★ 18+ YEARS CHASING DIGITAL EVIDENCE ★ 170+ INVESTIGATIONS WORLDWIDE ★ CHURCHILL FELLOW 2025 ★ FOUNDER, SHERFOX LABS ★ OPENLY AUTISTIC ACADEMIC ★ HAS FORENSICALLY EXAMINED A WASHING MACHINE ★ TYPE THE WORD "FOX" ANYWHERE ON THIS PAGE...
★ 18+ YEARS CHASING DIGITAL EVIDENCE ★ 170+ INVESTIGATIONS WORLDWIDE ★ CHURCHILL FELLOW 2025 ★ FOUNDER, SHERFOX LABS ★ OPENLY AUTISTIC ACADEMIC ★ HAS FORENSICALLY EXAMINED A WASHING MACHINE ★ TYPE THE WORD "FOX" ANYWHERE ON THIS PAGE...
Hi, I'm Prof. Sarah Morris
Digital Exploitation and Intelligence · University of Southampton
I take apart devices, drag secrets out of broken hard drives, and occasionally perform stand-up comedy about all of it. Poke a bubble below to find out more.
0+ yrs casework
0+ investigations
2015 churchill fellow
0 lab humans
👋 About Me
🕵️ Casework
🧪 Research
🏛️ Advisory
📺 Media
💛 Wellbeing
🦊 My Lab
📄 Downloads
💌 Say Hello
🎲 Random Fact
✕
EXHIBIT A · THE PROF.
About Me
I'm a Professor of Digital Forensics at the University of Southampton, and Deputy Head of School (Knowledge Exchange and Enterprise) for the School of Electronics and Computer Science. I hold a chair, in Digital Exploitation and Intelligence, though "the Chair" makes it sound grander than it is; it's a standard professorship, I just get to pick the wording on the certificate. In 2022 I founded a digital forensics lab called SherFox.
My PhD proved that thumbnail cache file fragments hiding in unallocated space are forensically valuable, a sentence that has ended more pub conversations than started them. (There's a whole page on the research itself if you want the properly academic version.)
"If we needed it and it didn't exist, we built it."
0+ investigations, worldwide
I'm a 2025 Churchill Fellow . My advisory and public-service roles (Home Office, NPCC, the House of Lords, that sort of thing) get their own page, since the list got long enough to need one.
Before Southampton, at Cranfield University, I secured the first NCSC/GCHQ-certified MSc in Digital Forensics (2017).
I'm an openly autistic academic and an active advocate for neurodivergent researchers in cyber security. Outside the lab: policy work, media commentary, and science-based stand-up comedy, writing and performing my own material.
✕
EXHIBIT B · THE DAY JOB
Casework
I'm a practitioner as much as an academic, so the theory gets tested against real devices, real deadlines, and real courtrooms. Criminal, civil, employment, corporate, private, and media instructions, across multiple jurisdictions, and it covers a lot more ground than "document forensics" suggests.
Acquisition, every device type Mobile, computer, vehicle, IoT, cloud, and comms data, plus damaged, legacy, or plain unusual hardware. Chip-off, JTAG, and ISP where needed.
Document & data forensics Data recovery, bespoke and legacy file formats, file fragment identification and reassembly.
Memory, malware & intrusion Volatile memory analysis, anti-forensics, persistence mechanisms, APT investigation.
Video, image & audio CCTV recovery, authentication, frame-by-frame analysis, AI-generated media detection.
OSINT & correlation Open-source intelligence, and reconciling multiple sources into one defensible timeline.
Expert witness & review Independent expert reports, Single Joint Expert instructions, peer review of opposing reports, ISO accreditation review.
Corporate & insider matters Discreet internal investigations, breach response, incident response, insider threat.
Pre-action advisory Early technical advice on whether a case has digital-evidence merit, and what to preserve.
Yes, I have forensically examined a washing machine. No, I will not stop bringing it up.
