Cybersecurity Expert at a leading financial institution in Kuwait. I design security architectures, lead incident response, and ship open source tools that turn hard security problems into something a team can actually run. The work spans offensive security, cloud and OT defense, and compliance automation for the Gulf, most of it built to a simple bar: zero dependencies, offline first, and bilingual where it matters.
Education Carnegie Mellon University · Kuwait University · GUST University
Certs 8x GIAC | SANS LDR514 | SANS SEC566 | MCT | PCI DSS Professional
Focus Blue team defense · Cloud & OT security · GRC automation · AI and MCP security
Location Kuwait 🇰🇼 · Building in Arabic and English
github.3li.info · the same profile as a site, in English and Arabic, dark and light, and offline
| Live from GitHub | Repositories, followers, stars, languages, and pushes per week, straight from the public API, with a static snapshot when it is unavailable. |
| Project explorer | Search, filter by domain or tag, sort by stars or last push, grid or list, and one click to load every public repository. |
Ctrl K palette and a terminal |
Jump to any project, section, or action. Or press ` and type help, ls cloud, open raqib, stats, neofetch. |
| SecOps playbooks | The playbooks in this repository, searchable by MITRE ATT&CK technique ID, with the planned ones listed. |
| Bilingual, both themes, no backend | English and Arabic with right to left layout, dark and light, installable, and it keeps working without a connection. |
☁️ Cloud & Container Security
| Project | What it does |
|---|---|
Raqib راقب |
Read only exposure auditor for AWS, Azure, GCP, and Kubernetes. Reads IAM and RBAC, then reports the moves an intruder would make after a foothold across all six ATT&CK tactics, each with the fix. Matching Bash and Python engines, an interactive report, a posture score, and a diff for drift over time. |
| S7aba | Offensive cloud framework in pure Bash for AWS, Azure, GCP, and K8s. Red team post exploitation and privilege escalation, the attacker mirror that Raqib defends against. |
| CloudMCP-Arsenal | MCP servers and AI agent attacks and defenses for cloud security, covering both the offensive and the defensive side of AI agents. |
| InfraCode | Declarative infrastructure as code with state management, drift detection, and compliance enforcement across multi cloud. |
🏭 ICS / OT / IoT Security
| Project | What it does |
|---|---|
| ICS IoT OT Hardening ⭐ | Industrial cybersecurity platform: asset discovery, SNMP monitoring, vulnerability scanning, and an incident timeline, mapped to IEC 62443, NIST 800-82, NERC CIP, and MITRE ATT&CK for ICS. |
| OpenICS-Atlas | ICS and OT exposure intelligence: eight protocols, the Purdue model, asset inventory, APT threat intel, and 72 hardening controls, Shodan aware. |
| ConduitShield | Zone and conduit policy with blast radius analysis, SBOM and supply chain visibility, safety gates, and MITRE ATT&CK ICS mapping. |
| OTAUD | An all in one open source auditing framework for ICS, IoT, and OT environments. |
Smart Mubarakiya المباركية |
A personal vision for a safer Souq Al-Mubarakiya through smart technology that works in silence, in English and Arabic: a map twin of all 67 places with real coordinates and a street map, five playable drills with recorded Kuwaiti announcements, a scenario builder and rooms for group training, an operations view that follows a real broker, a trust zoned IEC 62443 blueprint reviewed with Hisn and reported in both languages, plain language throughout, accessible, printable, and offline. Part of an educational experience, shared to read and discuss. |
📋 GRC, Compliance & Frameworks
| Project | What it does |
|---|---|
| CORF | Offline assessment workbook and open control catalog for the Central Bank of Kuwait Cyber and Operational Resilience Framework, 876 controls across 27 domains. |
Hisn حصن |
Security and compliance blueprints as code. Draw a trust zoned reference architecture from a short text source, then review it for control gaps across eight frameworks including PCI DSS, SWIFT CSP, and IEC 62443. |
| SAMA CSF Assessment | Saudi Central Bank Cybersecurity Framework assessment, bilingual, 114 controls with ISO, NIST, CIS, and PCI DSS mappings, offline first. |
| NCA ECC Crosswalk | Interactive crosswalk mapping Saudi NCA ECC 2:2024 to NIST CSF 2.0, SP 800-53, CIS v8.1, ISO 27001, and PCI DSS v4.0. |
| CIS Audit Tool | A web based reference tool and audit checklist for implementing CIS Critical Security Controls v8.1. |
| CIS Kuwait Assessment | CIS Benchmark compliance checker for Kuwait government entities. |
