{"id":51989,"date":"2022-01-11T09:00:35","date_gmt":"2022-01-11T08:00:35","guid":{"rendered":"https:\/\/nolabnoparty.com\/?p=51989"},"modified":"2022-01-09T15:22:05","modified_gmt":"2022-01-09T14:22:05","slug":"runecast-analyzer-6-0-with-os-level-analysis-and-log4j-scan","status":"publish","type":"post","link":"https:\/\/nolabnoparty.com\/en\/runecast-analyzer-6-0-with-os-level-analysis-and-log4j-scan\/","title":{"rendered":"Runecast Analyzer 6.0 with OS-level analysis and Log4J scan"},"content":{"rendered":"<p><img decoding=\"async\" class=\"aligncenter wp-image-51995 size-full\" title=\"runecast-analyzer-60-os-level-analysis-log4j-scan-01\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2022\/01\/runecast-analyzer-60-os-level-analysis-log4j-scan-01.jpg\" alt=\"runecast-analyzer-60-os-level-analysis-log4j-scan-01\" width=\"602\" height=\"202\" \/><\/p>\n<p>Latest <a href=\"https:\/\/nolabnoparty.com\/en\/runecast-analyzer-5-1-with-configuration-vault-and-remediation\/\">Runecast Analyzer<\/a> 6.0 introduces the new <strong>OS-level analysis<\/strong> for Windows and Linux as well as the <strong>Log4j vulnerability scan<\/strong>.<\/p>\n<p>Windows and Linux OSs can now be scanned against <strong>vulnerabilities and security compliance<\/strong> extending the supported environments by Runecast besides <a href=\"https:\/\/nolabnoparty.com\/runecast-analyzer-vcenter-server-plugin-configurazione\/\">VMware<\/a>, <a href=\"https:\/\/nolabnoparty.com\/runecast-analyzer-4-0-con-analisi-aws\/\">AWS<\/a>, <a href=\"https:\/\/nolabnoparty.com\/runecast-analyzer-5-0-con-analisi-azure\/\">Azure<\/a>, <a href=\"https:\/\/nolabnoparty.com\/runecast-analyzer-4-5-con-analisi-per-kubernetes\/\">Kubernetes<\/a>, etc.<!--more--><\/p>\n<p>If you have configured Runecast Analyzer to receive <strong>automatic updates<\/strong>, when you access the program a pop-up message informs you about a <strong>new version installed<\/strong>.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-51997 size-full\" title=\"runecast-analyzer-60-os-level-analysis-log4j-scan-02\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2022\/01\/runecast-analyzer-60-os-level-analysis-log4j-scan-02.jpg\" alt=\"runecast-analyzer-60-os-level-analysis-log4j-scan-02\" width=\"329\" height=\"377\" \/><\/p>\n<p>At the time of writing, latest available Runecast <strong>version is 6.0.4.1<\/strong>. Check out the <a href=\"https:\/\/www.runecast.com\/release-notes\" target=\"_blank\" rel=\"noopener\">Release Notes<\/a> for additional details.<\/p>\n<p>&nbsp;<\/p>\n<h2>OS-level analysis<\/h2>\n<p>Windows and Linux are the supported OSs in version 6.0. Despite the <strong>limited number of Linux distributions<\/strong> currently supported, more distributions will be added in the next Runecast releases.<\/p>\n<p>From a <strong>single pane of glass<\/strong> you can have an overview of the <strong>security status<\/strong> for the supported environments.<\/p>\n<p>&nbsp;<\/p>\n<h4>Enable OS-level analysis<\/h4>\n<p>OS-level analysis feature supports both <strong>physical and virtual machines<\/strong> and must be enabled in the program since it is <strong>not active by default<\/strong>.<\/p>\n<p>From the Runecast dashboard go to <strong>Settings &gt; Connections<\/strong> and click <strong>Activate OS connection<\/strong>\u00a0button under <strong>Operating System connection settings<\/strong>.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-51999 size-large\" title=\"runecast-analyzer-60-os-level-analysis-log4j-scan-03\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2022\/01\/runecast-analyzer-60-os-level-analysis-log4j-scan-03-600x272.jpg\" alt=\"runecast-analyzer-60-os-level-analysis-log4j-scan-03\" width=\"600\" height=\"272\" \/><\/p>\n<p>Enter the <strong>Runecast Address<\/strong> of your appliance and click <strong>Continue<\/strong>.