The investigation of computer crime is a delicate, involved process that requires a deep understanding of the evidential standards expected in circumstances where electronic forensic data is to be used. This course describes the current best practice in understanding and deconstructing an attack whilst preserving evidence, and explores how to design and evaluate systems in order to facilitate forensic examination. It combines a strong overview of principles with some illustrative practical work, recovering data using necessarily low-level tools.