SecurCheckCyber Centre

IMAGE · EXIF · C2PA

How to analyse a manipulated image or photo: a forensics guide

Secur Cloud ·

False payment confirmations, altered identity documents and edited contracts can mislead approval processes for businesses and individuals. Editing and generative AI tools make visual inspection alone insufficient in many cases.

An image manipulation analyser helps identify technical inconsistencies. Learn how to examine clues, understand their limits and cross-check before trusting an image.

1. Review metadata and provenance

  1. Interpret EXIF cautiously

    Depending on format and export, an image may contain a device model, dates, capture settings, software information or GPS location. Fields can be missing, edited or inconsistent because of an incorrect clock. A Photoshop marker suggests possible processing, not necessarily fraud. Compare metadata with the claimed context and original file.

  2. Distinguish signed provenance from truthful content

    C2PA can bind a file to signed provenance assertions. Validation requires checking the signature, binding to the file and signer trust. This does not prove that the depicted scene is true. Metadata can be removed or lost. SecurCheck identifies C2PA/JUMBF markers but does not validate their cryptographic signature chain.

2. Examine compression, pixels and noise

  1. Understand ELA and its limits

    Error Level Analysis compares an image, generally JPEG, with a recompressed version to visualise differences. Detail, edges, textures and resaving can create legitimate differences. A bright region does not prove splicing; a uniform map does not guarantee an original. Do not confuse this method with the module’s compression-discontinuity measurements.

  2. Cross-check texture and noise anomalies

    SecurCheck measures noise, textures, gradients and certain compression discontinuities. Lighting, smartphone denoising and repeated exports can create anomalies similar to editing. Noise is not uniformly distributed in every photo; these measurements do not identify a camera sensor through a PRNU fingerprint.

  3. Also review the visual context

    Distorted text, unusual shadows or perspectives can warrant further human review. None alone proves AI generation. The module does not perform complete automated scene understanding or specialised anatomical detection: unavailable checks must remain separate from measurements actually performed.

3. Verify context before approving a document

  1. Do not conclude from missing metadata

    Messaging services, social networks, exports or screenshots can strip EXIF and provenance information. Missing data is not evidence of forgery. Request the original when useful and consistent with your confidentiality rules.

  2. Cross-check with reverse image search

    Reverse image search may reveal an earlier publication or different context. Verify matches; no match does not prove originality. Do not submit identity documents or confidential material to a public search service without authorisation and reviewing its processing terms.

  3. Request a complete original and confirm the issuer

    Prefer a complete source file over a cropped or heavily compressed screenshot. A native PDF remains editable and does not certify authenticity; neither does a high-resolution photograph. For HR, financial or KYC decisions, confirm the document with its issuer through an independent channel and follow your approval process. Preserve the original unchanged for examination.

Conclusion: assess visual evidence methodically

Image forensics is useful when technical clues are linked to a verifiable source and context. Do not turn a score into a verdict. If doubts remain, pause approval, preserve the file and seek independent confirmation or specialist examination.

Deploy SecurCheck Business to support your compliance teams

Provenance and additional checks