In #SANS FOR508 with @robtlee a quick class survey indicates that students spend avg 2 weeks per drive on forensics investigations.
3
5
2
Replying to @MalwareJake
@MalwareJake @robtlee Sounds about right. I wonder if they're including the time it takes to write the report.

Dec 12, 2013 · 9:05 PM UTC

1
Replying to @hal_pomeranz
@hal_pomeranz @robtlee The question was from phrased 'from acquisition to report' - many commented that it could be much, much longer
1
@MalwareJake Yeah, I've done "deep dives" on critical systems that have taken months.
3