About

About

Hi, I’m Aurélien 👋

I’m a Senior Incident Responder specialising in DFIR and threat hunting, based in Belgium. For more than 9 years, I’ve been helping organisations detect attacks, understand how they happened, and regain control when an incident strikes.

This blog is where I share hands-on write-ups from the field: malware analysis, incident response techniques, forensic artefacts, detection engineering and threat hunting. Expect practical content, real commands, and IOCs you can actually use.

Background

My career began in the networks of the Belgian Ministry of Defence, first as a network technician and then as a cybersecurity analyst within the Belgian Cyber Command, investigating advanced threats on classified environments, including suspected state-sponsored activity.

I then moved into incident response, handling 50+ incidents, including several large-scale ransomware attacks. Today I work in the financial sector, within a global incident response team.

I’ve also defended 5,000+ systems at Locked Shields, the world’s largest live-fire cyber defence exercise, and served on the EU Cyber Rapid Response Teams (CRRT).

Certifications

  • Expert level (GIAC): GSE #433, GSP, GX-PT, GX-IH, GX-IA, GX-CS
  • Forensics, detection & response: GCIH, GCIA, GCDA, GNFA, GBFA, BTL1, HTB CDSA, CCD / CCDL2
  • Offensive: GPEN, GAWN, CRTO, HTB CPTS
  • Specialties: Ransomware negotiation, Blockchain analysis (Chainalysis), GSEC

Verify on Credly and GIAC.

Speaking

  • DFIR at the speed of a Velociraptor
    • Barbhack 2025, Toulon, France
    • Hackfest 2025, Quebec, Canada
    • Unlock Your Brain 2025, Brest, France

Need help?

Through Cyber Horizon, I offer incident response, threat hunting, penetration testing, MDR and training for businesses.

📧 info@cyberhorizon.be · 💼 LinkedIn


Opinions expressed on this blog are my own and do not reflect those of my employer.