daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

image-video-forensics.md (27972B)


      1 ---
      2 title: "Image & Video Forensics"
      3 description: "Read a file's metadata, test it for manipulation, and work out what the camera and encoder can tell you."
      4 category: osint
      5 subcategory: "Images & Video"
      6 tags: [osint, forensics, metadata, exif, verification]
      7 tools: [exiftool, ffprobe, ffmpeg, mediainfo, fotoforensics, forensically, invid]
      8 difficulty: intermediate
      9 updated: 2026-10-03
     10 references:
     11   - name: "Bellingcat's Online Investigation Toolkit"
     12     url: "https://bellingcat.gitbook.io/toolkit"
     13     author: "Bellingcat"
     14     license: none
     15     relation: derived
     16     note: "Tool catalogue: names, descriptions, cost flags and links for this area."
     17   - name: "OSINT Newsletter Tools Library"
     18     url: "https://tools.osintnewsletter.com"
     19     author: "The OSINT Newsletter"
     20     license: none
     21     relation: derived
     22     note: "Second tool catalogue, cross-checked against the above."
     23 ---
     24 
     25 ## What this covers
     26 
     27 What the file itself says, as distinct from what its caption says. Metadata gives you camera, time
     28 and sometimes location; container and encoder artefacts tell you the processing history;
     29 manipulation analysis suggests where to look harder. None of it is proof on its own, and all of it
     30 is easy to over-read.
     31 
     32 ## Method
     33 
     34 1. **Hash the file before you touch it.** `shasum -a 256 evidence.jpg`, recorded with the time you
     35    received it and who from. Every later claim you make is about that hash. Work on a copy.
     36 2. **Ask for the original.** Every major platform re-encodes and strips metadata on upload, so a
     37    file pulled from a timeline has already lost most of what you want. The original off the camera
     38    or phone is a different artefact from the one in the post.
     39 3. **Read metadata before anything else**, because it is cheap and it either corroborates the claim
     40    or contradicts it. A contradiction is a lead; agreement is weak evidence, since metadata is
     41    trivially written.
     42 4. **Inventory the container separately from the codec.** The file extension, the container brand
     43    and the codec inside it are three independent facts, and a mismatch between them means a tool
     44    touched the file after capture.
     45 5. **Only then run manipulation analysis.** Error Level Analysis and noise residual tell you where
     46    to look, not what happened. Decide in advance what result would change your conclusion;
     47    otherwise you will find whatever you went looking for.
     48 6. **Corroborate outside the file.** The defensible finding is the one that survives a second,
     49    independent source — a different upload of the same footage, a shadow angle consistent with the
     50    claimed time, a satellite pass over the claimed place. The file alone almost never settles it.
     51 7. **Record what you ran.** Keep the exact command, its full output and the tool version alongside
     52    the hash. "exiftool showed no GPS" is not reproducible; a saved JSON dump with a version string
     53    is.
     54 
     55 ## Key tools
     56 
     57 ### ExifTool
     58 
     59 The reference metadata reader and writer, and the only one worth learning properly. It parses more
     60 tag families than anything else — EXIF, XMP, IPTC, ICC, maker notes, QuickTime atoms, PDF and
     61 RIFF — and it tells you which family each tag came from, which matters because the same logical
     62 field appears in several places and they disagree when a file has been edited.
