Early Console release notes

View as Markdown

Console release notes prior to 1.7.9

Please see the current release notes for recent updates.

v1.7.8

2020-05-23

  • The pre-login pages now have an updated style.
  • Account activation during registration is now smoother.

v1.7.7

2020-05-17

  • Restricted user accounts can now hold roles in multiple organizations.

v1.7.6

2020-05-14

  • Asset and Service attributes are now normalized. All keys are camelCase, and most service attributes are prefixed with the protocol name.

v1.7.5

2020-05-13

  • SMB v2 OS detection now weights Windows 10 more heavily than Server 2019 in most situations.
  • SMB v1 OS detection has improved for non-Windows platforms.

v1.7.4

2020-05-08

  • SSO now supports a default role of No Access. Accounts created through the SSO login process with this default role must be promoted manually to a usable account role.
  • Users can now hold a No Access role for both All Orgs and specific organizations.
  • The per-account Demo Organization is accessible again. Explorer and CLI downloads for the Demo Organization are now explicitly disabled. Any agents assigned to the Demo Organization uninstall automatically.
  • All runZero Console confirmation dialogs now name the specific item they are confirming. This helps prevent misclicks from removing the wrong item.
  • Non-Windows machines running SMB services are fingerprinted correctly again. A regression had classified some NAS devices as Microsoft Windows.

v1.7.3

2020-05-08

v1.7.2

2020-05-07

  • Asset correlation now ignores Cisco HSRP MAC addresses.

v1.7.1

2020-05-06

  • The agent details page now shows Explorer diagnostic information. This requires agent version 1.7.1 or later.

v1.7.0

2020-05-04

  • The Subnet Grid View report is now available through the Subnet Report.

  • You can now query the ts, tls.notBeforeTS, and tls.notAfterTS service fields with time comparison operators.

v1.6.10

2020-05-03

  • Scan schedules now show the day of the week for first, last, and next timestamps.
  • The validation error for invalid TCP ports is no longer obscured.
  • You can now limit Alert Rules to specific Sites or All Sites.
  • This release includes a dependency upgrade across the backend and frontend.

v1.6.7

2020-04-26

  • The recurring scan limits of the Starter Edition now work correctly.

v1.6.6

2020-04-23

  • The asset export no longer omits service details.

v1.6.5

2020-04-22

  • A free tier, the Starter Edition, is now available.

v1.6.4

2020-04-19

  • The dashboard now shows statistics for live assets only, instead of all assets.
  • The license view now excludes demo organizations and sites from its statistics.
  • The task view now shows scans pending processing more accurately.

v1.6.3

2020-04-18

  • The Asset and Service exports now include the service.address, service.transport, service.port, and service.vhost fields when present, which makes them more consistent with the runZero CLI assets.jsonl exports.

v1.6.2

2020-04-12

  • The new Analysis Reports section includes the Domain Membership and Service Attribute reports.
  • The new Query Library includes a set of predefined common queries.
  • You can now save inventory search queries to the Query Library.
  • Inventory search action buttons are now slimmer.
  • The Explore tab links to the Analysis Reports and Query Library.

v1.6.1

2020-04-07

  • Superusers can now use the Team page to manually unlock accounts that were temporarily locked after failed logins.

v1.6.0

2020-04-06

  • Data retention controls are now available on the Organization Settings page. You can use them to set data retention periods and remove stale offline assets after a fixed period.

  • Inventory, Site, and Organization search now support exact matches with the = prefix. For example, name:=SERVER01 matches an exact hostname.

  • Inventory, Site, and Organization search now support matching empty fields with the = prefix. For example, name:= matches an empty hostname.

  • Inventory searches now support the mac-vendor_count, macvendor_count, and vendor_count terms.

  • Inventory Asset and Service search now support the haspublic, hasprivate, hasipv6, and haslinklocal terms.

  • Inventory Asset and Service search now support % as a wildcard for address matching. The query address:%.0.1 finds all assets with an address ending in .0.1.

  • Searches for fewer than one hostname (name_count:0 and name_count:<1) now work.

  • Active and Failed scan tasks now support the Copy action. Copied scans that were scheduled in the past default to starting at the current time.

  • Single Sign On users can now set the default organization role for SSO-enrolled users.

  • Accounts now lock after 10 failed password-based login attempts.

v1.5.6

2020-04-01

  • The Screenshot Inventory now sorts by address instead of port number by default.

v1.5.5

2020-03-27

  • The Asset Inventory now lets you query attributes that conflict with a keyword by using the _asset. prefix.
  • The Service Inventory now lets you query attributes that conflict with a keyword by using the _service. prefix.

v1.5.4

2020-03-24

  • Fingerprinting improvements for HTTP, X509, Telnet, SSH, FTP, and SIP.

v1.5.3

2020-03-22

  • Scan tasks now have a configurable grace period. Setting it to zero or a negative value makes the scheduler retry indefinitely until an agent becomes available.

v1.5.2

2020-03-15

  • Web services with multiple asset icons now show each icon correctly.
  • Site imports work again.
  • Superusers can now log in directly when SSO is in required mode.

