THE SHOWCASE
Hi, I'm Michael Swain — welcome.
I work in IT and cybersecurity, and I build tools — for the people who live in these systems every day, and the teams who keep them secure. This is where that work lives.
I build tools for the people using the systems — and the ones defending them.
I'm Michael Swain, an IT and cybersecurity professional. I build practical tools across the stack — from polished desktop apps that make everyday computing easier and safer, to purpose-built instruments that help security and IT teams see more, test more, and respond faster.
I care about the unglamorous parts most people skip: does it actually do what it claims, does it hold up, and is it something a real person would want to use?The projects below are how I put that into practice.
Selected work
A range of tools — for end users and for security & IT teams. Each card opens a deep dive.
Rule Range
A synthetic-telemetry firing range for Elastic detection rules.
A purple-team lab that proves your Elastic Security detections fire when they should — and stay quiet when they shouldn't — without running a single piece of real malware.
Unit 80
A local-first desktop AI companion that guards, operates, and never phones home.
A retro-anime PyQt6 desktop agent for Windows: witty companion, autonomous OS operator, and EDR-style security sentinel — all running on a local LLM with nothing leaving the machine.
VulnOps
The operator console Vulners never shipped — orchestrated CVE scanning, end to end.
A full GUI and management layer for Vulners-powered scanning: nmap discovery and service fingerprinting, Vulners CVE/CVSS correlation, scheduling, poll-only remote agents, multi-client engagements, and polished PDF/XLSX reporting.
Toolbox
- › Detection Engineering
- › Elastic Security
- › MITRE ATT&CK
- › EDR / Endpoint
- › Threat Intel
- › Purple Team
- › Python
- › TypeScript
- › JavaScript
- › Bash
- › Docker
- › Windows
- › Linux
- › PyQt6
- › Local LLMs
- › SQLite
- › Astro
- › React
- › GSAP
- › HTML / CSS