Work out forensic storage requirement instantly with clear inputs, formula shown and shareable results.
Forensic imaging captures full disks bit for bit plus volatile memory, so storage is host count times disk plus memory, multiplied by the number of evidence copies chain-of-custody procedure requires. Compression is usually avoided or applied only to the working copy, since the master must remain a verifiable bit-for-bit image with a matching hash.
Evidence volume
per host = disk size + memory size; total = per host x hosts x copies; imaging time = total bits / sustained rate
Encryption keys, injected code, network connections and running processes exist only in RAM. Powering the host off to image the disk destroys that evidence permanently.
The working copy can be. The master should stay uncompressed with a recorded hash so its integrity can be demonstrated independently of any tooling.