     63 
     64 ```bash
     65 brew install exiftool          # or: apt install libimage-exiftool-perl
     66 ```
     67 
     68 ```bash
     69 # everything, grouped and labelled by the tag family it came from
     70 exiftool -a -G1 -s image.jpg
     71 
     72 # the fields that usually decide a question, in one line
     73 exiftool -Make -Model -DateTimeOriginal -CreateDate -ModifyDate \
     74          -GPSLatitude -GPSLongitude -Software -Orientation image.jpg
     75 
     76 # every timestamp in the file at once: camera, GPS, filesystem, XMP
     77 exiftool -time:all -a -G1 -s image.jpg
     78 
     79 # GPS as a decimal pair you can paste straight into a map
     80 exiftool -n -p '$GPSLatitude,$GPSLongitude' image.jpg
     81 
     82 # maker notes and undecoded tags — where lens, shutter count and burst IDs hide
     83 exiftool -U -a -G1 image.jpg
     84 
     85 # structural sanity check: does the file match its own format spec
     86 exiftool -validate -warning -a image.jpg
     87 
     88 # the full set as JSON, which is what you archive next to the hash
     89 exiftool -j -g1 -a image.jpg > image.exif.json
     90 
     91 # a whole directory into one CSV, so you can sort a set by camera and time
     92 exiftool -r -csv -Make -Model -SerialNumber -DateTimeOriginal -GPSPosition ./images/ > meta.csv
     93 
     94 # embedded metadata in video streams, not just the container header
     95 exiftool -ee -G3 -a clip.mp4
     96 
     97 # strip everything before you publish, to protect a source
     98 exiftool -all= -overwrite_original copy.jpg
     99 ```
    100 
    101 Reading the output: `Make`/`Model` should match the claimed device, and a `SerialNumber` that
    102 recurs across a set ties those files to one body. `Software` naming an editor means the file was
    103 processed — not that it was faked, but that this is not the original. `DateTimeOriginal` is capture
    104 time from the camera clock, which carries no timezone and is routinely wrong by hours or years;
    105 `CreateDate` and `ModifyDate` can be later. `-validate` flagging a truncated or non-conforming
    106 structure is a genuine signal that something rewrote the file.
    107 
    108 Missing metadata is the normal case, not a red flag — platform stripping accounts for almost all of
    109 it. The reverse error is worse: metadata that supports a convenient claim proves very little,
    110 because `exiftool` writes as easily as it reads, and a forged `DateTimeOriginal` takes one command.
    111 Treat supporting metadata as consistent-with, and contradicting metadata as a thread to pull.
    112 
    113 ### ffprobe
    114 
    115 Stream and container inventory for video and audio. Use it to establish what the file actually is
    116 before you argue about what it shows: how many streams, which codec, what container brand, whether
    117 the frame rate is constant, and where the keyframes fall.
    118 
    119 ```bash
    120 brew install ffmpeg            # ffprobe ships with ffmpeg
    121 ```
    122 
    123 ```bash
    124 # full container and stream dump, archived next to the hash
    125 ffprobe -v error -print_format json -show_format -show_streams video.mp4 > video.probe.json
    126 
    127 # the container's own identity: brand, duration, and who wrote it
    128 ffprobe -v error -show_entries format=format_name,format_long_name,duration:format_tags \
    129         -of default=nw=1 video.mp4
    130 
    131 # codec vs container in one view — mismatches start here
    132 ffprobe -v error -select_streams v -show_entries \
    133         stream=codec_name,codec_tag_string,profile,level,pix_fmt,width,height,r_frame_rate,avg_frame_rate,nb_frames \
    134         -of default=nw=1 video.mp4
    135 
    136 # encoder string and creation time, which usually name the producing app
    137 ffprobe -v error -show_entries format_tags=creation_time,encoder,com.apple.quicktime.software \
    138         -of default=nw=1 video.mp4
    139 
    140 # frame types and timestamps: is the cadence constant, where are the I-frames
    141 ffprobe -v error -select_streams v -show_entries frame=pts_time,pict_type \
    142         -of csv=p=0 video.mp4 | head -50
    143 
    144 # keyframe interval from the packet layer, cheaper than decoding frames
    145 ffprobe -v error -select_streams v -show_entries packet=pts_time,flags,size \
    146         -of csv=p=0 video.mp4 | awk -F, '$2 ~ /K/ {print $1}' | head -20
    147 
    148 # is there a second audio track, a timecode track, or stray metadata streams
    149 ffprobe -v error -show_entries stream=index,codec_type,codec_name -of csv=p=0 video.mp4
    150 ```
    151 
    152 Note that `pkt_pts_time` was removed in ffmpeg 5 — on any current build the entry is `pts_time`,
    153 and an old recipe using the former silently returns an empty column rather than erroring.
    154 
    155 **Container-versus-codec mismatch is the single most useful manipulation signal in video.** A file
    156 named `.mp4` whose `format_name` is `matroska`, an iPhone clip whose major brand is not `qt`/`mp4`,
    157 H.264 in a container the capturing device never writes, or a `creation_time` later than the claimed
    158 upload — each means something re-muxed or re-encoded the file. Encoder strings are a strong
    159 fingerprint of the producing application: a clip claimed to be straight off a phone but carrying a
    160 desktop editor's encoder has been through an edit, and that is a finding you can state plainly.
