Add masscan+nuclei mode, operator tuning controls, and vars file support to webrunner

- New scan mode: masscan+nuclei — masscan finds open ip:port pairs,
  nuclei runs operator-supplied CVE template against discovered hosts
- Per-country vulnerable host count in merge output via CIDR→country lookup
- Tuning args on every scan: --nmap-timing, --nmap-timeout, --nmap-workers,
  --nuclei-rate, --nuclei-concurrency, --nuclei-timeout, --masscan-rate
- Vars file support: operator provides scan_vars.yaml to pre-fill all
  tuning settings without interactive prompts
- Templates copied to nodes at provision time — no live fetches (OPSEC)
- run_scan.yml passes all tuning args with Ansible defaults as fallback
- configure_node.yml installs nuclei binary + uploads template on demand
- Updated deployment summary shows mode-specific tuning params
- countries-format.md and targets-format.md updated for new capabilities
- scan_vars.yaml.example documents all configurable settings with comments
This commit is contained in:
n0mad1k
2026-05-02 14:49:24 -04:00
parent c34f9f0401
commit acb32ab3c6
9 changed files with 406 additions and 13 deletions
@@ -0,0 +1,31 @@
# scan_vars.yaml — WEBRUNNER pre-configuration
# Copy this file, fill in values, and provide the path at the "Vars file" prompt.
# All fields are optional. Omit any field to be prompted interactively.
# ── masscan ───────────────────────────────────────────────────────────────────
masscan_rate: 5000 # packets/sec (default: mode-dependent, 300010000)
# Lower for clients with strict IPS/rate-limiting
# ── nmap (masscan+nmap and geo-scout modes) ───────────────────────────────────
nmap_timing: 3 # T1=sneaky T2=polite T3=normal T4=aggressive (default: 4)
nmap_timeout: 120 # per-host timeout in seconds (default: 60)
# Increase for slow/filtered networks
nmap_workers: 10 # parallel nmap threads per node (default: 10)
# ── nuclei (masscan+nuclei mode only) ─────────────────────────────────────────
nuclei_template: "/path/to/your/cve-template.yaml"
# Local path — copied to nodes at provision time
# Never fetched from the internet during scans
nuclei_rate: 150 # requests/sec rate limit (default: 150)
# Lower for clients with WAF/rate-limiting
nuclei_concurrency: 25 # concurrent goroutines (default: 25)
nuclei_timeout: 10 # per-request timeout in seconds (default: 10)
# ── example: conservative client profile ─────────────────────────────────────
# masscan_rate: 1000
# nmap_timing: 2
# nmap_timeout: 180
# nmap_workers: 5
# nuclei_rate: 50
# nuclei_concurrency: 10
# nuclei_timeout: 20