Add WEBRUNNER distributed geo-targeted recon module
Multi-provider (Linode/AWS/FlokiNET) scan orchestration: - Flatten all country CIDRs, chunk by IP count (sprint/balanced/economy presets) - Assign chunks round-robin across providers - Cost+time estimate table before deploy - Ansible provisions N nodes in parallel, runs masscan/nmap/probe per node - Results fetched back and merged into unified JSON report - Scanner IPs logged per engagement for client IR reporting - Operator IP whitelisting, enhanced OPSEC mode, YAML targets.yaml support
This commit is contained in:
@@ -0,0 +1,92 @@
|
||||
---
|
||||
# WEBRUNNER — Distributed geo-targeted recon
|
||||
# Multi-provider: Linode, AWS, FlokiNET
|
||||
# Controller: ~/tools/c2itall/ (CWD when ansible-playbook runs)
|
||||
|
||||
- name: WEBRUNNER — Provision scan nodes
|
||||
hosts: localhost
|
||||
connection: local
|
||||
gather_facts: false
|
||||
vars:
|
||||
ansible_python_interpreter: "{{ ansible_playbook_python }}"
|
||||
ssh_key_name: "{{ ssh_key_path | basename | regex_replace('\\.pub$', '') }}"
|
||||
all_node_chunks: "{{ lookup('file', node_chunks_file) | from_json }}"
|
||||
|
||||
tasks:
|
||||
- name: Ensure results directory
|
||||
file:
|
||||
path: "{{ results_dir }}"
|
||||
state: directory
|
||||
mode: '0755'
|
||||
|
||||
- name: Initialize scanner IP log
|
||||
copy:
|
||||
content: "# WEBRUNNER scanner IPs — {{ webrunner_name }}\n"
|
||||
dest: "{{ scanner_ip_log }}"
|
||||
mode: '0644'
|
||||
force: false
|
||||
|
||||
- name: Provision Linode nodes
|
||||
include_tasks: "Linode/webrunner_provision_tasks.yml"
|
||||
loop: "{{ all_node_chunks | selectattr('provider', 'equalto', 'linode') | list }}"
|
||||
loop_var: node_chunk
|
||||
|
||||
- name: Provision AWS nodes
|
||||
include_tasks: "AWS/webrunner_provision_tasks.yml"
|
||||
loop: "{{ all_node_chunks | selectattr('provider', 'equalto', 'aws') | list }}"
|
||||
loop_var: node_chunk
|
||||
|
||||
- name: Provision FlokiNET nodes
|
||||
include_tasks: "FlokiNET/webrunner_provision_tasks.yml"
|
||||
loop: "{{ all_node_chunks | selectattr('provider', 'equalto', 'flokinet') | list }}"
|
||||
loop_var: node_chunk
|
||||
|
||||
|
||||
- name: WEBRUNNER — Configure and scan
|
||||
hosts: webrunner_nodes
|
||||
gather_facts: false
|
||||
become: true
|
||||
|
||||
tasks:
|
||||
- name: Wait for SSH
|
||||
wait_for_connection:
|
||||
delay: 20
|
||||
timeout: 300
|
||||
|
||||
- name: Configure node
|
||||
include_tasks: "{{ playbook_dir }}/../modules/webrunner/tasks/configure_node.yml"
|
||||
|
||||
- name: Run scan
|
||||
include_tasks: "{{ playbook_dir }}/../modules/webrunner/tasks/run_scan.yml"
|
||||
|
||||
- name: Collect results
|
||||
include_tasks: "{{ playbook_dir }}/../modules/webrunner/tasks/collect_results.yml"
|
||||
|
||||
|
||||
- name: WEBRUNNER — Merge and report
|
||||
hosts: localhost
|
||||
connection: local
|
||||
gather_facts: false
|
||||
|
||||
tasks:
|
||||
- name: Merge per-node results
|
||||
command: >
|
||||
python3 {{ playbook_dir }}/../modules/webrunner/tasks/merge_results.py
|
||||
--results-dir {{ results_dir }}
|
||||
--output {{ results_dir }}/merged_results.json
|
||||
--deployment-id {{ deployment_id }}
|
||||
register: merge_out
|
||||
ignore_errors: true
|
||||
|
||||
- name: Show merge output
|
||||
debug:
|
||||
var: merge_out.stdout_lines
|
||||
when: merge_out.stdout_lines is defined and merge_out.stdout_lines | length > 0
|
||||
|
||||
- name: Summary
|
||||
debug:
|
||||
msg:
|
||||
- "WEBRUNNER complete — {{ webrunner_name }}"
|
||||
- "Results: {{ results_dir }}/merged_results.json"
|
||||
- "Scanner IPs: {{ scanner_ip_log }}"
|
||||
- "Log: logs/deployment_{{ deployment_id }}.log"
|
||||
Reference in New Issue
Block a user