image-video-forensics.md (27972B)
1 --- 2 title: "Image & Video Forensics" 3 description: "Read a file's metadata, test it for manipulation, and work out what the camera and encoder can tell you." 4 category: osint 5 subcategory: "Images & Video" 6 tags: [osint, forensics, metadata, exif, verification] 7 tools: [exiftool, ffprobe, ffmpeg, mediainfo, fotoforensics, forensically, invid] 8 difficulty: intermediate 9 updated: 2026-10-03 10 references: 11 - name: "Bellingcat's Online Investigation Toolkit" 12 url: "https://bellingcat.gitbook.io/toolkit" 13 author: "Bellingcat" 14 license: none 15 relation: derived 16 note: "Tool catalogue: names, descriptions, cost flags and links for this area." 17 - name: "OSINT Newsletter Tools Library" 18 url: "https://tools.osintnewsletter.com" 19 author: "The OSINT Newsletter" 20 license: none 21 relation: derived 22 note: "Second tool catalogue, cross-checked against the above." 23 --- 24 25 ## What this covers 26 27 What the file itself says, as distinct from what its caption says. Metadata gives you camera, time 28 and sometimes location; container and encoder artefacts tell you the processing history; 29 manipulation analysis suggests where to look harder. None of it is proof on its own, and all of it 30 is easy to over-read. 31 32 ## Method 33 34 1. **Hash the file before you touch it.** `shasum -a 256 evidence.jpg`, recorded with the time you 35 received it and who from. Every later claim you make is about that hash. Work on a copy. 36 2. **Ask for the original.** Every major platform re-encodes and strips metadata on upload, so a 37 file pulled from a timeline has already lost most of what you want. The original off the camera 38 or phone is a different artefact from the one in the post. 39 3. **Read metadata before anything else**, because it is cheap and it either corroborates the claim 40 or contradicts it. A contradiction is a lead; agreement is weak evidence, since metadata is 41 trivially written. 42 4. **Inventory the container separately from the codec.** The file extension, the container brand 43 and the codec inside it are three independent facts, and a mismatch between them means a tool 44 touched the file after capture. 45 5. **Only then run manipulation analysis.** Error Level Analysis and noise residual tell you where 46 to look, not what happened. Decide in advance what result would change your conclusion; 47 otherwise you will find whatever you went looking for. 48 6. **Corroborate outside the file.** The defensible finding is the one that survives a second, 49 independent source — a different upload of the same footage, a shadow angle consistent with the 50 claimed time, a satellite pass over the claimed place. The file alone almost never settles it. 51 7. **Record what you ran.** Keep the exact command, its full output and the tool version alongside 52 the hash. "exiftool showed no GPS" is not reproducible; a saved JSON dump with a version string 53 is. 54 55 ## Key tools 56 57 ### ExifTool 58 59 The reference metadata reader and writer, and the only one worth learning properly. It parses more 60 tag families than anything else — EXIF, XMP, IPTC, ICC, maker notes, QuickTime atoms, PDF and 61 RIFF — and it tells you which family each tag came from, which matters because the same logical 62 field appears in several places and they disagree when a file has been edited. 63 64 ```bash 65 brew install exiftool # or: apt install libimage-exiftool-perl 66 ``` 67 68 ```bash 69 # everything, grouped and labelled by the tag family it came from 70 exiftool -a -G1 -s image.jpg 71 72 # the fields that usually decide a question, in one line 73 exiftool -Make -Model -DateTimeOriginal -CreateDate -ModifyDate \ 74 -GPSLatitude -GPSLongitude -Software -Orientation image.jpg 75 76 # every timestamp in the file at once: camera, GPS, filesystem, XMP 77 exiftool -time:all -a -G1 -s image.jpg 78 79 # GPS as a decimal pair you can paste straight into a map 80 exiftool -n -p '$GPSLatitude,$GPSLongitude' image.jpg 81 82 # maker notes and undecoded tags — where lens, shutter count and burst IDs hide 83 exiftool -U -a -G1 image.jpg 84 85 # structural sanity check: does the