Hi — I'm Michael Swain.
I work in IT and cybersecurity, and I build tools — for the people who live in these systems every day, and the teams who keep them secure.
I build tools for the people using the systems — and the ones defending them.
An IT and cybersecurity professional building practical tools across the stack — from polished desktop apps that make everyday computing easier and safer, to purpose-built instruments that help security and IT teams see more, test more, and respond faster.
Three tools, each born from a gap I hit on the job.
Rule Range
A synthetic-telemetry firing range for Elastic detection rules.
A purple-team lab that proves your Elastic Security detections fire when they should — and stay quiet when they shouldn't — without running a single piece of real malware.
Unit 80
A local-first desktop AI companion that guards, operates, and never phones home.
A retro-anime PyQt6 desktop agent for Windows: witty companion, autonomous OS operator, and EDR-style security sentinel — all running on a local LLM with nothing leaving the machine.
VulnOps
The operator console Vulners never shipped — orchestrated CVE scanning, end to end.
A full GUI and management layer for Vulners-powered scanning: nmap discovery and service fingerprinting, Vulners CVE/CVSS correlation, scheduling, poll-only remote agents, multi-client engagements, and polished PDF/XLSX reporting.
I care about the unglamorous parts most people skip — does it actually do what it claims, does it hold up, and is it something a real person would want to use?
I work in the fieldyears on the SOC floor, in the day-to-day fight.
I build tools for itshaped by what the work actually needs, not what a demo wants.
I do it to help othersthe best tool is the one that makes someone else's job easier.