In #SANS FOR508 with @robtlee a quick class survey indicates that students spend avg 2 weeks per drive on forensics investigations.
3
5
2
@MalwareJake @robtlee Sounds about right. I wonder if they're including the time it takes to write the report.
1
@hal_pomeranz @robtlee The question was from phrased 'from acquisition to report' - many commented that it could be much, much longer
1
Replying to @MalwareJake
@MalwareJake Yeah, I've done "deep dives" on critical systems that have taken months.

Dec 12, 2013 · 11:50 PM UTC

3
Replying to @hal_pomeranz
@hal_pomeranz @MalwareJake I've had the report alone take much longer than that 2 weeks, but that's more the exception than the norm.
1
@W3nd1g04n6 @hal_pomeranz Eek. I'd hate for reporting to take that long. I'd fear the result would be a job search...
1
Replying to @hal_pomeranz
@hal_pomeranz No doubt. It's all about the specific case at hand.
Replying to @hal_pomeranz
@hal_pomeranz @MalwareJake I think it depends entirely on how convoluted the system is, and the type of operating system.