v1.5.1

2020-03-09

  • Asset icons now load lazily as they scroll into the viewport.
  • Asset icon URLs are now more cache friendly.
  • Page meta tags received small tweaks.

v1.5.0

2020-03-04

  • The asset inventory now displays any HTTP and UPnP icons acquired during the scan.
  • The asset inventory now displays an icon for assets with available screenshots.
  • The inventory search no longer triggers an error on some grouped query corner cases.
  • The inventory search now supports /32 masks for the net and cidr keywords.
  • The inventory search now treats the type keyword as an exact match.
  • The inventory search now supports filtering by service count.
  • The inventory search now supports filtering by the RTT and TTL fields.
  • The inventory search for services now supports filtering by port range.
  • The asset detail page now describes upstream and downstream layer 2 links.
  • The asset detail page now lists all acquired icons in the top summary.
  • The asset detail page menu now includes a Scan action.
  • The new scan page can now apply a list of tags to all identified assets.
  • Agent selection on the new scan page now defaults to the first site-specific agent.
  • The tasks page now lets you pause and unpause recurring scans.
  • The console now always shows the live agent count on the navigation menu.
  • The console now applies styling to the print view.
  • Asset correlation now ignores hostnames with leading digits.
  • The correct timezone is now used after SSO login.
  • Scans triggered through the API now default to the site scope when no targets are specified.
  • Scans triggered through the API can now specify a list of tags to apply to all identified assets.
  • Import tasks with the wrong data format are now rejected before task creation.

v1.4.5

2020-02-19

  • Completed tasks now always appear in the order they finished, rather than the order they were created.
  • A Cisco IOS fallback fingerprint that led to false positives is now disabled.

v1.4.4

2020-02-15

  • The License page now lists invoices and lets you update payment methods.
  • Asset correlation now uses the SMB Server GUID attribute to match results to assets.
  • Asset correlation now uses the SNMP sysName and sysObjectID attributes to unmatch assets that changed IPs or were mistakenly matched through another attribute, such as a shared bogus MAC address.

v1.4.3

2020-02-13

  • Active agents are no longer treated as offline.
  • Windows agents are now limited to a single concurrent scan to avoid resource contention.

v1.4.2

2020-02-09

  • Changes in source TTLs on external segments no longer disqualify an asset match during correlation.
  • Email templates and task displays received cosmetic updates.

v1.4.1

2020-02-05

  • This release updates several JavaScript and backend dependencies.

v1.4.0

2020-02-04

  • Version 1.4.0 is a rollup of post-1.3.0 point release work.

v1.3.5

2020-02-02

  • Scans can now specify the SNMP v3 Context for devices that require it, such as CatOS.
  • Scans now support the “Fast” option for the ARP probe, which is on by default in AWS VPC environments.
  • Explorers now support concurrent scans, with a limit you can configure per agent.
  • Asset correlation now avoids accidental grouping when a forged MAC address appears in routed protocol responses such as NetBIOS and SNMP.
  • Change reports now ignore differences in reverse DNS, hostnames, domain names, and the top-level service count.
  • Recurring, scheduled, and queued tasks without an available agent are now marked as failed after 4 hours. Recurring tasks then attempt to run scans normally during the next scheduled period.
  • CLI binaries for OEM customers now behave according to the license agreement.
  • The task list now truncates long task names automatically.

v1.3.4

2020-01-29

  • The failed tasks tab now shows a longer history by default.

v1.3.3

2020-01-29

  • This release includes minor JavaScript and backend dependency upgrades.

v1.3.2

2020-01-28

  • Search queries can now use parentheses to group terms, for example: os:linux AND (port:22 OR port:80) AND NOT port:3306.

v1.3.1

2020-01-15

  • The Export API now supports an asset sync backend with checkpointing based on the created_at or updated_at fields.

v1.3.0

2020-01-07

  • Version 1.3.0 is a rollup of post-1.2.0 point release work.

v1.2.9

2020-01-04

v1.2.8

2019-12-29

  • The Teams view now separates members, who have access to all organizations, from restricted users, who have access to single organizations.
  • Team member invitations now set the Reply-To header to the inviting user.
  • Team member invitations can now include custom subject lines and messages.
  • Active tasks now always sort by start time rather than last update time.
  • Tasks created or updated after v1.2.2 now always show the created by field.
  • The search warnings field now clears after each new query.
  • The search timestamp fields now default to less-than (<) when no operator is specified.

v1.2.7

2019-12-28

  • The Active Tasks tab now has a Clear Queue button that removes all queued tasks.

v1.2.6

2019-12-27

  • You can now sort and search Sites and Organizations.

v1.2.5

2019-12-26

  • The Beta discount is officially retired.
  • The end-of-year discount is valid until 2019 ends.

v1.2.4

2019-12-19

  • New scans now support BACnet.
  • Leading and trailing spaces in Site and Organization names are now removed.

v1.2.3

2019-12-13

  • This release adds many new fingerprints for HTTP and SIP endpoints. These may trigger asset change notifications because device and service recognition has improved.
  • Network scans now appropriately handle segments where a device responds to all ARP requests with the same MAC address.
  • The SIP protocol is now reported properly on UDP SIP responses.