✕
EXHIBIT C · THE THEORY BIT
Research
My research begins from a deceptively simple problem: the devices that now hold the evidence of modern life were never designed to be examined. Operating systems, applications, and storage formats change constantly, often without documentation, and an investigator is routinely asked to recover reliable, defensible meaning from data that is fragmentary, proprietary, or actively obscured. My work is a sustained answer to that problem, pursued at the level where it actually has to be solved: the binary itself.
Much of it concerns acquisition and recovery: how evidence is faithfully obtained from a device in the first place, and how it can be reconstructed when it survives only in pieces. Document forensics, data recovery, acquisition approaches, and bespoke data formats all share a common concern with extracting structure and significance from incomplete or undocumented data, alongside a longstanding interest in file carving and digital archaeology. Where existing tools fall short, particularly against unusual or emerging formats, I build the methodology that doesn't yet exist.
Bytes alone are rarely the answer, though. A second strand moves from recovery to interpretation: what does recovered data actually mean within an investigation? That question gets harder as devices become interdependent, which is why current projects include the forensic contextual value of AI services and activity on mobile devices, smart wearable forensics, novel acquisition approaches, and IoT forensic chain reactions, where the state of one connected device cascades into the evidential picture of another.
Running through all of it: research should serve the people who depend on it. I'm an active practitioner as well as an academic, and the work is oriented explicitly toward supporting practitioners on the ground, not toward sitting quietly in a journal.
Document forensics Metadata, authenticity, hidden content.
File fragment ID My doctoral home turf, still going strong.
Acquisition methods New approaches for legacy and unusual media.
IoT & wearables Smart devices and connected ecosystems.
✕
EXHIBIT C½ · ADVISORY & PUBLIC SERVICE
Advisory Roles
This list got long enough that lumping it into my bio stopped being fair to it, so it gets its own space.
Home Office Science Advisory Council Member (HOSAC).
Home Office STEAC Engagement Lead, and Working Group Lead for AI & Emerging Technology. Formerly the Biometrics and Forensics Ethics Group (BFEG), since 2021.
NPCC Police Science Council Member; co-led the Future of Digital Forensics review.
House of Lords Oral evidence to the Select Committee on Forensic Science, on two occasions.
ECS Partners Ltd Director.
Awards & recognition (20 total)
0 educational, including student-led teaching awards and a Vice-Chancellor's Award finalist placement (top 3 university-wide)
✕
EXHIBIT D · ON SCREEN
Media
I do a fair bit of media work, mostly turning "what does this evidence actually show" into something that isn't three hours of acronyms.
✕
EXHIBIT E · CHURCHILL FELLOW 2025
Wellbeing
Digital forensics involves looking at genuinely awful material, repeatedly, and our sector hasn't talked about that enough. My 2025 Churchill Fellowship looks at how other countries support the mental health of digital forensic practitioners, and brings back practical, compassionate recommendations for the UK.
Grounded in peer-reviewed research on trauma exposure among UK-based digital forensic investigators. Not a hunch.
Need to talk to someone right now?
✕
EXHIBIT F · WHERE THE WORK HAPPENS
My Lab: SherFox
27 people · 250+ combined years · 15 CPD courses · 7 home-built tools · one fictional investigation universe called Cyberly.
I founded SherFox in 2022, the University of Southampton's operational digital forensics laboratory. Most of us hold day jobs in active practice alongside the academic side. CPD courses, home-built tools (AURORA, SCOUT, ReviewBox, SpectrumAcquire, SignalSentinel, BOB, The Lattice), and a fair amount of cheese jokes, all live here.
sherfoxlabs.com ↗
cyberlyhq.com ↗
✕
EXHIBIT G · PAPERWORK
Downloads
Three brochures, because apparently one was never going to cover it. All viewable here, or grab your own copy.
Preview not loading on your phone? The download button opens it directly.
✕
EXHIBIT H · SAY HELLO
Find Me
Further sources, every link I found while building this page:
Official pages
Research
Advisory & wellbeing
Media coverage
✕
EXHIBIT ??? · RANDOM PROF FACT
Roll again
Click the button below for a fact.
🎲 Gimme another
🎲