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-52005 size-full\" title=\"runecast-analyzer-60-os-level-analysis-log4j-scan-04\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2022\/01\/runecast-analyzer-60-os-level-analysis-log4j-scan-04.jpg\" alt=\"runecast-analyzer-60-os-level-analysis-log4j-scan-04\" width=\"600\" height=\"519\" \/><\/p>\n<p>When the OS analysis service has been activated, click <strong>Finish<\/strong>.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-52007 size-full\" title=\"runecast-analyzer-60-os-level-analysis-log4j-scan-05\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2022\/01\/runecast-analyzer-60-os-level-analysis-log4j-scan-05.jpg\" alt=\"runecast-analyzer-60-os-level-analysis-log4j-scan-05\" width=\"600\" height=\"519\" \/><\/p>\n<p>Now click <strong>Install OS agents<\/strong> to download the agents for the supported OSs.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-52009 size-large\" title=\"runecast-analyzer-60-os-level-analysis-log4j-scan-06\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2022\/01\/runecast-analyzer-60-os-level-analysis-log4j-scan-06-600x108.jpg\" alt=\"runecast-analyzer-60-os-level-analysis-log4j-scan-06\" width=\"600\" height=\"108\" \/><\/p>\n<p>Click the <strong>desired OS agent package<\/strong> button to download the installation package and save it anywhere in your computer. Click <strong>Close<\/strong> when done.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-52011 size-large\" title=\"runecast-analyzer-60-os-level-analysis-log4j-scan-07\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2022\/01\/runecast-analyzer-60-os-level-analysis-log4j-scan-07-600x368.jpg\" alt=\"runecast-analyzer-60-os-level-analysis-log4j-scan-07\" width=\"600\" height=\"368\" \/><\/p>\n<p>When the required packages have been downloaded, <strong>deploy the packages<\/strong> to the machines to analyze.<\/p>\n<p>&nbsp;<\/p>\n<h4>Install Windows agent<\/h4>\n<p>Runecast Windows agent can be deployed in two ways:<\/p>\n<ul>\n<li>via GPO if Active Directory environment is available<\/li>\n<li>manual installation<\/li>\n<\/ul>\n<p>To manually install the agent, <strong>copy the package<\/strong> to the Windows machine and <strong>unzip<\/strong> the file. Then right click the <em>install-osquery.ps1<\/em>\u00a0file and select\u00a0<strong>Run with PowerShell<\/strong>.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-52013 size-large\" title=\"runecast-analyzer-60-os-level-analysis-log4j-scan-08\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2022\/01\/runecast-analyzer-60-os-level-analysis-log4j-scan-08-600x420.jpg\" alt=\"runecast-analyzer-60-os-level-analysis-log4j-scan-08\" width=\"600\" height=\"420\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Type <strong>y<\/strong> to run the script.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-52015 size-large\" title=\"runecast-analyzer-60-os-level-analysis-log4j-scan-09\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2022\/01\/runecast-analyzer-60-os-level-analysis-log4j-scan-09-600x193.jpg\" alt=\"runecast-analyzer-60-os-level-analysis-log4j-scan-09\" width=\"600\" height=\"193\" \/><\/p>\n<p>When the installation has been completed, you may need to <strong>reboot the machine<\/strong>\u00a0to activate the service.<\/p>\n<p>&nbsp;<\/p>\n<h4>Install Linux agent<\/h4>\n<p>Using a tool like WinSCP, <strong>copy the Runecast agent package<\/strong> to the Linux machine.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-52017 size-large\" title=\"runecast-analyzer-60-os-level-analysis-log4j-scan-10\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2022\/01\/runecast-analyzer-60-os-level-analysis-log4j-scan-10-600x337.jpg\" alt=\"runecast-analyzer-60-os-level-analysis-log4j-scan-10\" width=\"600\" height=\"337\" \/><\/p>\n<p><strong>Extract the content<\/strong> from the file with the <em>tar<\/em> command.<\/p>\n<p><span style=\"color: #0000ff;\"># sudo tar xzvf runecast-deb-osquery_5.0.1-1.linux_amd64.tar.gz<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-52019 size-large\" title=\"runecast-analyzer-60-os-level-analysis-log4j-scan-11\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2022\/01\/runecast-analyzer-60-os-level-analysis-log4j-scan-11-600x150.jpg\" alt=\"runecast-analyzer-60-os-level-analysis-log4j-scan-11\" width=\"600\" height=\"150\" \/><\/p>\n<p>Go to the just created <em>runecast-deb-osquery_5.0.1-1.linux_amd64<\/em> directory.