> MOUNTING EVIDENCE LOCKER ……… OK
> VERIFYING CHAIN OF CUSTODY … OK
> LOADING CASE FILE №0x4B7 …… OK
> REDACTIONS ACTIVE — PROCEED WITH CAUTION
CASE FILE №0x4B7
SECURITY ENGINEER — DOSSIER
LOCAL TIME 00:00:00
DECRYPTED 000%
0x4B7

Declassified — Eyes Only

The responder they call when the breach is already over.

Subject is Nathan Buisson — Lead Forensics & N3 Incident Response at Free (Iliad). Red teamer turned DFIR lead: formerly breaking into networks for the Gendarmerie Nationale, now building Kubernetes-based DFIR tooling for a group CSIRT. Motto: assume breach — then prove it.

Open a channel ↓
CLASSIFIED
№0x4B7 — DO NOT DUPLICATE
ASSUME BREACH — THEN PROVE IT/// INCIDENT CLOSED/// LOGS PRESERVED/// MAPPED TO ATT&CK/// NO EVIDENCE DESTROYED///
Scroll to decrypt
01 /

The dossier

Compiled from field reports. Accuracy: confirmed by the subject.

REDACTED
EXHIBIT ASUBJECT — FACE WITHHELD

Subject profile — handle with care

Summary. Hey — I'm Nathan. I do incident response and offensive security. By day I lead Forensics & N3 incident response at Free (Iliad): building Kubernetes-based DFIR tooling, running major incidents, and driving a security-operations & governance transformation. Before that I broke into networks as a penetration tester for the Gendarmerie Nationale, and cut my teeth on blue-team incident response as a consultant.

By night I write open-source DFIR tools — memory forensics, cloud log normalization to ECS, file carving, malware triage, and attack timelines mapped to MITRE ATT&CK. If it helps a responder move faster during an incident, I want to build it.

CodenameNathan Buisson
Handlenbuisson
Base of operationsParis, FR
SpecialisationDFIR · Red Team · Detection
LanguagesFrench & English — bilingual (TOEIC 990, TOEFL 104)
StatusActive — since 2021 · blue → red → DFIR
02 /

Field log

Chronology reconstructed from timestamped artefacts.

Nov 2025 — now
Lead Forensics & N3 Incident Response — Free (Iliad)

Build and run Kubernetes-based DFIR tooling for the group CSIRT. Technical and team lead for N3 (deep) incident response, driving a major IS transformation across security operations and governance.

Ongoing operation
Sep 2023 — Nov 2025
Penetration Tester — Gendarmerie Nationale

Offensive engagements and network-security assessments. Built Python tooling for red-team operations and reporting.

Offence
Mar 2022 — Aug 2023
Blue Team Consultant — Incident Response — HeadMind Partners

Hands-on incident response and forensic analysis for client engagements. Detection engineering on the Elastic Stack (ELK).

Defence
Apr 2021 — Aug 2021
System & Network Administrator (intern) — Greenworking

Administered systems and networks; automated operational tasks. First recorded sighting of the subject near a production system.

Origin story
2017 — 2022
Engineer's Degree (M.Sc.), Information Systems Security — INSA
Education
2014 — 2017
Baccalauréat, Science — English/Physics (DNL) — Lycée Jean de Lattre de Tassigny
Education
03 /

Case files

Open-source DFIR tooling. Full inventory on GitHub.

01

citadel →

FlagshipPythonECSOrchestration

End-to-end DFIR platform that composes standalone forensic tools: acquire, ingest, parse, normalize to ECS, detect, analyze, and report a case end to end — one investigation workflow.

2026
02

Madeleine →

PythonVolatility3ATT&CKSTIX

Memory forensics toolkit built on Volatility3: malware detection, timelining, and ECS/STIX export. The memory-analysis pillar of the DFIR suite.

2026
03

cumulonimbus →

AWSAzureGCPKubernetes

Cloud forensics & incident-response toolkit: collects, parses and normalizes AWS, Azure, GCP & Kubernetes logs to ECS v8 so cloud incidents can be triaged with one consistent schema.

2026
04

CherryPick →

WindowsLinuxmacOSYARA

Cross-OS forensic acquisition agent: walks a live host, mounted volume, disk image or raw device and gathers artifacts into a signed, content-addressed bundle. BitLocker- and YARA-aware.

2026
04 /

The arsenal

Proficiency self-reported. Treat with suspicion.

DFIR & Forensics exhibit B-1

Incident Response■■■■■■■■■■ 94
Digital Forensics (disk / memory)■■■■■■■■■■ 91
Volatility3 / memory analysis■■■■■■■■■■ 85
Malware analysis (static)■■■■■■■■■■ 78
MITRE ATT&CK■■■■■■■■■■ 88

Offensive exhibit B-2

Red Teaming■■■■■■■■■■ 82
Penetration Testing■■■■■■■■■■ 84
Network Security■■■■■■■■■■ 83

Detection & Data exhibit B-3

Elastic Stack (ELK)■■■■■■■■■■ 90
ECS normalization■■■■■■■■■■ 88
Threat Detection■■■■■■■■■■ 85
PostgreSQL■■■■■■■■■■ 72

Platform & Code exhibit B-4

Python■■■■■■■■■■ 93
Linux■■■■■■■■■■ 92
Kubernetes■■■■■■■■■■ 88
Docker■■■■■■■■■■ 87
Bash / Shell■■■■■■■■■■ 85

Confiscated at the door

PythonBashKubernetes DockerVolatility3YARA Elastic StackECSMITRE ATT&CK PostgreSQLFlaskKVM / libvirt Swift
05 /

Open a channel

All communications logged. Obviously.

Got an incident, a DFIR problem, or a tool idea that helps responders move faster? Transmit.

linkedin.com/in/nathan-buisson Fastest channel · FR / EN
Encrypted MailPGP
No email on the public site —
prefer encrypted mail? Ping me on
LinkedIn and I'll share a PGP key.

Response time: faster than a
cat /etc/shadow on a misconfigured box.