I break things carefully, then build the defense in the open.
Security architecture and incident response at a leading financial institution in Kuwait, and open source tools across cloud, industrial, and enterprise security. Built to a simple bar: zero dependencies, offline first, and bilingual where it matters.
Search, filter by domain, click a tag, or load every public repository live from GitHub.
Counts from the flagship set, plus live figures from GitHub when the API answers. Hover for values, click a domain to filter the work.
Playbooks that live in this repository: NIST SP 800-61 lifecycle, MITRE ATT&CK techniques, detection queries for Sentinel and Splunk, and metrics.
Core domains of specialization, and the standards the work is measured against. Click one to see the matching tools.
Cybersecurity Expert at a leading financial institution in Kuwait. I design security architectures, lead incident response, and build open source tools for the security community, with a focus on enterprise and critical infrastructure in the Gulf.
The work runs from offensive security and cloud post exploitation to compliance automation for the Central Bank of Kuwait, the Saudi Central Bank, and the Saudi NCA, to hardening for industrial control systems. A theme runs through all of it: tools that need no backend, run offline, and speak both Arabic and English, so the people who need them can actually use them.
AI agent and Model Context Protocol security is a growing focus, reflected in tools like CloudMCP Arsenal and LLM DFIR, and I contribute Arabic security content to the regional community.