file match its own format spec 86 exiftool -validate -warning -a image.jpg 87 88 # the full set as JSON, which is what you archive next to the hash 89 exiftool -j -g1 -a image.jpg > image.exif.json 90 91 # a whole directory into one CSV, so you can sort a set by camera and time 92 exiftool -r -csv -Make -Model -SerialNumber -DateTimeOriginal -GPSPosition ./images/ > meta.csv 93 94 # embedded metadata in video streams, not just the container header 95 exiftool -ee -G3 -a clip.mp4 96 97 # strip everything before you publish, to protect a source 98 exiftool -all= -overwrite_original copy.jpg 99 ``` 100 101 Reading the output: `Make`/`Model` should match the claimed device, and a `SerialNumber` that 102 recurs across a set ties those files to one body. `Software` naming an editor means the file was 103 processed — not that it was faked, but that this is not the original. `DateTimeOriginal` is capture 104 time from the camera clock, which carries no timezone and is routinely wrong by hours or years; 105 `CreateDate` and `ModifyDate` can be later. `-validate` flagging a truncated or non-conforming 106 structure is a genuine signal that something rewrote the file. 107 108 Missing metadata is the normal case, not a red flag — platform stripping accounts for almost all of 109 it. The reverse error is worse: metadata that supports a convenient claim proves very little, 110 because `exiftool` writes as easily as it reads, and a forged `DateTimeOriginal` takes one command. 111 Treat supporting metadata as consistent-with, and contradicting metadata as a thread to pull. 112 113 ### ffprobe 114 115 Stream and container inventory for video and audio. Use it to establish what the file actually is 116 before you argue about what it shows: how many streams, which codec, what container brand, whether 117 the frame rate is constant, and where the keyframes fall. 118 119 ```bash 120 brew install ffmpeg # ffprobe ships with ffmpeg 121 ``` 122 123 ```bash 124 # full container and stream dump, archived next to the hash 125 ffprobe -v error -print_format json -show_format -show_streams video.mp4 > video.probe.json 126 127 # the container's own identity: brand, duration, and who wrote it 128 ffprobe -v error -show_entries format=format_name,format_long_name,duration:format_tags \ 129 -of default=nw=1 video.mp4 130 131 # codec vs container in one view — mismatches start here 132 ffprobe -v error -select_streams v -show_entries \ 133 stream=codec_name,codec_tag_string,profile,level,pix_fmt,width,height,r_frame_rate,avg_frame_rate,nb_frames \ 134 -of default=nw=1 video.mp4 135 136 # encoder string and creation time, which usually name the producing app 137 ffprobe -v error -show_entries format_tags=creation_time,encoder,com.apple.quicktime.software \ 138 -of default=nw=1 video.mp4 139 140 # frame types and timestamps: is the cadence constant, where are the I-frames 141 ffprobe -v error -select_streams v -show_entries frame=pts_time,pict_type \ 142 -of csv=p=0 video.mp4 | head -50 143 144 # keyframe interval from the packet layer, cheaper than decoding frames 145 ffprobe -v error -select_streams v -show_entries packet=pts_time,flags,size \ 146 -of csv=p=0 video.mp4 | awk -F, '$2 ~ /K/ {print $1}' | head -20 147 148 # is there a second audio track, a timecode track, or stray metadata streams 149 ffprobe -v error -show_entries stream=index,codec_type,codec_name -of csv=p=0 video.mp4 150 ``` 151 152 Note that `pkt_pts_time` was removed in ffmpeg 5 — on any current build the entry is `pts_time`, 153 and an old recipe using the former silently returns an empty column rather than erroring. 154 155 **Container-versus-codec mismatch is the single most useful manipulation signal in video.** A file 156 named `.mp4` whose `format_name` is `matroska`, an iPhone clip whose major brand is not `qt`/`mp4`, 157 H.264 in a container the capturing device never writes, or a `creation_time` later than the claimed 158 upload — each means something re-muxed or re-encoded the file. Encoder strings are a strong 159 fingerprint of the producing application: a clip claimed to be straight off a phone but carrying a 160 desktop editor's encoder has been through an edit, and that is a finding you can state plainly. 