13ce8a9b8a
- New scan mode: masscan+nuclei — masscan finds open ip:port pairs, nuclei runs operator-supplied CVE template against discovered hosts - Per-country vulnerable host count in merge output via CIDR→country lookup - Tuning args on every scan: --nmap-timing, --nmap-timeout, --nmap-workers, --nuclei-rate, --nuclei-concurrency, --nuclei-timeout, --masscan-rate - Vars file support: operator provides scan_vars.yaml to pre-fill all tuning settings without interactive prompts - Templates copied to nodes at provision time — no live fetches (OPSEC) - run_scan.yml passes all tuning args with Ansible defaults as fallback - configure_node.yml installs nuclei binary + uploads template on demand - Updated deployment summary shows mode-specific tuning params - countries-format.md and targets-format.md updated for new capabilities - scan_vars.yaml.example documents all configurable settings with comments
2.4 KiB
2.4 KiB
countries.yaml — Format Specification
Purpose
Defines which countries to scan and optional per-country exclusions. Used by all WEBRUNNER scan modes. The scanner resolves each country code to its CIDR ranges using RIR delegated stats files (ARIN, RIPE, APNIC, LACNIC, AFRINIC — cached 24h locally).
Scope options
- Targeted countries: list specific ISO codes in this file
- Single country: just one entry
- Global sweep: include every country you want — WEBRUNNER distributes CIDRs across nodes automatically regardless of count
Relationship to scan_vars.yaml
scan_profile.rate in this file sets the masscan default, but it is
overridden by masscan_rate in scan_vars.yaml or the interactive tuning
prompt. Prefer scan_vars.yaml for operator-level tuning.
Schema
scan_profile:
name: string # Label for this profile (used in logs/reports)
rate: integer # masscan packets/sec (default: 1000, max: 100000)
max_hosts_per_country: integer|null # Cap IPs per country. null = no limit
countries:
- code: string # ISO 3166-1 alpha-2 (e.g. US, VE, NL, GB, NG)
priority: high|medium|low # Scan order. high = first
exclude_cidrs: # Optional CIDR blocks to skip within this country
- "x.x.x.x/xx"
notes: string # Optional context (not used by scanner)
Rules
codemust be a valid ISO 3166-1 alpha-2 code- GB is the correct code for United Kingdom (not UK)
rateapplies globally to the masscan run, not per-countryexclude_cidrsentries must be valid CIDR notation- Countries are scanned in priority order: high → medium → low
- Within same priority, order in the list is preserved
Valid priority values
high | medium | low
Common country codes
| Country | Code |
|---|---|
| United States | US |
| United Kingdom | GB |
| Venezuela | VE |
| Netherlands | NL |
| Canada | CA |
| Nigeria | NG |
| Russia | RU |
| Germany | DE |
| China | CN |
| Brazil | BR |
| Iran | IR |
| India | IN |
| France | FR |
| Australia | AU |
Example
scan_profile:
name: "latam-europe-sweep"
rate: 2000
max_hosts_per_country: 100000
countries:
- code: VE
priority: high
exclude_cidrs: []
notes: "Primary target"
- code: US
priority: medium
exclude_cidrs:
- "10.0.0.0/8"
- "172.16.0.0/12"
- "192.168.0.0/16"
- code: NL
priority: low