PROF.MORRIS
file_03 · research
← Constellation Get in touch ↗
file_03 · research

Practice-led
research (and a lot
stays that way).

All research runs through the University of Southampton. Because Prof. Morris works operationally, much of it is not publicly available — restricted for legal reasons, embargoed pending casework, or held back for operational security. This is by design, not accident.

150+Total publications
2010Publishing since
🔒Most outputs restricted
UoSPractitioner access
Operational casework Mental Health in DFIR Mobile forensics IoT acquisition Document analysis Anti-forensics OS forensics Browser artefacts Operational casework Mental Health in DFIR Mobile forensics IoT acquisition Document analysis Anti-forensics OS forensics Browser artefacts
— why some research is restricted

An honest
explanation of
what can &
can't be shared.

Research from real operations has real constraints. Practitioner-honesty about restrictions is itself a signal of operational seriousness.

Operational casework

Live cases come first

Much of the research emerges directly from live or recent casework. Publishing during or immediately after a case can compromise legal proceedings, expose investigative methods, or breach obligations to clients. The work waits for the case to close.

Operational security

Some methods stay closed

Findings around acquisition techniques for unusual devices, anti-forensics, and novel attack vectors are deliberately not published openly. Public release would hand an advantage to those we investigate. These are shared selectively with verified practitioners.

Practitioner-only

Secured whitepapers

Whitepapers, technical notes, acquisition guides — available through the University of Southampton to verified practitioners. These are not academic journal articles. They are operational tools.

Public

Open where possible

Peer-reviewed journal papers and conference proceedings that don't carry operational risk are published openly and listed below. They represent the publicly shareable portion of a much larger body of work.

Practitioner access via UoS ↗
— publicly available outputs

Peer-reviewed
publications.

A reverse-chronological selection of openly-published work. For secured whitepaper outputs available to verified practitioners, contact via the University of Southampton.

2023
Morris S, Hadgkiss M, David A, Guiness J, Frewin C
WIREs Forensic Science · e1487
2022
Hadgkiss M, Morris S, Paget S, Ventress A, Norris K
FSI: Digital Investigation · Vols 42–43
2021
Ashawa M, Morris S
Journal of Cybersecurity and Privacy · Vol 1, Issue 4
David A, Morris S, Appleby-Thomas G
JDFSL · Vol 16, Issue 1
Jarrett M, Morris S
FSI: Digital Investigation · 39
2020
David A, Morris S, Appleby-Thomas G
JDFSL · Vol 15, Issue 2
2019
Ashawa M, Morris S
Analysis of Android malware detection techniques: a systematic review
Earlier proceedings
2018 ↓ 2010
Various co-authors
Earlier work spanning mobile forensics, file systems, browser artefacts, document analysis, and OS forensics
Multiple venues · Available via UoS profile

A full publication list — including the openly-shareable older work — is maintained on the University of Southampton profile. Practitioner-only outputs are available on request to verified practitioners.

Full publication list at UoS ↗ Discuss collaboration →
Other case files
Get in touch