161 Variable frame rate where the device records constant, or an `nb_frames` that does not match 162 duration times frame rate, points the same way. 163 164 What this does not tell you: nothing in the stream inventory distinguishes an innocent re-encode — 165 a messaging app, a download wrapper, a format conversion for upload — from a deliberate edit. It 166 tells you the file is not the original, and that you should be arguing about provenance rather than 167 about pixels. 168 169 ### ffmpeg 170 171 Extraction, not analysis. Use it to pull the frames you will actually look at, and to cut the 172 segment you will cite, without silently re-encoding what you cite. 173 174 ```bash 175 # every keyframe, decoded fast because P- and B-frames are skipped entirely 176 ffmpeg -skip_frame nokey -i video.mp4 -fps_mode vfr keyframes/kf_%04d.png 177 178 # frames at scene changes: 0.3-0.5 is the useful threshold range 179 ffmpeg -i video.mp4 -vf "select='gt(scene,0.4)',showinfo" -fps_mode vfr scenes/sc_%04d.png 180 181 # a contact sheet of keyframes, for finding the shot you need 182 ffmpeg -skip_frame nokey -i video.mp4 -vf "scale=240:-1,tile=5x4" -frames:v 1 sheet.jpg 183 184 # the exact frame at a timestamp, for a geolocation attempt 185 ffmpeg -ss 00:01:37.500 -i video.mp4 -frames:v 1 -q:v 2 frame.jpg 186 187 # cut a clip without re-encoding, so the excerpt keeps the original stream 188 ffmpeg -ss 00:01:30 -to 00:01:50 -i video.mp4 -c copy excerpt.mp4 189 190 # extract the audio untouched — background sound often dates or places a clip 191 ffmpeg -i video.mp4 -vn -c:a copy audio.m4a 192 193 # log scene-change scores to a file instead of writing frames, to find the cut points 194 ffmpeg -i video.mp4 -vf "select='gt(scene,0.3)',metadata=print:file=scenes.txt" -f null - 195 ``` 196 197 `-c copy` matters for anything you will publish or hand to someone else: re-encoding an excerpt 198 destroys the compression history that any later analysis would use, and makes your excerpt 199 unfalsifiable in the wrong direction. `-fps_mode vfr` replaced `-vsync vfr` in ffmpeg 5, and `-vsync` 200 was removed outright in ffmpeg 9 — it now fails with `Unrecognized option 'vsync'`. Any older 201 cheatsheet or Stack Overflow answer using it will not run. 202 203 Scene-change detection finds cuts, and cuts in material claimed to be a single continuous recording 204 are worth explaining. It also fires on pans, flashes and camera shake, so read the list as 205 candidates. 206 207 ### MediaInfo 208 209 A second opinion on container structure, with a tag vocabulary closer to how broadcast and 210 camera manufacturers name things. Worth running alongside `ffprobe` because it surfaces writing 211 library, muxing application and per-track UUIDs that ffmpeg's inventory does not break out. 212 213 ```bash 214 brew install mediainfo # or: apt install mediainfo 215 ``` 216 217 ```bash 218 # human-readable, every track 219 mediainfo video.mp4 220 221 # full detail including container atoms and writing library 222 mediainfo --Full video.mp4 223 224 # machine-readable, for archiving next to the hash 225 mediainfo --Output=JSON video.mp4 > video.mediainfo.json 226 227 # just the fields that identify the producing tool 228 mediainfo --Inform="General;%Format%|%Encoded_Application%|%Encoded_Library%|%Encoded_Date%" video.mp4 229 230 # batch a directory and diff the writing libraries across a set 231 mediainfo --Output=CSV ./clips/ > clips.csv 232 ``` 233 234 Where `ffprobe` and `mediainfo` disagree about the container, that disagreement is itself 235 informative: it usually means the file is malformed or was written by something that does not 236 follow the spec. 237 238 ### FotoForensics 239 240 Web-only Error Level Analysis, JPEG quality estimation and metadata, run on an upload. The useful 241 part is not the ELA image, it is the combination of the quality estimate and the metadata panel on 242 the same screen. 243 244 What you do: paste a URL or upload the file at [fotoforensics.com](https://fotoforensics.com/). 245 Read the panels in this order. 