<\/p>\n<p><span style=\"color: #0000ff;\"># cd runecast-deb-osquery_5.0.1-1.linux_amd64<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-52021 size-large\" title=\"runecast-analyzer-60-os-level-analysis-log4j-scan-12\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2022\/01\/runecast-analyzer-60-os-level-analysis-log4j-scan-12-600x44.jpg\" alt=\"runecast-analyzer-60-os-level-analysis-log4j-scan-12\" width=\"600\" height=\"44\" \/><\/p>\n<p>Run the <em>install-osquery-deb.sh<\/em> script to <strong>install the agent<\/strong>.<\/p>\n<p><span style=\"color: #0000ff;\"># sudo .\/install-osquery-deb.sh<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-52023 size-large\" title=\"runecast-analyzer-60-os-level-analysis-log4j-scan-13\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2022\/01\/runecast-analyzer-60-os-level-analysis-log4j-scan-13-600x141.jpg\" alt=\"runecast-analyzer-60-os-level-analysis-log4j-scan-13\" width=\"600\" height=\"141\" \/><\/p>\n<p>&nbsp;<\/p>\n<h4>Check installed machines<\/h4>\n<p>To check installed machines with the Runecast agent, go to <strong>Connections<\/strong> tab and click on <strong>Show Details<\/strong> link in the <strong>Host with agents<\/strong> column. The number indicates the current installed machines.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-52025 size-large\" title=\"runecast-analyzer-60-os-level-analysis-log4j-scan-14\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2022\/01\/runecast-analyzer-60-os-level-analysis-log4j-scan-14-600x107.jpg\" alt=\"runecast-analyzer-60-os-level-analysis-log4j-scan-14\" width=\"600\" height=\"107\" \/><\/p>\n<p>The list of installed machines is displayed.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-52027 size-large\" title=\"runecast-analyzer-60-os-level-analysis-log4j-scan-15\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2022\/01\/runecast-analyzer-60-os-level-analysis-log4j-scan-15-600x371.jpg\" alt=\"runecast-analyzer-60-os-level-analysis-log4j-scan-15\" width=\"600\" height=\"371\" \/><\/p>\n<p>&nbsp;<\/p>\n<h4>Perform the OS-level analysis<\/h4>\n<p>To analyze your Windows and Linux machines, click <strong>Analyze now<\/strong> button. The new <strong>Operating Systems<\/strong> item is now available in the list of supported environments. Click <strong>Analyze<\/strong> to proceed.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-52029 size-large\" title=\"runecast-analyzer-60-os-level-analysis-log4j-scan-16\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2022\/01\/runecast-analyzer-60-os-level-analysis-log4j-scan-16-600x268.jpg\" alt=\"runecast-analyzer-60-os-level-analysis-log4j-scan-16\" width=\"600\" height=\"268\" \/><\/p>\n<p>Selected environments are being scanned.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-52031 size-full\" title=\"runecast-analyzer-60-os-level-analysis-log4j-scan-17\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2022\/01\/runecast-analyzer-60-os-level-analysis-log4j-scan-17.jpg\" alt=\"runecast-analyzer-60-os-level-analysis-log4j-scan-17\" width=\"519\" height=\"114\" \/><\/p>\n<p>To check the result, select <strong>Operating Systems<\/strong> from the <strong>All Systems<\/strong> drop-down menu.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-52033 size-large\" title=\"runecast-analyzer-60-os-level-analysis-log4j-scan-18\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2022\/01\/runecast-analyzer-60-os-level-analysis-log4j-scan-18-600x342.jpg\" alt=\"runecast-analyzer-60-os-level-analysis-log4j-scan-18\" width=\"600\" height=\"342\" \/><\/p>\n<p>The <strong>Operating Systems Dashboard<\/strong> displays the result of the analysis.