┌────────────────────────────────────────────┐
│ │
│ █████╗ ██╗ ██╗ │
│ ██╔══██╗██║ ██║ │
│ ███████║██║ ██║ │
│ ██╔══██║██║ ██║ │
│ ██║ ██║███████╗██║ │
│ ╚═╝ ╚═╝╚══════╝╚═╝ │
│ │
│ Cybersecurity Expert • Kuwait 🇰🇼 │
│ │
└────────────────────────────────────────────┘
Cybersecurity Expert at a leading financial institution in Kuwait. I design security architectures, lead incident response, and build open-source tools for the cybersecurity community. My work spans offensive security, compliance automation, and critical infrastructure protection.
Education Carnegie Mellon University • Kuwait University • GUST University
Certs 8x GIAC | SANS LDR514 | SANS SEC530 | MCT | PCI DSS Professional
Location Kuwait 🇰🇼
┌─────────────────────────┬──────────────────────────────────────────────────┐
│ Banking & Financial │ PCI DSS v4.0, SWIFT CSP, CBK CORF, SAMA CSF │
│ ICS / OT / IoT │ IEC 62443, NIST SP 800-82, NERC CIP │
│ Offensive Security │ Penetration Testing, Red Teaming, CTF │
│ Cloud Security │ AWS, Azure, GCP — Zero Trust Architecture │
│ Threat Hunting │ KQL, Sentinel, Splunk, MITRE ATT&CK │
│ GRC & Compliance │ NIST CSF, ISO 27001, CIS Controls v8 │
│ Community │ Arabic infosec content, mentorship, open source │
└─────────────────────────┴──────────────────────────────────────────────────┘
Offensive & Red Team
| Tool | Description |
|---|---|
| S7aba | Cloud privilege escalation framework — AWS, Azure, GCP, K8s. 49 privesc methods. |
| VulnScan Framework | Automated penetration testing & vulnerability scanning engine. |
| CyberToolkit | Modular bash pentesting toolkit — recon, exploitation, post-exploit. |
| AlEnezi CTF Tool | All-in-one CTF terminal toolkit — forensics, OSINT, web, crypto. |
| HardNix | Linux security auditing for red teamers and pentesters. |
| Field Manual | Red & Blue Team field manual — interactive terminal reference. |
Compliance & GRC
| Tool | Description |
|---|---|
| CORF Compliance Tool | CBK CORF v1.0 — 876 controls, 27 domains. React + Node.js + SQLite. |
| SAMA CSF Assessment | Saudi Central Bank framework — bilingual AR/EN, 114 sub-controls. |
| CIS Benchmark Checker | CIS compliance checker for Kuwait government entities. |
| Arabic InfoSec Policies | Information security policies in Arabic (ISO/NIST aligned). |
| CIS Audit Tool | Web-based CIS Critical Security Controls audit checklist. |
Security Operations
| Tool | Description |
|---|---|
| Security Leadership Panel | CISO governance dashboard — NIST CSF 2.0 + CIS Controls v8. |
| TLS Cert Radar | SSL/TLS certificate monitoring with radar, maps, scanner. |
| KWTCyberWatch | Real-time Certificate Transparency monitoring for Kuwait. |
| SecOpsDash | Security operations dashboard for SOC analysts. |
| PhishBOT | Real-time phishing detection — REST API + React + Telegram bot. |
Infrastructure & ICS
| Tool | Description |
|---|---|
| ICS/IoT/OT Hardening | Industrial security framework — IEC 62443, NIST 800-82. |
| SecureArch | Security architecture designer with STRIDE threat modeling. |
| OpenICS-Atlas | Map & harden ICS exposure — Shodan-aware, vendor-neutral. |
| FalconOT | IoT / ICS / OT self-security assessment toolkit. |
Community
| Tool | Description |
|---|---|
| KW-OS | 🇰🇼 Kuwait Open Source Directory — 266 projects, 177 developers. |
| Daily Ayah | Complete Quran — 114 surahs, 6,236 ayahs, Uthmani script. |
| Dua Collection | 337+ authentic duas from Quran, Sunnah & Hisn al-Muslim. |
| CyberArsenal | Open-source cybersecurity tools platform — 60+ tools cataloged. |

