I’m Matt Swann, a cyber intelligence analyst and detection engineer working across the Microsoft security stack. Most of my work sits at the seam between threat intelligence and detection engineering — turning “here’s what the attacker did” into “here’s the query that catches it next time.” This site is where I collect the notes, tools, and write-ups that come out of that habit: I build something to solve my own problem, then write up what I learned.
Browse the series below, try the interactive tools I’ve built, or start with the latest post.