246 247 ```text 248 1. Metadata confirm it matches what exiftool told you; if it differs, the 249 upload was re-encoded in transit and the analysis is of the wrong file 250 2. JPEG Quality a quality estimate well below the camera's normal output means 251 at least one re-save; "last saved at ~75%" is a provenance fact 252 3. ELA uniform noise across a single-source photo is the expected result; 253 look for a region whose edge brightness differs sharply from 254 identically-textured regions elsewhere in the same frame 255 4. Hidden Pixels cropped-out image data still present in the file 256 ``` 257 258 Capture for the record: the analysis URL, a screenshot of each panel, and the quality estimate as a 259 number. The URL alone is not enough, because the site's analysis can change. 260 261 **This site publicly retains uploads.** Anything you submit becomes part of a public corpus. Do not 262 put a source's photograph, an unpublished image or anything identifying a person at risk into it — 263 use Forensically instead, which runs locally in the browser. 264 265 **ELA is the most over-interpreted technique in this field.** Differing compression across regions 266 has mundane causes: resizing, text overlay, a logo burned in, successive saves, a screenshot of a 267 screenshot. ELA tells you where to look harder. It never tells you a region was pasted in, and an 268 ELA image with arrows drawn on it is not a finding. 269 270 ### Forensically 271 272 The same family of analyses, running entirely client-side in your browser, so the file never leaves 273 your machine. That makes it the right default for sensitive material, and it adds clone detection 274 and a noise view that FotoForensics does not. 275 276 Open [29a.ch/photo-forensics](https://29a.ch/photo-forensics/) and drop the file in. The panels 277 worth your time: 278 279 ```text 280 Clone Detection finds regions similar to other regions in the same image; raise the 281 threshold until repetitive texture (foliage, gravel, sky) stops matching 282 itself, then look at what still matches 283 Noise Analysis a pasted region often carries a different sensor noise floor; flat or 284 smoothed patches in an otherwise noisy frame are the signal 285 Level Sweep sweeps the brightness range to expose banding and edges hidden in 286 shadow or blown highlights 287 Luminance Gradient surfaces inconsistent lighting direction across objects that should 288 share one light source 289 Magnifier pixel-level inspection for resampling edges around inserted text 290 ``` 291 292 Shut the browser tab when you are done and nothing has been transmitted. Noise analysis degrades 293 badly on anything heavily compressed or resized, which is most images sourced from social media — 294 if the file has been through a platform, expect all of these panels to be inconclusive and say so 295 rather than straining to read them. 296 297 ### InVID / WeVerify plugin 298 299 A browser extension that bundles the video-specific steps: keyframe extraction from a platform URL 300 without downloading the file yourself, reverse image search of those keyframes across several 301 engines in one click, a Twitter/X timeline search by time window, and a magnifier. 302 303 Install from [weverify.eu/verification-plugin](https://weverify.eu/verification-plugin/). It is 304 maintained as part of an EU research project, so expect individual platform integrations to break 305 when those platforms change their markup; the keyframe and reverse-search functions are the durable 306 parts. Use it for triage, then come back to `ffmpeg` and `exiftool` for anything you intend to 307 publish, because the plugin does not give you a reproducible command or a hash. 308 309 ### Hashing and the record 310 311 The thing that makes a forensic finding defensible is not the analysis, it is the chain from the 312 file you were given to the file you analysed. 