Skip to content

runZero

An agentless, credential-less asset discovery and exposure management platform — formerly Rumble Network Discovery — built by Metasploit creator HD Moore to inventory IT, OT, IoT, and cloud assets that other tools miss.

Visit Website ↗ + Add to Compare
68/100Incremental Innovator

Overview

runZero, founded in 2019 in Austin, Texas as Rumble Network Discovery before rebranding in August 2022, solves a problem most attack surface tools only partly address: finding the assets an organization does not already know it has. Its scanner fingerprints devices across IT, OT, IoT, cloud, and mobile without requiring agents or credentials, running from a lightweight command-line binary on Windows, macOS, and multiple Linux architectures — down to hardware as small as a Raspberry Pi — while the management layer runs in the cloud or on-premises.

The company was founded by HD Moore, the creator of the Metasploit penetration testing framework, which gives runZero a level of technical credibility in the security research community that most asset-discovery vendors don’t carry. That pedigree shows up in the product’s positioning: rather than relying on a CMDB or endpoint agent (both of which only see what’s already been enrolled), runZero actively probes the network to surface shadow IT, forgotten OT/ICS equipment, and unmanaged IoT devices that create real, exploitable blind spots.

Commercially, runZero raised a $15 million Series A in March 2022 led by Decibel Partners and has grown to roughly 75 employees, with the platform now marketed around exposure management and attack path mapping in addition to core asset discovery. It has become a frequently cited reference point in security press coverage (Dark Reading, among others) of the asset-inventory and exposure-management category.

For CISOs, the practical value is straightforward: you cannot secure or patch what you don’t know exists, and runZero’s agentless approach means it can surface assets that agent-based and credentialed tools structurally cannot reach, including networks and OT segments where deploying agents isn’t feasible.

Innovation Matrix Assessment

Innovation Velocity 7/10

The company has iterated from a pure network-scanner (Rumble) through a full rebrand and platform expansion into OT/IoT/cloud/mobile exposure management and attack-path mapping in the space of a few years, tracked publicly through its own release blog history.

Operational Value 7/10

The agentless, credential-less scanner runs across Windows, macOS, and multiple Linux architectures down to Raspberry Pi-class hardware, and the company has scaled to roughly 75 employees supporting production deployments across IT and OT environments.

Market Momentum 6/10

A $15M Series A led by Decibel Partners (March 2022) and steady headcount growth to ~75 employees show real but not explosive commercial momentum for a still-independent, single-round-funded company.

Category Disruption 7/10

Agentless, credential-less fingerprinting that reaches OT/ICS and IoT devices where agents can't be deployed is structurally different from CMDB- and agent-based asset inventory approaches, and is a meaningful part of why the product carved out its own category recognition.

Real-World Efficacy 6/10

Founder HD Moore's track record building Metasploit lends real technical credibility, and the product is regularly cited in independent security press (Dark Reading covered the rebrand directly), though no formal third-party red-team or MITRE-style evaluation of detection accuracy was found.

Enduring Relevance 8/10

Asset visibility is foundational to nearly every other security control, and the growth of unmanaged IoT/OT and shadow cloud assets makes agentless discovery increasingly central to attack surface management programs.

Why CISOs Should Care

runZero finds the devices a CISO's other tools structurally cannot see — unmanaged IoT, forgotten OT/ICS gear, and shadow IT — because it doesn't depend on an agent already being installed or credentials already being known.

What Makes It Different

Most competitors in asset inventory lean on agents or a CMDB; runZero's agentless, credential-less active fingerprinting reaches segments and device types those approaches structurally miss.

The Matrix Verdict

68/100 — INCREMENTAL INNOVATOR

A technically well-regarded, founder-credible attack surface management tool with real differentiation in coverage breadth; still a single-round-funded independent company, so its long-term trajectory versus larger ASM platforms remains to be proven.

Editorial Note: Claims vs. Verified Findings

Independently verifiable: the 2022 rebrand from Rumble to runZero, the $15M Series A led by Decibel Partners, and HD Moore's identity as founder and Metasploit creator are all corroborated by Dark Reading and the company's own press page. Not independently verified: any specific detection-accuracy or scan-coverage percentage claims, which were not found published with third-party backing.

Sources