Files
CoM-c2itall/modules/webrunner/inputs/countries-format.md
T
n0mad1k 13ce8a9b8a Add masscan+nuclei mode, operator tuning controls, and vars file support to webrunner
- New scan mode: masscan+nuclei — masscan finds open ip:port pairs,
  nuclei runs operator-supplied CVE template against discovered hosts
- Per-country vulnerable host count in merge output via CIDR→country lookup
- Tuning args on every scan: --nmap-timing, --nmap-timeout, --nmap-workers,
  --nuclei-rate, --nuclei-concurrency, --nuclei-timeout, --masscan-rate
- Vars file support: operator provides scan_vars.yaml to pre-fill all
  tuning settings without interactive prompts
- Templates copied to nodes at provision time — no live fetches (OPSEC)
- run_scan.yml passes all tuning args with Ansible defaults as fallback
- configure_node.yml installs nuclei binary + uploads template on demand
- Updated deployment summary shows mode-specific tuning params
- countries-format.md and targets-format.md updated for new capabilities
- scan_vars.yaml.example documents all configurable settings with comments
2026-05-02 14:49:24 -04:00

2.4 KiB

countries.yaml — Format Specification

Purpose

Defines which countries to scan and optional per-country exclusions. Used by all WEBRUNNER scan modes. The scanner resolves each country code to its CIDR ranges using RIR delegated stats files (ARIN, RIPE, APNIC, LACNIC, AFRINIC — cached 24h locally).

Scope options

  • Targeted countries: list specific ISO codes in this file
  • Single country: just one entry
  • Global sweep: include every country you want — WEBRUNNER distributes CIDRs across nodes automatically regardless of count

Relationship to scan_vars.yaml

scan_profile.rate in this file sets the masscan default, but it is overridden by masscan_rate in scan_vars.yaml or the interactive tuning prompt. Prefer scan_vars.yaml for operator-level tuning.

Schema

scan_profile:
  name: string                  # Label for this profile (used in logs/reports)
  rate: integer                 # masscan packets/sec (default: 1000, max: 100000)
  max_hosts_per_country: integer|null  # Cap IPs per country. null = no limit

countries:
  - code: string                # ISO 3166-1 alpha-2 (e.g. US, VE, NL, GB, NG)
    priority: high|medium|low   # Scan order. high = first
    exclude_cidrs:              # Optional CIDR blocks to skip within this country
      - "x.x.x.x/xx"
    notes: string               # Optional context (not used by scanner)

Rules

  • code must be a valid ISO 3166-1 alpha-2 code
  • GB is the correct code for United Kingdom (not UK)
  • rate applies globally to the masscan run, not per-country
  • exclude_cidrs entries must be valid CIDR notation
  • Countries are scanned in priority order: high → medium → low
  • Within same priority, order in the list is preserved

Valid priority values

high | medium | low

Common country codes

Country Code
United States US
United Kingdom GB
Venezuela VE
Netherlands NL
Canada CA
Nigeria NG
Russia RU
Germany DE
China CN
Brazil BR
Iran IR
India IN
France FR
Australia AU

Example

scan_profile:
  name: "latam-europe-sweep"
  rate: 2000
  max_hosts_per_country: 100000

countries:
  - code: VE
    priority: high
    exclude_cidrs: []
    notes: "Primary target"

  - code: US
    priority: medium
    exclude_cidrs:
      - "10.0.0.0/8"
      - "172.16.0.0/12"
      - "192.168.0.0/16"

  - code: NL
    priority: low