313 314 ```bash 315 # the hash you cite, computed before any processing 316 shasum -a 256 evidence.mp4 | tee evidence.sha256 317 318 # hash a whole set, so a later re-download can be compared 319 find ./evidence -type f -exec shasum -a 256 {} \; > manifest.sha256 320 321 # verify nothing drifted while you worked 322 shasum -a 256 -c manifest.sha256 323 324 # perceptual hash, for matching re-encodes of the same footage across platforms 325 ffmpeg -i a.mp4 -i b.mp4 -filter_complex "signature=nb_inputs=2:detectmode=full" -f null - 326 ``` 327 328 Record alongside the hash: where the file came from and when, the archive copy 329 ([see archiving and evidence](/sheets/osint/archiving-and-evidence)), the tool versions, and the 330 exact commands with their output. A cryptographic hash and a perceptual hash answer different 331 questions — the first proves you analysed the file you were given, the second lets you say two 332 differently-encoded uploads are the same recording. 333 334 ### Further viewers and one-pass analysers 335 336 The long tail, useful when you want a second opinion or have no shell to hand. 337 338 | Tool | What it does | 339 | --- | --- | 340 | [Reveal Image Verification Assistant](https://mever.iti.gr/forensics/) | Runs several forensic filters in one pass and produces a report, which saves time on triage; the filters are the same family as Forensically's, so treat agreement between them as one result, not two. | 341 | [Jimpl](https://jimpl.com/) | Browser EXIF and GPS viewer with a map pin. Quick, and fine for a file you do not mind uploading. | 342 | [xIFr](https://xifr.eu/) | Detailed EXIF viewer that decodes maker notes, which is the one thing a casual viewer usually drops. | 343 | [metadata2go](https://www.metadata2go.com/) | Metadata for both images and video in a browser, when you cannot install anything. | 344 | [DeepFake-O-Meter](https://zinc.cse.buffalo.edu/ubmdfl/deep-o-meter/) | Academic ensemble of synthetic-media detectors. Reports a score, not a verdict, and false positives on compressed footage are common — never cite it alone. | 345 346 Any of these that works by upload has the same exposure problem as FotoForensics: assume the file 347 is retained. For sensitive material the only safe tools are the local ones. 348 349 ## Facial recognition 350 351 Searching a face across the web, rather than searching an image. Treat this as a 352 different category of act from reverse image search: it identifies a person, the error 353 rate is not zero, and a false match aimed at the wrong human causes real harm. Several 354 of these are barred or restricted in some jurisdictions, and uploading someone's face 355 to a commercial service hands that service biometric data about them. 356 357 Use it to *corroborate* an identity you already have reason to suspect, not to generate 358 one from nothing, and never treat a match as confirmation on its own. 359 360 | Tool | What it does | Cost | 361 | --- | --- | --- | 362 | [Amazon Rekognition](https://aws.amazon.com/rekognition/) | Check how similar two faces are | free | 363 | [Azure AI Video Indexer](https://vi.microsoft.com/en-us) | AI video tool for facial detection and other types of insights. | paid | 364 | [Face Comparison by ToolPie](https://facecomparison.toolpie.com/) | Compares two human face photos to determine similarity. | free | 365 | [FaceCheck.ID](https://facecheck.id/) | A facial recognition search engine that tries to find photos of people that look similar to a person of interest. | paid | 366 | [PimEyes](https://pimeyes.com/en) | An AI-powered facial recognition reverse image search tool. | paid | 367 | [Search4Faces](https://search4faces.com) | Upload the picture of a face and find pictures of similar looking people on VKontakte, Odnoklassniki, TikTok and Clubhouse. | free | 368 369 ## Tool reference 370 371 | Tool | What it does | Cost | 372 | --- | --- | --- | 373 | [Am I Real?](https://seintpl.github.io/AmIReal/) | A simple online tool that allows users to check whether a photo might have been generated by ThisPersonDoesNotExist.com. | free | 374 | [AutoStitch](https://mattabrown.github.io/autostitch.html) | Autostitch is a free tool for seamlessly combining multiple photos into a single panoramic image, making it ideal for creating wide-angle photography… | free | 375 | [Cleanup.Pictures](https://cleanup.pictures/) | Web tool for quickly removing objects from an image. | free | 376 | [DeepFake-O-Meter](https://zinc.cse.buffalo.edu/ubmdfl/deep-o-meter/) | DeepFake-O-Meter