    161 Variable frame rate where the device records constant, or an `nb_frames` that does not match
    162 duration times frame rate, points the same way.
    163 
    164 What this does not tell you: nothing in the stream inventory distinguishes an innocent re-encode —
    165 a messaging app, a download wrapper, a format conversion for upload — from a deliberate edit. It
    166 tells you the file is not the original, and that you should be arguing about provenance rather than
    167 about pixels.
    168 
    169 ### ffmpeg
    170 
    171 Extraction, not analysis. Use it to pull the frames you will actually look at, and to cut the
    172 segment you will cite, without silently re-encoding what you cite.
    173 
    174 ```bash
    175 # every keyframe, decoded fast because P- and B-frames are skipped entirely
    176 ffmpeg -skip_frame nokey -i video.mp4 -fps_mode vfr keyframes/kf_%04d.png
    177 
    178 # frames at scene changes: 0.3-0.5 is the useful threshold range
    179 ffmpeg -i video.mp4 -vf "select='gt(scene,0.4)',showinfo" -fps_mode vfr scenes/sc_%04d.png
    180 
    181 # a contact sheet of keyframes, for finding the shot you need
    182 ffmpeg -skip_frame nokey -i video.mp4 -vf "scale=240:-1,tile=5x4" -frames:v 1 sheet.jpg
    183 
    184 # the exact frame at a timestamp, for a geolocation attempt
    185 ffmpeg -ss 00:01:37.500 -i video.mp4 -frames:v 1 -q:v 2 frame.jpg
    186 
    187 # cut a clip without re-encoding, so the excerpt keeps the original stream
    188 ffmpeg -ss 00:01:30 -to 00:01:50 -i video.mp4 -c copy excerpt.mp4
    189 
    190 # extract the audio untouched — background sound often dates or places a clip
    191 ffmpeg -i video.mp4 -vn -c:a copy audio.m4a
    192 
    193 # log scene-change scores to a file instead of writing frames, to find the cut points
    194 ffmpeg -i video.mp4 -vf "select='gt(scene,0.3)',metadata=print:file=scenes.txt" -f null -
    195 ```
    196 
    197 `-c copy` matters for anything you will publish or hand to someone else: re-encoding an excerpt
    198 destroys the compression history that any later analysis would use, and makes your excerpt
    199 unfalsifiable in the wrong direction. `-fps_mode vfr` replaced `-vsync vfr` in ffmpeg 5, and `-vsync`
    200 was removed outright in ffmpeg 9 — it now fails with `Unrecognized option 'vsync'`. Any older
    201 cheatsheet or Stack Overflow answer using it will not run.
    202 
    203 Scene-change detection finds cuts, and cuts in material claimed to be a single continuous recording
    204 are worth explaining. It also fires on pans, flashes and camera shake, so read the list as
    205 candidates.
    206 
    207 ### MediaInfo
    208 
    209 A second opinion on container structure, with a tag vocabulary closer to how broadcast and
    210 camera manufacturers name things. Worth running alongside `ffprobe` because it surfaces writing
    211 library, muxing application and per-track UUIDs that ffmpeg's inventory does not break out.
    212 
    213 ```bash
    214 brew install mediainfo         # or: apt install mediainfo
    215 ```
    216 
    217 ```bash
    218 # human-readable, every track
    219 mediainfo video.mp4
    220 
    221 # full detail including container atoms and writing library
    222 mediainfo --Full video.mp4
    223 
    224 # machine-readable, for archiving next to the hash
    225 mediainfo --Output=JSON video.mp4 > video.mediainfo.json
    226 
    227 # just the fields that identify the producing tool
    228 mediainfo --Inform="General;%Format%|%Encoded_Application%|%Encoded_Library%|%Encoded_Date%" video.mp4
    229 
    230 # batch a directory and diff the writing libraries across a set
    231 mediainfo --Output=CSV ./clips/ > clips.csv
    232 ```
    233 
    234 Where `ffprobe` and `mediainfo` disagree about the container, that disagreement is itself
    235 informative: it usually means the file is malformed or was written by something that does not
    236 follow the spec.