v1.2.2

2019-12-10

  • Tasks now track which user created or last updated them.

v1.2.1

2019-12-05

  • SSO configurations with multiple IdP x509 certificates now validate against any certificate in the list, not just the first.

v1.2.0

2019-12-01

  • Version 1.2.0 is a rollup of post-1.1.0 point release work.

v1.1.9

2019-12-01

  • The new wlan-list probe provides initial support for the Wireless Inventory.

v1.1.8

2019-11-27

  • Some Inventory columns now display with the correct encoding.

v1.1.7

2019-11-24

  • Copying an older scan now sets the Scan Max Group Size to a reasonable default.
  • The Copy action no longer creates names with more than one “Copy of” prefix by default.

v1.1.6

2019-11-19

  • The scan configuration now accepts SNMP v3 credentials.

v1.1.5

2019-11-19

  • The Switch Topology report is now available from the Inventory reports menu.
  • Assets that respond to SNMP enumeration of the CAM/MAC table are now automatically classified as switches.

v1.1.4

2019-11-18

  • The email notifier no longer fails to deliver in rare circumstances.

v1.1.3

2019-11-14

  • The Network Bridges report is now more readable.

v1.1.2

2019-11-11

  • The new agent inventory search term accepts a UUID as well as the agent name.

v1.1.1

2019-11-08

  • Email notifications are now sent for expiring, deactivating, and unused trial accounts.

v1.1.0

2019-11-05

  • Version 1.1.0 is a rollup of post-1.0.0 point release work.

v1.0.20

2019-11-04

  • OS detection now prefers the most granular fingerprint when multiple fingerprints match.
  • Stopped tasks now appear in the Failed list instead of the Completed list.
  • Scans now support the Max Group Size option to limit the number of concurrent scan targets.
  • The site inventory search term now accepts a UUID as well as the site name.
  • The task inventory search term now shows all assets last updated by a given task ID.
  • Asset change notifications no longer treat the lowest_ttl field as a significant change.
  • Assets are no longer stored with only IPv6 link-local addresses.
  • OS version numbers are now tracked properly.
  • Hostname-based OS matching no longer overrides more reliable fingerprints.

v1.0.19

2019-11-01

  • Trial accounts and their associated data are now removed automatically two weeks after the license period expires.

v1.0.18

2019-10-31

  • The Network Bridges report now supports filtering using the same syntax as the Asset Inventory search.
  • The Network Bridges report is now much faster, although nodes are no longer draggable.
  • The Network Bridges report now supports up to 1,000 multi-homed nodes at a time.
  • The Completed Tasks view no longer shows tasks in a Cancelled or Error state. These now appear under Failed Tasks.
  • The Asset Inventory view now lets you merge multiple assets into a single asset.

v1.0.17

2019-10-26

  • You can now clear failed tasks with the Clear action button.

v1.0.16

2019-10-25

  • The Export API now treats the Organization ID in the URL as optional.
  • The Asset and Services inventory now support the id search term to find assets by ID.

v1.0.15

2019-10-25

  • The Export API now returns a list of sites in CSV, JSON, and JSONL formats.
  • The change summary titles in the task view now link to their respective sections in the body.

v1.0.14

2019-10-24

  • This release fixes a small number of typos and cosmetic issues in the web console.

v1.0.13

2019-10-23

  • The SYN probe now retries twice if it receives no RST. This improves reliability at the cost of slightly longer scan times. You can change the retry count with the syn-max-retries advanced parameter for the SYN probe in the new scan configuration screen.

v1.0.8

2019-10-18

  • Single Sign On support (SAML2) is now available for all users through the SSO Settings button on the My Team page.

v1.0.7

2019-10-07

  • This release fixes a handful of small cosmetic issues in the web interface.

v1.0.6

2019-10-08

  • The asset correlation algorithm now accepts looser matches for TCP/IP stack fingerprints when matching an asset by IP address. This reduces the chance of asset churn when one or more services change between scan runs.

v1.0.5

2019-10-07

  • Scan tasks now have Name and Description fields. You can set them during task creation and update them in Recurring and Scheduled tasks. The main task view shows these fields right after the task type.
  • You can now copy an existing scan task to a new scan configuration with the Copy action in the task list. This makes it simpler to run a one-off scan from an existing recurring scan definition.
  • Less common scan options now live in the Advanced Scan Options section, which is visible by default on the scan configuration page.
  • The Team Manage menu now includes an option for superusers to reset a team member’s security tokens.
  • The Sites listing now links the site name to the inventory search query. To edit the Site definition, use the Update Site action from the Modify menu.

v1.0.3

2019-10-06

  • A race condition no longer causes some scan tasks to fail with the error agent failed to queue task.
  • The console received minor cosmetic improvements.

v1.0.2

2019-10-03

  • CLI downloads no longer have a license expiration set in the past.
  • The task scheduler is now more tolerant of temporary network errors when queueing scans.

v1.0.0

2019-10-01

Updated