Prerequisite(s): ITN 276. Develops skills in the forensic extraction of computer evidence at a logical level using a variety of operating systems and applications (i.e. e-mail), and learn techniques for recovering data from virtual memory, temporary Internet files, and intentionally hidden files. Lecture 3 hours per week.