    237 
    238 ### FotoForensics
    239 
    240 Web-only Error Level Analysis, JPEG quality estimation and metadata, run on an upload. The useful
    241 part is not the ELA image, it is the combination of the quality estimate and the metadata panel on
    242 the same screen.
    243 
    244 What you do: paste a URL or upload the file at [fotoforensics.com](https://fotoforensics.com/).
    245 Read the panels in this order.
    246 
    247 ```text
    248 1. Metadata        confirm it matches what exiftool told you; if it differs, the
    249                    upload was re-encoded in transit and the analysis is of the wrong file
    250 2. JPEG Quality    a quality estimate well below the camera's normal output means
    251                    at least one re-save; "last saved at ~75%" is a provenance fact
    252 3. ELA             uniform noise across a single-source photo is the expected result;
    253                    look for a region whose edge brightness differs sharply from
    254                    identically-textured regions elsewhere in the same frame
    255 4. Hidden Pixels   cropped-out image data still present in the file
    256 ```
    257 
    258 Capture for the record: the analysis URL, a screenshot of each panel, and the quality estimate as a
    259 number. The URL alone is not enough, because the site's analysis can change.
    260 
    261 **This site publicly retains uploads.** Anything you submit becomes part of a public corpus. Do not
    262 put a source's photograph, an unpublished image or anything identifying a person at risk into it —
    263 use Forensically instead, which runs locally in the browser.
    264 
    265 **ELA is the most over-interpreted technique in this field.** Differing compression across regions
    266 has mundane causes: resizing, text overlay, a logo burned in, successive saves, a screenshot of a
    267 screenshot. ELA tells you where to look harder. It never tells you a region was pasted in, and an
    268 ELA image with arrows drawn on it is not a finding.
    269 
    270 ### Forensically
    271 
    272 The same family of analyses, running entirely client-side in your browser, so the file never leaves
    273 your machine. That makes it the right default for sensitive material, and it adds clone detection
    274 and a noise view that FotoForensics does not.
    275 
    276 Open [29a.ch/photo-forensics](https://29a.ch/photo-forensics/) and drop the file in. The panels
    277 worth your time:
    278 
    279 ```text
    280 Clone Detection    finds regions similar to other regions in the same image; raise the
    281                    threshold until repetitive texture (foliage, gravel, sky) stops matching
    282                    itself, then look at what still matches
    283 Noise Analysis     a pasted region often carries a different sensor noise floor; flat or
    284                    smoothed patches in an otherwise noisy frame are the signal
    285 Level Sweep        sweeps the brightness range to expose banding and edges hidden in
    286                    shadow or blown highlights
    287 Luminance Gradient surfaces inconsistent lighting direction across objects that should
    288                    share one light source
    289 Magnifier          pixel-level inspection for resampling edges around inserted text
    290 ```
    291 
    292 Shut the browser tab when you are done and nothing has been transmitted. Noise analysis degrades
    293 badly on anything heavily compressed or resized, which is most images sourced from social media —
    294 if the file has been through a platform, expect all of these panels to be inconclusive and say so
    295 rather than straining to read them.
    296 
    297 ### InVID / WeVerify plugin
    298 
    299 A browser extension that bundles the video-specific steps: keyframe extraction from a platform URL
    300 without downloading the file yourself, reverse image search of those keyframes across several
    301 engines in one click, a Twitter/X timeline search by time window, and a magnifier.
    302 
    303 Install from [weverify.eu/verification-plugin](https://weverify.eu/verification-plugin/). It is
    304 maintained as part of an EU research project, so expect individual platform integrations to break
    305 when those platforms change their markup; the keyframe and reverse-search functions are the durable
    306 parts. Use it for triage, then come back to `ffmpeg` and `exiftool` for anything you intend to
    307 publish, because the plugin does not give you a reproducible command or a hash.
    308 
    309 ### Hashing and the record
    310 
    311 The thing that makes a forensic finding defensible is not the analysis, it is the chain from the
    312 file you were given to the file you analysed.