Arabic InfoSec Policies سياسات |
A collection of information security policies in Arabic, developed according to the latest global standards. |
🔎 Threat Hunting & DFIR
| Project | What it does |
|---|---|
| NetHawk | Reconstruct an attack from a packet capture. Threat hunting for pcap, zero dependencies. |
| ShadowPulse | Linux threat hunting and incident response toolkit, eight forensic modules from evidence collection to timeline reconstruction, with chain of custody, in pure Bash. |
Athar أثر |
Offline network forensics workbench: BPF builder, statistical beacon detection, DGA scoring, and a command forge for tshark, Zeek, and Arkime. Air gapped, zero telemetry. |
| LLM-DFIR | Forensic artifact taxonomy, triage scripts, and IR playbooks for AI, LLM, MCP, and Copilot artifacts across Windows, macOS, and Linux. |
🏗️ AppSec, Architecture & Modeling
| Project | What it does |
|---|---|
Mimar معمار |
Security architecture and STRIDE threat modeling. Describe a system as trust zones, components, and data flows, then see the diagram and the threats and weaknesses it produces. |
Naqsha نقشة |
Diagrams as code. Turn a short text description into a polished, interactive HTML diagram with pan, zoom, trace, search, and SVG and PNG export. |
| APIShield | API security testing across the OWASP API Top 10: BOLA, authentication, SSRF, injection, rate limiting, and mass assignment, with JSON and HTML reports. |
| LeakHound | A zero dependency scanner that catches leaked secrets before they ship. |
📡 Security Operations & Intelligence
| Project | What it does |
|---|---|
Tayyar تيّار |
Every new TLS certificate from public Certificate Transparency logs the moment it is logged, RFC 6962 and static tiles, with each log's signature checked. Raises an alert when a name imitates a watched brand: lookalike letters from other scripts, digits for letters, misspellings, another ending, or the real domain written inside another, and Arabic letters that read alike. Alerts to triage, signed webhooks, and a full interface in English and Arabic, with zero dependencies. Shared to show how it works. |
| PublicEye | OSINT platform, 20 modules across 13 categories including DNS, subdomains, Shodan, dark web, certificate transparency, and GitHub. |
Marsad مرصد |
Enterprise vulnerability management: contextual risk scoring from CVSS, criticality, and exposure, remediation workflow with SLAs, and executive dashboards. FastAPI and PostgreSQL, dockerized and tested. |
| KWTCyberWatch | Certificate transparency monitoring, domain squatting detection, and brand impersonation alerting, built for Kuwait's digital ecosystem. |
| CISO Dashboard | A CISO friendly governance dashboard for KPIs, controls coverage, incidents, and risk posture at a glance. |
🎓 Training & Awareness
| Project | What it does |
|---|---|
Wa3i وعي |
Arabic cybersecurity awareness site: 11 interactive guides and 173 items across personal, financial, and small business security and Gulf regulatory frameworks, with a phishing quiz game, a printable October checklist, and a 70 term glossary. Fully Arabic, right to left. |
| AZ-900 Azure Fundamentals | Bilingual English and Arabic student resource for the AZ-900 exam: complete notes for all three domains, seven hands on labs, an 85 question interactive quiz, exam day strategy, and printable quick reference PDFs in both languages. |
Around 120 more are in the repositories: hardening for Linux, Windows, and OpenShift, phishing and certificate radars, a client side secrets sieve, Arabic security policy libraries, and the Kuwait open source directory. Or browse them all live with search and filters.
SecOps playbooks that live in this repository, each on the NIST SP 800-61 lifecycle with MITRE ATT&CK mapping, detection queries for Microsoft Sentinel and Splunk, response phases, and metrics. Browse them or open the folder.
| ID | Playbook | Severity | MITRE ATT&CK |
|---|---|---|---|
| IR-001 | Ransomware Incident Response | 🔴 Critical | T1486 · T1490 · T1027 |
| IR-002 | Business Email Compromise (BEC) Response | 🔴 Critical | T1566.001 · T1534 · T1114 |
| TH-001 | Lateral Movement Detection | 🟠 High | T1021 · T1076 · T1028 · T1077 |
| CS-001 | Azure AD / Entra ID Compromise Response | 🔴 Critical | T1078.004 · T1136.003 · T1098 |
| VM-001 | Critical Vulnerability Response | 🔴 Critical | T1190 · T1203 |
Planned next: data exfiltration, insider threat, DDoS, supply chain, C2 detection, credential access, LOLBins, S3 exposure, container escape, zero day, and patch management. Contributions welcome, see CONTRIBUTING.md and the playbook template.