is an online tool designed to detect deepfake media and help users differentiate between genuine and manipulated content. | free | 377 | [ExifPurge](http://www.exifpurge.com/) | EXIF Purge is a small portable application to remove EXIF metadata from multiple images at once. With the click of a button you can remove the camera… | free | 378 | [fdupes](https://github.com/adrianlopezroche/fdupes) | Github - Locating exact matches of duplicate files. | free | 379 | [Hugin](https://hugin.sourceforge.io/) | Hugin is a free and open-source panorama photo stitching and HDR (High Dynamic Range imaging) merging software that helps users create seamless panoramic… | free | 380 | [InVID](https://weverify.eu/verification-plugin/) | A toolkit that supports the verification of videos and images. | free | 381 | [Irfanview](http://irfanview.com/) | Windows-based software to extract metadata. | free | 382 | [metadata2go](https://www.metadata2go.com/) | Check metadata for both photos and videos online. | free | 383 | [PureRef](https://www.pureref.com/index.php) | Image workspace; lets you arrange images in groups, organize them, etc. | free | 384 385 ## Pitfalls 386 387 - **Metadata is trivially forged.** `exiftool` writes as easily as it reads. Metadata that supports 388 a claim is weak evidence; metadata that contradicts one is a lead. 389 - **Platform stripping destroys the evidence** you want. Always ask for the original file. 390 - **Clock error is normal.** Do not build a timeline on an unverified camera timestamp. 391 - **Facial recognition on found images** raises real risk of misidentifying someone. Corroborate 392 before acting, and consider whether identification is necessary at all. 393 394 ## Worked example 395 396 A 40-second clip arrives by Telegram, captioned as filmed that morning on a phone at a named 397 street corner. 398 399 ```bash 400 # 1. hash first, work on a copy 401 shasum -a 256 clip.mp4 402 # 9f2c...e41b — recorded with "received 2026-03-12 09:14 UTC from <source>" 403 404 # 2. metadata: no EXIF, no GPS, one QuickTime atom 405 exiftool -a -G1 -s -ee clip.mp4 | grep -iE 'software|encoder|create|model' 406 # [QuickTime] CreateDate : 2026:03:11 22:41:08 407 # [QuickTime] Encoder : Lavf60.16.100 408 ``` 409 410 `Lavf` is ffmpeg's muxer, not a phone. The clip was written by a desktop or server-side tool, so 411 whatever it shows, this file is not the camera original — and `CreateDate` is the evening *before* 412 the claimed morning. 413 414 ```bash 415 # 3. container inventory: does the shape match a phone capture 416 ffprobe -v error -select_streams v -show_entries \ 417 stream=codec_name,codec_tag_string,pix_fmt,r_frame_rate,avg_frame_rate,nb_frames \ 418 -of default=nw=1 clip.mp4 419 # codec_name=h264 codec_tag_string=avc1 pix_fmt=yuv420p 420 # r_frame_rate=30/1 avg_frame_rate=2997/100 nb_frames=1198 421 ``` 422 423 Constant 30 declared, 29.97 actual — a broadcast-standard rate a phone does not record. Two 424 independent signals now say re-encoded. 425 426 ```bash 427 # 4. find the cuts, because the caption says one continuous take 428 ffmpeg -i clip.mp4 -vf "select='gt(scene,0.4)',metadata=print:file=scenes.txt" -f null - 429 # 3 scene changes at 11.2s, 24.6s, 31.0s 430 431 # 5. pull the frame with the readable shopfront 432 ffmpeg -ss 00:00:26 -i clip.mp4 -frames:v 1 -q:v 2 frame26.jpg 433 ``` 434 435 Three cuts in a clip described as one take is the finding; the frame is the pivot. Reverse image 436 search on `frame26.jpg` ([see reverse image search](/sheets/osint/reverse-image-search)) returns 437 the same shopfront in a news photo dated fourteen months earlier, and 438 [geolocation](/sheets/osint/geolocation) puts the corner two streets from the one named. Shadow 439 direction in the frame is consistent with late afternoon, not morning. 