    313 
    314 ```bash
    315 # the hash you cite, computed before any processing
    316 shasum -a 256 evidence.mp4 | tee evidence.sha256
    317 
    318 # hash a whole set, so a later re-download can be compared
    319 find ./evidence -type f -exec shasum -a 256 {} \; > manifest.sha256
    320 
    321 # verify nothing drifted while you worked
    322 shasum -a 256 -c manifest.sha256
    323 
    324 # perceptual hash, for matching re-encodes of the same footage across platforms
    325 ffmpeg -i a.mp4 -i b.mp4 -filter_complex "signature=nb_inputs=2:detectmode=full" -f null -
    326 ```
    327 
    328 Record alongside the hash: where the file came from and when, the archive copy
    329 ([see archiving and evidence](/sheets/osint/archiving-and-evidence)), the tool versions, and the
    330 exact commands with their output. A cryptographic hash and a perceptual hash answer different
    331 questions — the first proves you analysed the file you were given, the second lets you say two
    332 differently-encoded uploads are the same recording.
    333 
    334 ### Further viewers and one-pass analysers
    335 
    336 The long tail, useful when you want a second opinion or have no shell to hand.
    337 
    338 | Tool | What it does |
    339 | --- | --- |
    340 | [Reveal Image Verification Assistant](https://mever.iti.gr/forensics/) | Runs several forensic filters in one pass and produces a report, which saves time on triage; the filters are the same family as Forensically's, so treat agreement between them as one result, not two. |
    341 | [Jimpl](https://jimpl.com/) | Browser EXIF and GPS viewer with a map pin. Quick, and fine for a file you do not mind uploading. |
    342 | [xIFr](https://xifr.eu/) | Detailed EXIF viewer that decodes maker notes, which is the one thing a casual viewer usually drops. |
    343 | [metadata2go](https://www.metadata2go.com/) | Metadata for both images and video in a browser, when you cannot install anything. |
    344 | [DeepFake-O-Meter](https://zinc.cse.buffalo.edu/ubmdfl/deep-o-meter/) | Academic ensemble of synthetic-media detectors. Reports a score, not a verdict, and false positives on compressed footage are common — never cite it alone. |
    345 
    346 Any of these that works by upload has the same exposure problem as FotoForensics: assume the file
    347 is retained. For sensitive material the only safe tools are the local ones.
    348 
    349 ## Facial recognition
    350 
    351 Searching a face across the web, rather than searching an image. Treat this as a
    352 different category of act from reverse image search: it identifies a person, the error
    353 rate is not zero, and a false match aimed at the wrong human causes real harm. Several
    354 of these are barred or restricted in some jurisdictions, and uploading someone's face
    355 to a commercial service hands that service biometric data about them.
    356 
    357 Use it to *corroborate* an identity you already have reason to suspect, not to generate
    358 one from nothing, and never treat a match as confirmation on its own.
    359 
    360 | Tool | What it does | Cost |
    361 | --- | --- | --- |
    362 | [Amazon Rekognition](https://aws.amazon.com/rekognition/) | Check how similar two faces are | free |
    363 | [Azure AI Video Indexer](https://vi.microsoft.com/en-us) | AI video tool for facial detection and other types of insights. | paid |
    364 | [Face Comparison by ToolPie](https://facecomparison.toolpie.com/) | Compares two human face photos to determine similarity. | free |
    365 | [FaceCheck.ID](https://facecheck.id/) | A facial recognition search engine that tries to find photos of people that look similar to a person of interest. | paid |
    366 | [PimEyes](https://pimeyes.com/en) | An AI-powered facial recognition reverse image search tool. | paid |
    367 | [Search4Faces](https://search4faces.com) | Upload the picture of a face and find pictures of similar looking people on VKontakte, Odnoklassniki, TikTok and Clubhouse. | free |
    368 
    369 ## Tool reference
    370 
    371 | Tool | What it does | Cost |
    372 | --- | --- | --- |
    373 | [Am I Real?](https://seintpl.github.io/AmIReal/) | A simple online tool that allows users to check whether a photo might have been generated by ThisPersonDoesNotExist.com. | free |
