Add masscan+nuclei mode, operator tuning controls, and vars file support to webrunner

- New scan mode: masscan+nuclei — masscan finds open ip:port pairs,
  nuclei runs operator-supplied CVE template against discovered hosts
- Per-country vulnerable host count in merge output via CIDR→country lookup
- Tuning args on every scan: --nmap-timing, --nmap-timeout, --nmap-workers,
  --nuclei-rate, --nuclei-concurrency, --nuclei-timeout, --masscan-rate
- Vars file support: operator provides scan_vars.yaml to pre-fill all
  tuning settings without interactive prompts
- Templates copied to nodes at provision time — no live fetches (OPSEC)
- run_scan.yml passes all tuning args with Ansible defaults as fallback
- configure_node.yml installs nuclei binary + uploads template on demand
- Updated deployment summary shows mode-specific tuning params
- countries-format.md and targets-format.md updated for new capabilities
- scan_vars.yaml.example documents all configurable settings with comments
This commit is contained in:
n0mad1k
2026-05-02 14:49:24 -04:00
parent c34f9f0401
commit acb32ab3c6
9 changed files with 406 additions and 13 deletions
@@ -15,6 +15,7 @@
- nmap
- python3
- python3-pip
- curl
state: present
retries: 3
delay: 10
@@ -76,3 +77,22 @@
mode: '0644'
when: scan_mode == 'geo-scout' and targets_file != ""
ignore_errors: true
- name: Install nuclei vulnerability scanner
shell: |
if ! command -v nuclei &>/dev/null; then
curl -sL "https://github.com/projectdiscovery/nuclei/releases/download/v3.3.9/nuclei_3.3.9_linux_amd64.tar.gz" | tar -xz -C /usr/local/bin nuclei
chmod +x /usr/local/bin/nuclei
fi
args:
executable: /bin/bash
when: scan_mode == 'masscan+nuclei'
retries: 2
delay: 5
- name: Upload nuclei template
copy:
src: "{{ nuclei_template_local }}"
dest: /root/webrunner/nuclei_template.yaml
mode: '0644'
when: scan_mode == 'masscan+nuclei' and nuclei_template_local | default('') != ''