The aim of the module is to investigate the principles of operating systems and how they hinder or support forensic investigation. The module includes significant practical sessions in applying computer forensics in realistic real-world scenarios, allowing students to analyse and evaluate digital evidence through the use of forensic tools and techniques. The practicals will be complemented with considerable theoretical knowledge of operating system information as digital evidence, and the basic techniques associated with gathering, preserving and presenting digital evidence. Outlines of the main areas include:? Introduction to common operating systems such as Windows, Linux, Android? Forensic artefacts specific to the operating system and their role as digital evidence (for example, the Windows registry).? Exploration of user data areas, directories and files.