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-52035 size-large\" title=\"runecast-analyzer-60-os-level-analysis-log4j-scan-19\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2022\/01\/runecast-analyzer-60-os-level-analysis-log4j-scan-19-600x302.jpg\" alt=\"runecast-analyzer-60-os-level-analysis-log4j-scan-19\" width=\"600\" height=\"302\" \/><\/p>\n<p>&nbsp;<\/p>\n<h2>Log4J vulnerability scan<\/h2>\n<p>Since <strong>version 6.0.2.0<\/strong>, Runecast Analyzer can can detect <strong>Apache Log4j Java library vulnerability<\/strong> (<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-44228\" target=\"_blank\" rel=\"noopener\">CVE-2021-44228<\/a>) on Windows, Linux, and VMware environments.<\/p>\n<p>Just click the <strong>Analyze now<\/strong> button and wait until the scan completes. Go to <strong>Vulnerabilities<\/strong> section to check which <strong>Products<\/strong> are affected by the CVE-2021-44228 vulnerability.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-52037 size-large\" title=\"runecast-analyzer-60-os-level-analysis-log4j-scan-20\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2022\/01\/runecast-analyzer-60-os-level-analysis-log4j-scan-20-600x402.jpg\" alt=\"runecast-analyzer-60-os-level-analysis-log4j-scan-20\" width=\"600\" height=\"402\" \/><\/p>\n<blockquote><p>Runecast is currently offering a <a href=\"https:\/\/nolabnoparty.com\/en\/runecast-free-log4shell-vulnerability-scan\/\">free scan of your environments<\/a> against Log4J vulnerability.<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<h2>Security profiles<\/h2>\n<p>Runecast added new security profiles support, such as <strong>BSI and GDPR for Azure<\/strong> and <strong>DISA STIG for vSphere 6.7<\/strong>.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-52039 size-large\" title=\"runecast-analyzer-60-os-level-analysis-log4j-scan-21\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2022\/01\/runecast-analyzer-60-os-level-analysis-log4j-scan-21-600x405.jpg\" alt=\"runecast-analyzer-60-os-level-analysis-log4j-scan-21\" width=\"600\" height=\"405\" \/><\/p>\n<p>Runecast Analyzer 6.0 is available to download as <a href=\"https:\/\/portal.runecast.com\/registration\" target=\"_blank\" rel=\"noopener\">14-day trial<\/a>.<\/p>\n<p><img decoding=\"async\" title=\"signature\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/images\/firma.jpg\" alt=\"signature\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Latest Runecast Analyzer 6.0 introduces the new OS-level analysis for Windows and Linux as well as the Log4j vulnerability scan. Windows and Linux OSs can now be scanned against vulnerabilities and security compliance extending the supported environments by Runecast besides VMware, AWS, Azure, Kubernetes, etc.<\/p>\n","protected":false},"author":3,"featured_media":51995,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"rop_custom_images_group":[],"rop_custom_messages_group":[],"rop_publish_now":"initial","rop_publish_now_accounts":{"linkedin_93tdZWzMZc_93tdZWzMZc":"","facebook_2879994398731222_17841400390232720":"","twitter_113568041_113568041":"","mastodon_115463926174894442_115463926174894442":""},"rop_publish_now_history":[],"rop_publish_now_status":"pending","footnotes":""},"categories":[1729,903],"tags":[1897,2424,2430,1727],"class_list":["post-51989","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-runecast-en","category-vmware-en","tag-analysis","tag-log4j","tag-os-level","tag-runecast","has_thumb"],"_links":{"self":[{"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/posts\/51989","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/comments?post=51989"}],"version-history":[{"count":0,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/posts\/51989\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/media\/51995"}],"wp:attachment":[{"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/media?parent=51989"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/categories?post=51989"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/tags?post=51989"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}