Quote:
anyone scoffing at live system forensics hasn't worked in a preassure cooker like a University where we get whacked boxes frequently. Live forensics allows us to make an inspection and within a half an hour make the "rebuild/remediate" decision w/ some intel. WFT has proven itself amply well over the past year here at my school. So much so that I developed a course for my sfaff on live system forensics, and now I have my job back.
Anyone praising live system forensics is wasting their organization quite a bit of money in training, time, and just all around inefficient system configuration.