440 441 What you can assert: the file was produced by ffmpeg, contains at least three edits, is at 442 least fourteen months old in part, and shows a different corner than claimed — each tied to a named 443 command, its output, and the hash `9f2c...e41b`. What you cannot say from the file alone is who 444 assembled it or why. That needs the second independent source: the earlier news photo, which is 445 what actually carries the date. 446 447 What would falsify it: the earlier image proving to be a later backdated copy, the scene-change 448 threshold firing on flashes rather than edits, or the analysed hash not matching the preserved 449 file. The fourteen-month bound rests on the independently dated earlier image; the ffmpeg encoder 450 and frame-rate evidence establish re-encoding, not the age of the depicted footage. 451 452 ## Broader catalogues 453 454 - [Image and Video Analysis OSINT](https://tools.osintnewsletter.com/tool-categories/image-and-video-analysis-osint) 455 456 457 ## More tools 458 459 Further tools for this area from the OSINT Newsletter Tools Library ([Image and Video Analysis OSINT](https://tools.osintnewsletter.com/tool-categories/image-and-video-analysis-osint)), excluding those already listed above. 460 461 | Tool | What it does | 462 | --- | --- | 463 | [Crowd Counter](https://digitaldigging.org/crowdchecker/) | Estimates crowd sizes from images. | 464 | [Deepware](https://deepware.ai/) | An AI-powered deepfake detection platform that analyses video and audio content for signs of AI-generated or manipulated media. | 465 | [Filmot](https://www.reddit.com/r/languagelearning/comments/odj2gx/ive_built_a_search_engine_across_youtube_captions/) | A search engine that lets you search through YouTube video subtitles and metadata to find videos that contain specific words or… | 466 | [Google Lens](https://lens.google/) | Identify objects or locations that are visible in an image. | 467 | [Hippie OSINT Toolkit](https://osint.hippie.cat/) | An OSINT web toolkit that allows you to reverse search a domain, a TikTok post, an image, or username (and more). | 468 | [Human or AI](https://humanizeai.com/human-or-ai/) | A game-style OSINT training tool that challenges you to spot the difference between real human profile photos and AI-generated… | 469 | [Image Whisperer](https://imagewhisperer.org/) | A fast, browser-based media verification tool that helps you detect AI-generated images, analyse visual anomalies, and assess… | 470 | [ImgOps](https://imgops.com/) | A free image investigation hub that provides quick access to multiple reverse image search engines and image analysis tools from… | 471 | [MW Metadata](https://mattw.io/youtube-metadata/) | A free web-based OSINT utility that extracts publicly available metadata from YouTube videos. | 472 | [Oceanir](https://oceanir.ai/) | Helps verify where images and video frames may have been captured when EXIF/GPS data is missing. | 473 | [OSINT Industries](https://app.osint.industries/) | An all-encompassing OSINT platform that gathers and correlates publicly available digital data such as emails, domains, phone… | 474 | [Pic Detective](https://picdetective.com/) | Reverse Image Search | 475 | [Profile Image Intel](https://profileimageintel.com/) | A reverse image search tool helping you find where a profile picture appears online and uncover linked accounts or identities. | 476 | [Reverse Image Location (GeoSolver)](https://reverseimagelocation.com/) | AI-assisted image geolocation tool that helps estimate where a photo was taken by reasoning from visible scene clues and map… | 477 | [TinEye](https://tineye.com/) | A reverse image search engine that helps you find where an image appears online, track its origin, and detect edits or reuse. | 478 479 ## Sources 480 481 Both catalogues below are maintained by other people and are considerably larger than 482 this page. Use them as the canonical index; this sheet is a working route through them. 483 484 - [Bellingcat's Online Investigation Toolkit](https://bellingcat.gitbook.io/toolkit) — ~340 tools, each with its own 485 review page covering cost, difficulty, requirements and limitations. 486 - [OSINT Newsletter Tools Library](https://tools.osintnewsletter.com) — ~280 tools, organised by investigative goal. 487 488 Neither publishes a licence, so nothing here is copied from them: tool names, one-line 489 descriptions, cost flags and links are catalogue facts, and the method and commentary are 490 this site's own. See [credits](/credits).