes are now consolidated across the Platform, Agent, and CLI.
  • Versioning is now shared across the Platform, Agent, and CLI.

Release notes prior to 1.7.9

Before version 1.7.9, the Platform, Explorer, and CLI had separate release notes and version numbers. The archived release notes for each are linked below.

Updated