Summary
Mark Woan is a Principal Security Researcher at Microsoft MSTIC with 14 years of hands-on experience in threat hunting, DFIR and application security across cloud and enterprise environments. He blends deep technical craftsmanship—C#, Go, Python, Linux, binary parsing and database work—with CREST-certified expertise in both host and network intrusion analysis and web application testing. At Microsoft he focuses on cloud telemetry (Azure Event Hubs, Storage, Cosmos DB, Kusto/KQL) and has authored 100+ detectors and public threat research that shaped high-profile investigations. Previously he led incident response and built large-scale automated hunting platforms using statistical analysis rather than signature-based IoCs. He’s as comfortable shipping security tooling and bespoke clients as he is performing forensic deep-dives, and maintains active open-source work in Go, C# and Python. Based in the UK, he combines investigative rigor with production-grade engineering to turn threat intelligence into reliable detections and operational systems.
14 years of coding experience
12 years of employment as a software developer
BSc (Hons) Computing, BSc (Hons) Computing at University of Northampton