Skip to content
View 9gkc's full-sized avatar

Block or report 9gkc

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
9gkc/README.md

Ali Alkarar

Cybersecurity Engineer · Secure Software Builder · Open-Source Developer

GitHub profile LinkedIn Email Application security

Basra, Iraq · Building useful, understandable, and safer technology


Profile

I am Ali Alkarar, known on GitHub as @9gkc. I design and build practical security tools, secure web applications, learning platforms, and open-source projects with a strong focus on clarity and responsible use.

My work sits at the intersection of application security, full-stack engineering, defensive tooling, and Arabic-first technical education. I care about software that solves a real problem, communicates its limitations honestly, and remains maintainable after the first release.

Responsible-use boundary: Security research and testing are performed only with explicit authorization, within an approved scope, and with safeguards that reduce unnecessary impact.

What I build

Area Direction
Application security Defensive review workflows, authorization verification, secure defaults, and structured findings.
Security education Arabic-first learning experiences, safe labs, progressive roadmaps, and accessible explanations.
Product engineering Focused web, desktop, Android, and browser applications built around reliable state and clear user flows.
Open source Small, documented, verifiable projects that are useful to learners, builders, and security practitioners.

Featured work

These projects represent the strongest themes across my current portfolio. Each link points to the project’s official repository or release surface.

Project Purpose Explore
CyKun Arabic right-to-left Android reader for university cybersecurity stages, semesters, subjects, lectures, approved PDF resources, announcements, and timetable notices. Releases
FileGuard Bilingual, offline-first Windows utility for inspecting selected local files without executing them or automatically uploading data. Releases
AuthZGuard Defensive authorization-verification tooling for explicitly approved API scopes, with CI-friendly reports and safety controls. Documentation
IraqCode Arabic-first bilingual programming platform with sequenced lessons, project missions, local progress, and a transparent skill passport. Live platform
AegisScope Allowlist-first AppSec workspace for authorized assets, low-impact reviews, findings, and structured reporting. Platform

Portfolio map

Security engineering

Cyber 4 Ever provides a bilingual cybersecurity learning workspace with safe-lab guidance and role-based roadmaps. Al-Kunooze-Security focuses on defensive web-security workflows with server-side target validation. WiFiScan is a defensive Python utility for inspecting Wi-Fi security and encryption information without automatically enabling network interfaces. AtomicSite presents educational material on encryption, network security, and secure-system concepts.

Web applications and learning tools

ShopFlow, Bookmarker, NewsFeed, CurrConv, and Eventify explore validated data, safe rendering, predictable state handling, and accessible interfaces.

Browser tools and interactive projects

PassGen, QuoteGen, Roshambo, SlideShow, and TicTacToe demonstrate practical browser development, responsive interaction, and controlled client-side state.

Technology focus

JavaScript TypeScript Python Dart Java React Node.js Flutter Docker GitHub Actions

Capability Tools and practices
Languages JavaScript, TypeScript, Python, Dart, Java, HTML5, and CSS3.
Web and mobile React, Node.js, Express, Firebase, Flutter, and Tailwind CSS.
Security Burp Suite, Kali Linux, Wireshark, Metasploit, OWASP ZAP, and defensive validation.
Delivery Git, GitHub Actions, Postman, Docker, VS Code, documentation, and incremental verification.

Engineering principles

I work from a few consistent principles: secure by default, explicit authorization, accessible interfaces, small verifiable changes, transparent limitations, and documentation that reflects the implementation. In security-focused projects, responsible-use boundaries are part of the product—not a disclaimer added at the end.

Collaboration

I welcome focused collaboration on open-source security tooling, Arabic-first technical education, secure web applications, and responsible disclosure. If you are reporting a security concern, please follow the private process described in SECURITY.md instead of posting sensitive details publicly.

For contribution standards, scope expectations, and pull-request guidance, see CONTRIBUTING.md.

Contact

The best way to reach me is through LinkedIn or email. You can also explore the complete project portfolio through my GitHub profile.


Build with clarity. Test with authorization. Ship useful software.

Popular repositories Loading

  1. Al-Kunooze-Security Al-Kunooze-Security Public

    🛡️ Advanced Cybersecurity Platform for Defensive Web Scanning.

    TypeScript 1

  2. FileGuard FileGuard Public

    Bilingual, offline-first desktop tool for safe local suspicious-file triage — no execution and no automatic upload.

    JavaScript 1

  3. cykun cykun Public

    Arabic academic cybersecurity library for university students — structured study paths, numbered lectures, and verified Android releases.

    1

  4. AtomicSite AtomicSite Public

    An educational cybersecurity platform featuring technical reports on encryption, network security, and secure system simulations.

    TypeScript

  5. 9gkc 9gkc Public

    Cybersecurity engineer building secure software, defensive AppSec tools, and Arabic-first learning platforms.

  6. WiFiScan WiFiScan Public

    Professional Python script for scanning and analyzing Wi-Fi network security and encryption.

    Python