All research runs through the University of Southampton. Because Prof. Morris works operationally, much of it is not publicly available — restricted for legal reasons, embargoed pending casework, or held back for operational security. This is by design, not accident.
Research from real operations has real constraints. Practitioner-honesty about restrictions is itself a signal of operational seriousness.
Much of the research emerges directly from live or recent casework. Publishing during or immediately after a case can compromise legal proceedings, expose investigative methods, or breach obligations to clients. The work waits for the case to close.
Findings around acquisition techniques for unusual devices, anti-forensics, and novel attack vectors are deliberately not published openly. Public release would hand an advantage to those we investigate. These are shared selectively with verified practitioners.
Whitepapers, technical notes, acquisition guides — available through the University of Southampton to verified practitioners. These are not academic journal articles. They are operational tools.
Peer-reviewed journal papers and conference proceedings that don't carry operational risk are published openly and listed below. They represent the publicly shareable portion of a much larger body of work.
A reverse-chronological selection of openly-published work. For secured whitepaper outputs available to verified practitioners, contact via the University of Southampton.
A full publication list — including the openly-shareable older work — is maintained on the University of Southampton profile. Practitioner-only outputs are available on request to verified practitioners.
Full publication list at UoS ↗ Discuss collaboration →