In #SANS FOR508 with @robtlee a quick class survey indicates that students spend avg 2 weeks per drive on forensics investigations.
3
5
2
@MalwareJake @robtlee Sounds about right. I wonder if they're including the time it takes to write the report.
1
@hal_pomeranz @robtlee The question was from phrased 'from acquisition to report' - many commented that it could be much, much longer
1
@MalwareJake Yeah, I've done "deep dives" on critical systems that have taken months.
3
@hal_pomeranz @MalwareJake I've had the report alone take much longer than that 2 weeks, but that's more the exception than the norm.
1
@W3nd1g04n6 @hal_pomeranz Eek. I'd hate for reporting to take that long. I'd fear the result would be a job search...
1
@MalwareJake @hal_pomeranz Or even more lawyers being involved.
1
Replying to @W3nd1g04n6
@W3nd1g04n6 @MalwareJake I've written some epic forensic reports in my time that have taken a couple of weeks. It's hell.

Dec 13, 2013 · 1:17 AM UTC