operator = {
"name" : "Farhang Fatih",
"alias" : "MrGuevara",
"location" : "Kurdistan, Iraq",
"role" : "Cybersecurity Researcher & Secure Software Architect",
"since" : 2021,
"languages" : ["Kurdish (Native)", "English"],
"os" : "Linux — always",
"specialty" : [
"Penetration Testing",
"Malware Analysis & Reverse Engineering",
"Web Application Security (OWASP)",
"Cloud Security (AWS)",
"Secure Full-Stack Development",
],
"building" : "AxiomBreak AI — 340+ uncensored models for cybersecurity ops",
"open_to" : "Remote security consulting · Red team · AppSec roles",
}I break things to understand how they work — then I build them better and harder to break. Security researcher since 2021, operating across pentesting, malware analysis, AppSec, and cloud hardening, with full-stack engineering skills to build tools that are both powerful and secure. Everything runs on Linux.
All repos are real builds — no templates, no tutorials.
🔴 AxiomBreak AI — Linux-native Cybersecurity AI Agent
An advanced Linux-native IDE agent I built from scratch that aggregates 340+ uncensored AI models into a single workspace — built exclusively for cybersecurity professionals, pentesters, and ethical hackers.
| Stack | Python · Linux · Custom AI Orchestration Layer · API Integration |
| Purpose | Single uncensored AI workspace for offensive security research |
| Scale | 340+ models routed through a custom orchestration engine |
| Use case | Pentesting research · Malware analysis · Exploit dev · Red team automation |
| Role | Sole architect, developer, maintainer |
🔴 Pentesting Platform — 44+ Scanner Bug Bounty Dashboard
I built this because I was running 15 different tools in separate terminals every bug bounty session. Subfinder, httpx, Burp, SQLi checks, header analysis — slow and repetitive. So I unified all of it.
44+ automated scanners behind a React dashboard, powered by an async FastAPI backend. Drop a target URL, pick a scan profile, and it runs the entire playbook — then exports a clean HTML/JSON/CSV report.
| Stack | Python 3.10+ · FastAPI · React 18 · Linux |
| Scanners | Subdomain enum · Web vuln checks · SQLi · CORS · JS secret hunting · Cloud misconfiguration · Network fingerprinting |
| Output | HTML / JSON / CSV reports |
| Platform | Linux-native |
| License | MIT — authorized security testing only |
🟡 SkySpy Kurdistan — Tactical Drone Detection & Radar System
An open-source intelligence platform that detects, identifies, and tracks UAVs in real-time using ESP32 hardware to passively scan Wi-Fi and RF frequencies. Built for Kurdistan's airspace security.
| Stack | Python · ESP32 · RF/MAC Scanning · Telegram API |
| Detection | Passive RF/Wi-Fi monitoring → cross-referenced against a drone signature database |
| Mapping | Real-time path output to KML + CSV (Google Earth ready) |
| Alerts | Instant Telegram bot notifications on new drone detection |
| Supports | DJI, Parrot, and custom-built UAVs |
🟡 ONE Cafe POS — Kurdish-first Point-of-Sale & Print Routing System
A full-stack POS system built for a real café inside Ranya Mall, Kurdistan. Entirely localized in Kurdish Sorani with native RTL layout and a companion print routing server that routes orders to the right kitchen printer automatically.
| Stack | React 19 · TypeScript · Tailwind CSS v4 · Bun · Node.js |
| Language | Kurdish Sorani — full RTL layout throughout |
| Currency | Iraqi Dinar (دینار) with live totals |
| Print routing | Kitchen printer (food) · Barista printer (drinks) · Shisha station |
| Deployment | Local network — offline capable |
🟡 Ratil (رتیل) — Offline-first Holy Quran Companion App
A beautifully crafted, fully offline Quran app built with Flutter. All 114 surahs, 6,236 verses, Tajweed color-coding, 14+ reciters, and Kurdish Sorani translation — no internet required.
| Stack | Flutter 3.x · Dart 3.x |
| Platform | Android · iOS · Web · Desktop |
| Features | Tajweed highlighting · 14+ reciters · Kurdish/English/Arabic translation · Prayer times · Qibla compass |
| Storage | Fully offline — complete Quran + audio bundled |
| License | MIT |
Cybersecurity Researcher & Ethical Hacker — Independent · 2021 → Present
- Conduct penetration testing across web, network, and application layers in controlled environments; identify SQLi, auth bypasses, and API flaws
- Build custom malware research tools and isolated multi-VM labs for behavioral analysis, crypter engineering, and detection-evasion research
- Run phishing simulations and MFA evaluation campaigns for client security training programs
- Perform network assessments using Wireshark, Nmap, and custom-built tooling; document TTPs to strengthen defensive posture
- Develop and deploy secure full-stack applications with hardened auth, RBAC, encryption, and API protection from the ground up
- Research cloud security on AWS; apply hardening patterns for storage, IAM, and network exposure
| Credential | Body |
|---|---|
| Certified Cloud Security Practitioner | AWS |
| Certified AppSec Practitioner (CAP) | The SecOps Group |
| Certified AppSec Pentesting Expert (CAPenX) | The SecOps Group |
| Certified Network Security Practitioner (CNSP) | The SecOps Group |
| Bug Bounty Advanced | — |
| Burp Suite — Web App Hacking | PortSwigger |
| Google CyberSecurity Certificate | |
| Google AI Certificate | |
| Malware Analysis Fundamentals | — |
| SQL Injection Attacks | — |
| Network Security | Great Learning |
| Practical Security Fundamentals | — |
| Linux Fundamentals | — |
| Programming 100: Fundamentals | — |
| Practical Help Desk | — |
Education: Information Technology (IT) · Raparin Technical and Vocational Institute · 2024 – 2026
# -- operator: MrGuevar4 // updated: 2026 --
actively_building:
- AxiomBreak AI # 340+ uncensored model cybersecurity agent — Linux native
- Security Browser Suite # Privacy-hardened browsers with isolation + request filtering
deep_learning:
- Advanced AWS cloud security architecture and IAM hardening
- AI-driven automated threat detection pipelines
- Offensive tooling development in Go
exploring:
- Zero-day research methodologies
- Advanced malware evasion and live crypter engineering
- RF/hardware security — drone detection systems
open_to:
- Remote security consulting and advisory engagements
- Penetration testing contracts
- Red team collaborations
- Freelance secure software development