█████╗ ██╗ ██╗
██╔══██╗██║ ██║
███████║██║ ██║
██╔══██║██║ ██║
██║ ██║███████╗██║
╚═╝ ╚═╝╚══════╝╚═╝
Cybersecurity Expert · Kuwait 🇰🇼
I break things carefully, then build the defense in the open.
Cybersecurity Expert at a leading financial institution in Kuwait. I design security architectures, lead incident response, and ship open source tools that turn hard security problems into something a team can actually run. The work spans offensive security, cloud and OT defense, and compliance automation for the Gulf, most of it built to a simple bar: zero dependencies, offline first, and bilingual where it matters.
Education Carnegie Mellon University · Kuwait University · GUST University
Certs 8x GIAC | SANS LDR514 | SANS SEC566 | MCT | PCI DSS Professional
Focus Blue team defense · Cloud & OT security · GRC automation · AI and MCP security
Location Kuwait 🇰🇼 · Building in Arabic and English
☁️ Cloud & Container Security
| Project | What it does |
|---|---|
Raqib راقب |
Read only exposure auditor for AWS, Azure, GCP, and Kubernetes. Reads IAM and RBAC, then reports the moves an intruder would make after a foothold across all six ATT&CK tactics, each with the fix. Matching Bash and Python engines, an interactive report, a posture score, and a diff for drift over time. |
| S7aba | Offensive cloud framework in pure Bash for AWS, Azure, GCP, and K8s. Red team post exploitation and privilege escalation, the attacker mirror that Raqib defends against. |
| CloudMCP-Arsenal | MCP servers and AI agent attacks and defenses for cloud security, covering both the offensive and the defensive side of AI agents. |
| InfraCode | Declarative infrastructure as code with state management, drift detection, and compliance enforcement across multi cloud. |
🏭 ICS / OT / IoT Security
| Project | What it does |
|---|---|
| ICS IoT OT Hardening ⭐ | Industrial cybersecurity platform: asset discovery, SNMP monitoring, vulnerability scanning, and an incident timeline, mapped to IEC 62443, NIST 800-82, NERC CIP, and MITRE ATT&CK for ICS. |
| OpenICS-Atlas | ICS and OT exposure intelligence: eight protocols, the Purdue model, asset inventory, APT threat intel, and 72 hardening controls, Shodan aware. |
| ConduitShield | Zone and conduit policy with blast radius analysis, SBOM and supply chain visibility, safety gates, and MITRE ATT&CK ICS mapping. |
| OTAUD | An all in one open source auditing framework for ICS, IoT, and OT environments. |
Smart Mubarakiya المباركية |
A personal vision for Kuwait's historic souq as an IoT and OT system, life safety and heritage first, published as two full consoles, English and Arabic: an interactive map with all 67 places on their real spots, five playable scenarios with sound and spoken announcements including a cyber attack stopped at the OT conduit, a trust zoned blueprint reviewed with Hisn, fourteen diagrams by Naqsha in both languages, a fourteen class sensor catalog, a digital twin registry, a gated roadmap, and a console that works offline. Part of an educational experience. |
📋 GRC, Compliance & Frameworks
| Project | What it does |
|---|---|
| CORF | Offline assessment workbook and open control catalog for the Central Bank of Kuwait Cyber and Operational Resilience Framework, 876 controls across 27 domains. |
Hisn حصن |
Security and compliance blueprints as code. Draw a trust zoned reference architecture from a short text source, then review it for control gaps across eight frameworks including PCI DSS, SWIFT CSP, and IEC 62443. |
| SAMA CSF Assessment | Saudi Central Bank Cybersecurity Framework assessment, bilingual, 114 controls with ISO, NIST, CIS, and PCI DSS mappings, offline first. |
| NCA ECC Crosswalk | Interactive crosswalk mapping Saudi NCA ECC 2:2024 to NIST CSF 2.0, SP 800-53, CIS v8.1, ISO 27001, and PCI DSS v4.0. |
🔎 Threat Hunting & DFIR
| Project | What it does |
|---|---|
| NetHawk | Reconstruct an attack from a packet capture. Threat hunting for pcap, zero dependencies. |
| ShadowPulse | Linux threat hunting and incident response toolkit, eight forensic modules from evidence collection to timeline reconstruction, with chain of custody, in pure Bash. |
Athar أثر |
Offline network forensics workbench: BPF builder, statistical beacon detection, DGA scoring, and a command forge for tshark, Zeek, and Arkime. Air gapped, zero telemetry. |
| LLM-DFIR | Forensic artifact taxonomy, triage scripts, and IR playbooks for AI, LLM, MCP, and Copilot artifacts across Windows, macOS, and Linux. |
🏗️ AppSec, Architecture & Modeling
| Project | What it does |
|---|---|
| Mimar | Security architecture and STRIDE threat modeling. Describe a system as trust zones, components, and data flows, then see the diagram and the threats and weaknesses it produces. |
Naqsha نقشة |
Diagrams as code. Turn a short text description into a polished, interactive HTML diagram with pan, zoom, trace, search, and SVG and PNG export. |
| APIShield | API security testing across the OWASP API Top 10: BOLA, authentication, SSRF, injection, rate limiting, and mass assignment, with JSON and HTML reports. |
| LeakHound | A zero dependency scanner that catches leaked secrets before they ship. |
📡 Security Operations & Intelligence
| Project | What it does |
|---|---|
| PublicEye | OSINT platform, 20 modules across 13 categories including DNS, subdomains, Shodan, dark web, certificate transparency, and GitHub. |
Marsad مرصد |
Enterprise vulnerability management: contextual risk scoring from CVSS, criticality, and exposure, remediation workflow with SLAs, and executive dashboards. FastAPI and PostgreSQL, dockerized and tested. |
| KWTCyberWatch | Certificate transparency monitoring, domain squatting detection, and brand impersonation alerting, built for Kuwait's digital ecosystem. |
| CISO Dashboard | A CISO friendly governance dashboard for KPIs, controls coverage, incidents, and risk posture at a glance. |
🎓 Training & Awareness
| Project | What it does |
|---|---|
Wa3i وعي |
Arabic cybersecurity awareness site: 11 interactive guides and 173 items across personal, financial, and small business security and Gulf regulatory frameworks, with a phishing quiz game, a printable October checklist, and a 70 term glossary. Fully Arabic, right to left. |
| AZ-900 Azure Fundamentals | Bilingual English and Arabic student resource for the AZ-900 exam: complete notes for all three domains, seven hands on labs, an 85 question interactive quiz, exam day strategy, and printable quick reference PDFs in both languages. |
Around 80 more are in the repositories: hardening for Linux, Windows, and OpenShift, phishing and certificate radars, a client side secrets sieve, Arabic security policy libraries, and the Kuwait open source directory.


