Skip to main content
Run any Skill in Manus
with one click
GitHub repository

blacklight

blacklight contains 6 collected skills from rfxn, with repository-level occupation coverage and site-owned skill detail pages.

skills collected
6
Stars
12
updated
2026-04-29
Forks
2
Occupation coverage
3 occupation categories · 100% classified
repository explorer

Skills in this repository

authoring-incident-briefs
detectives-and-criminal-investigators-333021

Renders the final incident-commander brief: executive summary, technical narrative, kill-chain stanzas (intrusion → persistence → execution → lateral → exfil), remediation ledger, and open-risk assessment. Use when the case is closing and the operator needs a structured human-readable handoff document.

2026-04-29
curating-cases
correspondence-clerks-434021

Executes case lifecycle state transitions (open / hold / reopen / close), maintains the INDEX row, and emits agentic-minutes status blocks with next-step + blocking-question. Use when the case needs lifecycle adjudication, status reporting, or close-criteria evaluation.

2026-04-29
extracting-iocs
information-security-analysts

Extracts, deduplicates, and clusters IPs (with /24 grouping and CDN-safelist awareness), domains (punycode-decoded, subdomain-flattened), file hashes (MD5/SHA256), URL patterns, and webshell fingerprint families from raw evidence. Use when the case needs IOC normalization or aggregation for downstream rule scoping or attribution.

2026-04-29
gating-false-positives
information-security-analysts

Adjudicates ModSec deny-events, APF blocks, YARA/LMD signature hits, or anomaly flags as genuine threat or benign-pattern match. Records suppression rationale. Use when the case has a candidate alert that needs FP/TP classification before downstream rule authoring or escalation.

2026-04-29
prescribing-defensive-payloads
information-security-analysts

Authors ModSec rules, APF/CSF/iptables/nftables firewall blocks, and LMD/ClamAV signature submissions for confirmed attack patterns. Validates with apachectl preflight, FP-corpus checks, and CDN-safelist awareness. Use when the case requires generating a defensive rule, signature, or block to prevent recurrence.

2026-04-29
synthesizing-evidence
information-security-analysts

Correlates forensic evidence across log streams (apache.access, apache.error, modsec.audit, journald, fs mtime clusters, cron events) to build attribution-grounded hypotheses with cross-stream citations. Use when the case needs evidence consolidation across multiple sources, hypothesis grounding, or kill-chain reconstruction.

2026-04-29