Add masscan+nuclei mode, operator tuning controls, and vars file support to webrunner
- New scan mode: masscan+nuclei — masscan finds open ip:port pairs, nuclei runs operator-supplied CVE template against discovered hosts - Per-country vulnerable host count in merge output via CIDR→country lookup - Tuning args on every scan: --nmap-timing, --nmap-timeout, --nmap-workers, --nuclei-rate, --nuclei-concurrency, --nuclei-timeout, --masscan-rate - Vars file support: operator provides scan_vars.yaml to pre-fill all tuning settings without interactive prompts - Templates copied to nodes at provision time — no live fetches (OPSEC) - run_scan.yml passes all tuning args with Ansible defaults as fallback - configure_node.yml installs nuclei binary + uploads template on demand - Updated deployment summary shows mode-specific tuning params - countries-format.md and targets-format.md updated for new capabilities - scan_vars.yaml.example documents all configurable settings with comments
This commit is contained in:
@@ -15,6 +15,7 @@
|
||||
- nmap
|
||||
- python3
|
||||
- python3-pip
|
||||
- curl
|
||||
state: present
|
||||
retries: 3
|
||||
delay: 10
|
||||
@@ -76,3 +77,22 @@
|
||||
mode: '0644'
|
||||
when: scan_mode == 'geo-scout' and targets_file != ""
|
||||
ignore_errors: true
|
||||
|
||||
- name: Install nuclei vulnerability scanner
|
||||
shell: |
|
||||
if ! command -v nuclei &>/dev/null; then
|
||||
curl -sL "https://github.com/projectdiscovery/nuclei/releases/download/v3.3.9/nuclei_3.3.9_linux_amd64.tar.gz" | tar -xz -C /usr/local/bin nuclei
|
||||
chmod +x /usr/local/bin/nuclei
|
||||
fi
|
||||
args:
|
||||
executable: /bin/bash
|
||||
when: scan_mode == 'masscan+nuclei'
|
||||
retries: 2
|
||||
delay: 5
|
||||
|
||||
- name: Upload nuclei template
|
||||
copy:
|
||||
src: "{{ nuclei_template_local }}"
|
||||
dest: /root/webrunner/nuclei_template.yaml
|
||||
mode: '0644'
|
||||
when: scan_mode == 'masscan+nuclei' and nuclei_template_local | default('') != ''
|
||||
|
||||
Reference in New Issue
Block a user