    374 | [AutoStitch](https://mattabrown.github.io/autostitch.html) | Autostitch is a free tool for seamlessly combining multiple photos into a single panoramic image, making it ideal for creating wide-angle photography… | free |
    375 | [Cleanup.Pictures](https://cleanup.pictures/) | Web tool for quickly removing objects from an image. | free |
    376 | [DeepFake-O-Meter](https://zinc.cse.buffalo.edu/ubmdfl/deep-o-meter/) | DeepFake-O-Meter is an online tool designed to detect deepfake media and help users differentiate between genuine and manipulated content. | free |
    377 | [ExifPurge](http://www.exifpurge.com/) | EXIF Purge is a small portable application to remove EXIF metadata from multiple images at once. With the click of a button you can remove the camera… | free |
    378 | [fdupes](https://github.com/adrianlopezroche/fdupes) | Github - Locating exact matches of duplicate files. | free |
    379 | [Hugin](https://hugin.sourceforge.io/) | Hugin is a free and open-source panorama photo stitching and HDR (High Dynamic Range imaging) merging software that helps users create seamless panoramic… | free |
    380 | [InVID](https://weverify.eu/verification-plugin/) | A toolkit that supports the verification of videos and images. | free |
    381 | [Irfanview](http://irfanview.com/) | Windows-based software to extract metadata. | free |
    382 | [metadata2go](https://www.metadata2go.com/) | Check metadata for both photos and videos online. | free |
    383 | [PureRef](https://www.pureref.com/index.php) | Image workspace; lets you arrange images in groups, organize them, etc. | free |
    384 
    385 ## Pitfalls
    386 
    387 - **Metadata is trivially forged.** `exiftool` writes as easily as it reads. Metadata that supports
    388   a claim is weak evidence; metadata that contradicts one is a lead.
    389 - **Platform stripping destroys the evidence** you want. Always ask for the original file.
    390 - **Clock error is normal.** Do not build a timeline on an unverified camera timestamp.
    391 - **Facial recognition on found images** raises real risk of misidentifying someone. Corroborate
    392   before acting, and consider whether identification is necessary at all.
    393 
    394 ## Worked example
    395 
    396 A 40-second clip arrives by Telegram, captioned as filmed that morning on a phone at a named
    397 street corner.
    398 
    399 ```bash
    400 # 1. hash first, work on a copy
    401 shasum -a 256 clip.mp4
    402 # 9f2c...e41b  — recorded with "received 2026-03-12 09:14 UTC from <source>"
    403 
    404 # 2. metadata: no EXIF, no GPS, one QuickTime atom
    405 exiftool -a -G1 -s -ee clip.mp4 | grep -iE 'software|encoder|create|model'
    406 # [QuickTime] CreateDate : 2026:03:11 22:41:08
    407 # [QuickTime] Encoder    : Lavf60.16.100
    408 ```
    409 
    410 `Lavf` is ffmpeg's muxer, not a phone. The clip was written by a desktop or server-side tool, so
    411 whatever it shows, this file is not the camera original — and `CreateDate` is the evening *before*
    412 the claimed morning.
    413 
    414 ```bash
    415 # 3. container inventory: does the shape match a phone capture
    416 ffprobe -v error -select_streams v -show_entries \
    417   stream=codec_name,codec_tag_string,pix_fmt,r_frame_rate,avg_frame_rate,nb_frames \
    418   -of default=nw=1 clip.mp4
    419 # codec_name=h264  codec_tag_string=avc1  pix_fmt=yuv420p
    420 # r_frame_rate=30/1  avg_frame_rate=2997/100  nb_frames=1198
    421 ```
    422 
    423 Constant 30 declared, 29.97 actual — a broadcast-standard rate a phone does not record. Two
    424 independent signals now say re-encoded.
    425 
    426 ```bash
    427 # 4. find the cuts, because the caption says one continuous take
    428 ffmpeg -i clip.mp4 -vf "select='gt(scene,0.4)',metadata=print:file=scenes.txt" -f null -
    429 # 3 scene changes at 11.2s, 24.6s, 31.0s
    430 
    431 # 5. pull the frame with the readable shopfront
    432 ffmpeg -ss 00:00:26 -i clip.mp4 -frames:v 1 -q:v 2 frame26.jpg
    433 ```
    434 
    435 Three cuts in a clip described as one take is the finding; the frame is the pivot. Reverse image
    436 search on `frame26.jpg` ([see reverse image search](/sheets/osint/reverse-image-search)) returns
    437 the same shopfront in a news photo dated fourteen months earlier, and
    438 [geolocation](/sheets/osint/geolocation) puts the corner two streets from the one named. Shadow
    439 direction in the frame is consistent with late afternoon, not morning.
