Repository navigation
Expand file tree
/
Copy pathconfig.json.sample
More file actions
37 lines (37 loc) · 5.3 KB
/
Copy pathconfig.json.sample
File metadata and controls
37 lines (37 loc) · 5.3 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
{
"__scan_categories_choices__": "All, Full, Web, Database, Remote Management, Email, LDAP, Network Infrastructure, File Transfer, SMB, Specialized, Containers & Debuggers, Local LLM",
"__scan_categories_full_note__": "Full scans TCP 1-65535 ONLY and runs no UDP discovery, so the U: ports in the categories (U:161, U:500, U:623, ...) are skipped. Use All, or dest_ports with the UDP ports appended, for UDP coverage.",
"scan_categories": ["Web", "Database"],
"__dest_ports_note__": "Optional: overrides scan_categories with an explicit port list. Use U: prefix for UDP (e.g. U:53).",
"dest_ports": [],
"__numeric_fields_note__": "masscan_batch_size, max_rate, nmap_threads and nmap_threshold accept a JSON number or a quoted number. A non-numeric or null value falls back to the default, and a value below the minimum of 1 is raised to 1; both print a warning rather than failing mid-scan.",
"masscan_batch_size": 5,
"__banner_scan_choices__" : "true, false (JSON booleans; legacy quoted \"True\"/\"False\" still accepted)",
"__banner_scan_udp_warning__": "WARNING: When scanning UDP ports (U:* prefixed) with banner_scan=False, hosts will not undergo NSE confirmation. All open|filtered UDP hosts (typically the majority) will appear in output, inflating host counts significantly. Enable banner_scan or script_scan when using UDP ports.",
"banner_scan" : true,
"__script_scan_choices__" : "true, false (JSON booleans; legacy quoted \"True\"/\"False\" still accepted)",
"script_scan" : false,
"__host_discovery_choices__" : "true, false (JSON booleans; legacy quoted \"True\"/\"False\" still accepted)",
"__host_discovery_note__": "When False, no host discovery sweep runs and every target is port-scanned directly. No source-port override is used in any phase. Independent of this setting, the port scan always runs a rate-calibration probe on a few TCP ports (max_rate, then half that rate) and drops to the reduced rate if the slower pass finds more hosts. Internal discovery is always capped at 1000 pps regardless of max_rate to protect enterprise firewall state tables (~60K concurrent entries max).",
"host_discovery" : true,
"__resume_choices__" : "true, false (JSON booleans; legacy quoted \"True\"/\"False\" still accepted)",
"resume" : false,
"__check_for_updates_note__": "Optional. When true, SpooNMAP contacts api.github.com at startup to see whether a newer release exists. Default false, and absent means false: the tool makes no network connection other than the scan itself unless you turn this on. Use --check-update for a one-off check without enabling it here.",
"check_for_updates": false,
"__honeypot_active_confirm_note__": "Optional. When true, SpooNMAP attempts a small number of raw TCP connects against unscanned high ports on any host flagged by the TTL-spread or port-profile signals, to confirm it. Hosts flagged only by the tarpit open-port-ratio heuristic are not probed. Default false, and absent means false: the tool sends no traffic beyond the scan itself unless you turn this on. A confirmed host answered a port that was never part of this scan, which is a strong tell that it accepts every connection rather than running a real service. Limitations: hosts outside target_file are never probed; on a Full (1-65535) scan there are almost no unscanned ports left to probe, so it does little or nothing; and honeypot detection as a whole only runs on the masscan path, not the direct-nmap path used for scans below nmap_threshold.",
"honeypot_active_confirm": false,
"__target_scan_choices__" : "External, Internal (case-insensitive; any other value stops the run rather than scanning with the Internal-only checks silently skipped)",
"target_scan" : "Internal",
"__max_rate_external_recommendation__" : "Default = 20000 (full port scan capped at 10000)",
"__max_rate_internal_recommendation__" : "Default = 2000 (full port scan capped at 1000)",
"max_rate" : "2000",
"nmap_threads" : 5,
"__nmap_threshold_note__": "Work-unit threshold (hosts × ports) for tool selection. When effective_hosts × port_count <= this value, nmap is used for port discovery instead of masscan. Nmap is more reliable and faster for small-to-medium scans (internal masscan caps at 200 work-units/sec due to 1000 pps + 5 retries; nmap -T4 does ~10,000/sec). Default: 5000000 (~76 hosts × full port scan, or ~5000 hosts × 1000 targeted ports). Lower to ~500000 for high-rate external setups (100k+ pps).",
"nmap_threshold": 5000000,
"target_file" : "ranges.txt",
"output_path" : "./",
"exclusions_file" : "exclusions.txt",
"__scanner_profile_choices__": "false/absent (default, disabled), \"random\", or an object pinning some of: probe_token, tls_random, rdp_cookie, workstation, native_os, user_agent, smtp_domain — any omitted key is drawn from a built-in pool",
"__scanner_profile_note__": "When set, nmap probes and SpooNMAP's bundled NSE scripts no longer send literal strings that identify the scanner (e.g. the RDP probe's \"mstshash=nmap\" cookie, or nmap's own NSE HTTP User-Agent) — see scan_profile.json in the output directory for exactly what was substituted, for engagement deconfliction. Does NOT affect TCP/IP stack fingerprinting, TLS/JA3 fingerprinting, or scan rate/shape; those are unrelated to string substitution.",
"scanner_profile" : false
}