Eighteen years of getting to the bottom of things — including a washing machine. Criminal, civil, corporate, intelligence. If it's digital and nobody else knows what to do with it, that's where this work begins.
Every engagement starts with a short conversation. Scope, quote, then work — keeping everything robust and legally defensible throughout.
A fully equipped digital forensics lab with hardware and software capability for device, document, and communications investigations. Sherfox Labs brings together practitioners and academics across computing, electronics, and law. Real-world mess handled with research-grade care. If there is no good tool for the job, we build one.
A short selection of past cases, anonymised. Names changed. Outcomes preserved. They show the shape of the work — not its details.
A washing machine offered as an alibi. The defence argued the device couldn't have been operated remotely. Acquisition required reverse-engineering a bespoke filesystem; the resulting timeline proved remote activation was not only possible but had occurred.
An IoT garage door at the centre of a divorce case. Logs had to be recovered from a device that wasn't designed to keep them — then verified for reliability before they could carry weight in family proceedings.
Evidence remotely wiped from a company device prior to acquisition. Recovery from unallocated space yielded enough to support the claim — and to demonstrate the deliberate nature of the deletion.
Pay fraud and falsified timesheets across multiple devices. Covert acquisition was followed by a unified timeline analysis that mapped activity across systems and put the dates beyond reasonable challenge.
More cases available on request, subject to confidentiality and legal constraints.
If your problem doesn't fit neatly into a category — that's usually exactly the point. Unusual is welcome.
Digital forensic analysis. Acquisition strategy and storage realities. Evidence communication, technical and non-technical. Legal, ethical and court considerations.
Mobile, app and browser artefacts. IoT and unusual devices. Vehicle, GPS, maritime and drone contexts. Operating system and file system analysis.
Email and communications data. Network and corporate investigations. Digital document analysis. Multimedia analysis and interpretation.
Engagements run through the University of Southampton and Sherfox Labs. For anything not listed — get in touch. Unusual requests are genuinely welcome.
Artefact analysis · Data recovery · Full investigations · Independent review
Artefact and data analysis · Data recovery · Document forensics · Framework design
Accreditation paperwork · Lab design · Protocols and frameworks · Training plans
TV, radio, magazine, social media — live and pre-recorded. Experienced with all formats.
General computing to highly technical sessions. Any age, any audience. School workshops too.
PhD, MPhil, MSc by Research and MSc projects through University of Southampton.
STEM mentoring for teenagers. ECS Mentor across a range of areas.
Wide variety of cybercrime and digital investigation topics. Practitioner-focused.
If what you're looking for isn't listed and you think Prof. Morris may help — just ask. The unusual cases are often the most interesting.