    440 
    441 What you can assert: the file was produced by ffmpeg, contains at least three edits, is at
    442 least fourteen months old in part, and shows a different corner than claimed — each tied to a named
    443 command, its output, and the hash `9f2c...e41b`. What you cannot say from the file alone is who
    444 assembled it or why. That needs the second independent source: the earlier news photo, which is
    445 what actually carries the date.
    446 
    447 What would falsify it: the earlier image proving to be a later backdated copy, the scene-change
    448 threshold firing on flashes rather than edits, or the analysed hash not matching the preserved
    449 file. The fourteen-month bound rests on the independently dated earlier image; the ffmpeg encoder
    450 and frame-rate evidence establish re-encoding, not the age of the depicted footage.
    451 
    452 ## Broader catalogues
    453 
    454 - [Image and Video Analysis OSINT](https://tools.osintnewsletter.com/tool-categories/image-and-video-analysis-osint)
    455 
    456 
    457 ## More tools
    458 
    459 Further tools for this area from the OSINT Newsletter Tools Library ([Image and Video Analysis OSINT](https://tools.osintnewsletter.com/tool-categories/image-and-video-analysis-osint)), excluding those already listed above.
    460 
    461 | Tool | What it does |
    462 | --- | --- |
    463 | [Crowd Counter](https://digitaldigging.org/crowdchecker/) | Estimates crowd sizes from images. |
    464 | [Deepware](https://deepware.ai/) | An AI-powered deepfake detection platform that analyses video and audio content for signs of AI-generated or manipulated media. |
    465 | [Filmot](https://www.reddit.com/r/languagelearning/comments/odj2gx/ive_built_a_search_engine_across_youtube_captions/) | A search engine that lets you search through YouTube video subtitles and metadata to find videos that contain specific words or… |
    466 | [Google Lens](https://lens.google/) | Identify objects or locations that are visible in an image. |
    467 | [Hippie OSINT Toolkit](https://osint.hippie.cat/) | An OSINT web toolkit that allows you to reverse search a domain, a TikTok post, an image, or username (and more). |
    468 | [Human or AI](https://humanizeai.com/human-or-ai/) | A game-style OSINT training tool that challenges you to spot the difference between real human profile photos and AI-generated… |
    469 | [Image Whisperer](https://imagewhisperer.org/) | A fast, browser-based media verification tool that helps you detect AI-generated images, analyse visual anomalies, and assess… |
    470 | [ImgOps](https://imgops.com/) | A free image investigation hub that provides quick access to multiple reverse image search engines and image analysis tools from… |
    471 | [MW Metadata](https://mattw.io/youtube-metadata/) | A free web-based OSINT utility that extracts publicly available metadata from YouTube videos. |
    472 | [Oceanir](https://oceanir.ai/) | Helps verify where images and video frames may have been captured when EXIF/GPS data is missing. |
    473 | [OSINT Industries](https://app.osint.industries/) | An all-encompassing OSINT platform that gathers and correlates publicly available digital data such as emails, domains, phone… |
    474 | [Pic Detective](https://picdetective.com/) | Reverse Image Search |
    475 | [Profile Image Intel](https://profileimageintel.com/) | A reverse image search tool helping you find where a profile picture appears online and uncover linked accounts or identities. |
    476 | [Reverse Image Location (GeoSolver)](https://reverseimagelocation.com/) | AI-assisted image geolocation tool that helps estimate where a photo was taken by reasoning from visible scene clues and map… |
    477 | [TinEye](https://tineye.com/) | A reverse image search engine that helps you find where an image appears online, track its origin, and detect edits or reuse. |
    478 
    479 ## Sources
    480 
    481 Both catalogues below are maintained by other people and are considerably larger than
    482 this page. Use them as the canonical index; this sheet is a working route through them.
    483 
    484 - [Bellingcat's Online Investigation Toolkit](https://bellingcat.gitbook.io/toolkit) — ~340 tools, each with its own
    485   review page covering cost, difficulty, requirements and limitations.
    486 - [OSINT Newsletter Tools Library](https://tools.osintnewsletter.com) — ~280 tools, organised by investigative goal.
    487 
    488 Neither publishes a licence, so nothing here is copied from them: tool names, one-line
    489 descriptions, cost flags and links are catalogue facts, and the method and commentary are
    490 this site's own. See [credits](/credits).