Declassified — Eyes Only
Subject is Nathan Buisson — Lead Forensics & N3 Incident Response at Free (Iliad). Red teamer turned DFIR lead: formerly breaking into networks for the Gendarmerie Nationale, now building Kubernetes-based DFIR tooling for a group CSIRT. Motto: assume breach — then prove it.
Compiled from field reports. Accuracy: confirmed by the subject.
Summary. Hey — I'm Nathan. I do incident response and offensive security. By day I lead Forensics & N3 incident response at Free (Iliad): building Kubernetes-based DFIR tooling, running major incidents, and driving a security-operations & governance transformation. Before that I broke into networks as a penetration tester for the Gendarmerie Nationale, and cut my teeth on blue-team incident response as a consultant.
By night I write open-source DFIR tools — memory forensics, cloud log normalization to ECS, file carving, malware triage, and attack timelines mapped to MITRE ATT&CK. If it helps a responder move faster during an incident, I want to build it.
Chronology reconstructed from timestamped artefacts.
Build and run Kubernetes-based DFIR tooling for the group CSIRT. Technical and team lead for N3 (deep) incident response, driving a major IS transformation across security operations and governance.
Ongoing operationOffensive engagements and network-security assessments. Built Python tooling for red-team operations and reporting.
OffenceHands-on incident response and forensic analysis for client engagements. Detection engineering on the Elastic Stack (ELK).
DefenceAdministered systems and networks; automated operational tasks. First recorded sighting of the subject near a production system.
Origin storyOpen-source DFIR tooling. Full inventory on GitHub.
End-to-end DFIR platform that composes standalone forensic tools: acquire, ingest, parse, normalize to ECS, detect, analyze, and report a case end to end — one investigation workflow.
Memory forensics toolkit built on Volatility3: malware detection, timelining, and ECS/STIX export. The memory-analysis pillar of the DFIR suite.
Cloud forensics & incident-response toolkit: collects, parses and normalizes AWS, Azure, GCP & Kubernetes logs to ECS v8 so cloud incidents can be triaged with one consistent schema.
Cross-OS forensic acquisition agent: walks a live host, mounted volume, disk image or raw device and gathers artifacts into a signed, content-addressed bundle. BitLocker- and YARA-aware.
Proficiency self-reported. Treat with suspicion.
All communications logged. Obviously.
Got an incident, a DFIR problem, or a tool idea that helps responders move faster? Transmit.
linkedin.com/in/nathan-buisson Fastest channel · FR / EN