NewsTools
From 13,000 to 20,000+ Endpoints: Architecting Forensics for the Remote Workforce
via DZoneRahul Karne
Traditional forensic processes fail when dealing with a large number of devices (over 20,000), such as in Fortune 500–level organizations. At that scale, the idea of taking a full disk image of a 512 GB laptop over a VPN is virtually impossible before the device shuts down, the user restarts it, or the legal window expires. To overcome the physics bottleneck (bandwidth), we need to reverse how we think about remote data collection. Instead of bringing all the data to the tool, we need to send the tool to the data.
Continue reading on DZone
Opens in a new tab
7 views



