// whoami

Hi — I'm Michael Swain.

I work in IT and cybersecurity, and I build tools — for the people who live in these systems every day, and the teams who keep them secure.

michael@soc — ~/showcasezsh
whoamimichael_swain · SOC lead / security engineer
cat ./focus.txtdetection engineering · threat hunting · tooling
uptime6 yrs in security · 8 in IT · still curious
ls ~/projectsrule-range unit-80 vulnops
git log --oneline -1ship tools practitioners actually reach for
./run --helpright-click a project · scroll to explore
// whoami --verbose

I build tools for the people using the systems and the ones defending them.

An IT and cybersecurity professional building practical tools across the stack — from polished desktop apps that make everyday computing easier and safer, to purpose-built instruments that help security and IT teams see more, test more, and respond faster.

// ls ./projects

Three tools, each born from a gap I hit on the job.

// ~/toolbox --all
Elastic SIEM·CrowdStrike XDR·SentinelOne·Cortex XQL·MITRE ATT&CK·Detection engineering·Threat hunting·Incident response·Python·PowerShell·Docker·Local LLMs·Purple team·Faithful test design
// cat approach.md

I care about the unglamorous parts most people skip does it actually do what it claims, does it hold up, and is it something a real person would want to use?

I work in the fieldyears on the SOC floor, in the day-to-day fight.
I build tools for itshaped by what the work actually needs, not what a demo wants.
I do it to help othersthe best tool is the one that makes someone else's job easier.

Currently leading a SOC.
Still shipping.

// session_end

Thanks for scrolling.

Built from the SOC floor, with care for the people who use it. If any of this resonated, my door's open.

michael@soc:~$ logout
Michael SwainIT & CybersecuritySOC Lead · Detection Engineering