Summary
Five tools come up in every "best photo forensics software" list. They are not interchangeable: two upload your image to a server, one needs its own server, one costs a quote-based licence, and only three run clone detection. The table below is built from each product's public documentation (checked 6 October 2026, re-checked and linked 9 October 2026; the sources are listed under the table); cells marked ◐ are partial. Corrections are welcome via the contact details.
Choose Max Intel Photo Forensics Studio when you need the broadest free, local method set with hashes, batch handling and a reproducible report. Choose Forensically for a quick single-image look with a magnifier and PCA. Choose FotoForensics when you specifically want its ELA rendering and JPEG % and do not mind uploading. Choose Ghiro if you must self-host a server for a team and can live with an unmaintained codebase. Choose Amped Authenticate when camera identification (PRNU), a quantization-table camera database and court-tested reporting justify a commercial licence.
Feature-by-feature comparison
| Capability | Max Intel Photo Forensics Studio | FotoForensics | Forensically | Ghiro | Amped Authenticate |
|---|---|---|---|---|---|
| Price / access | ✔ Free, no accountmaxintel.org/forensics.html | ✔ Free web serviceLab version is commercial | ✔ Free29a.ch/photo-forensics | ✔ Free, open sourceself-hosted server | ✖ Commercial, request prices |
| Where the image is processed | ✔ In your browser; nothing uploaded | ✖ Uploaded to the service; public uploads are kept and used for research | ✔ In your browser | ◐ On your own server | ✔ On your workstation |
| Error Level Analysis | ✔ Adjustable quality, edge-normalised block statistics, cluster verdict | ✔ Core feature | ✔ Adjustable quality/scale | ✔ | ✔ Plus many related filters |
| JPEG ghost / double compression | ✔ Sweep 40–100, own-quality exclusion, cluster map | ◐ JPEG % quality estimate | ◐ JPEG analysis (quantization tables) | ✖ | ✔ JPEG ghosts, DCT, quantization-table database (14k+ tables) |
| Copy-move / clone detection | ✔ Block matching with offset voting and coherence check | ✖ | ✔ Clone detection | ✖ | ✔ |
| Noise analysis | ✔ Noise floor on low-texture blocks, cluster verdict | ✖ | ✔ Noise analysis | ✖ | ✔ Several noise filters |
| Luminance gradient / level sweep | ✔ Gradient map | ✖ | ✔ Luminance gradient, level sweep, PCA | ✖ | ✔ |
| Bit planes / LSB statistics | ✔ LSB view + chi-square | ✖ | ✖ | ✖ | ✔ |
| EXIF thumbnail comparison | ✔ Correlation score | ✖ | ✔ Thumbnail analysis | ✔ Thumbnail consistency | ✔ |
| Metadata: EXIF / GPS / XMP / IPTC | ✔ All four, plus XMP edit history and digital-source-type | ✔ EXIF, IPTC, XMP | ✔ Metadata, geo tags | ✔ EXIF, IPTC, XMP, GPS map | ✔ |
| JPEG structure: quality, tables, markers, trailing data | ✔ Quality estimate, IJG check, subsampling, progressive, APP markers, bytes after EOI, embedded JPEG count | ◐ JPEG %, hidden pixels, strings | ◐ JPEG analysis, string extraction | ◐ Hashes, strings | ✔ Extensive, with camera database |
| C2PA / Content Credentials | ◐ Presence detected; verification via the C2PA hub | ✖ | ◐ Displays C2PA/JUMBF data (since April 2024); basic, no remote fetching | ✖ | ◐ Not stated on the public product page (checked 9 Oct 2026) |
| Camera identification (PRNU) | ✖ | ✖ | ✖ | ✖ | ✔ Core differentiator (PRNU identification, map, tampering) |
| File hashes (SHA-256 / SHA-1 / MD5) | ✔ Computed before decoding, printed on the report | ◐ Digest shown | ✖ | ✔ CRC32, MD5, SHA-1 to SHA-512 | ✔ |
| Batch / multiple exhibits | ✔ Queue any number, one report | ✖ One image at a time | ✖ One image at a time | ✔ Bulk upload, cases | ✔ Projects |
| Case / exhibit labelling | ✔ Case ID, exhibit prefix, examiner, notes | ✖ | ✖ | ✔ Cases | ✔ |
| Evidence report export | ✔ Printable PDF + JSON with parameters and verdicts | ✖ | ✖ | ✔ Per-image/case reports | ✔ Court-oriented reports |
| Plain-language verdict per method | ✔ no signal / weak / notable with the numbers | ✖ Visual output only | ✖ Visual output only | ◐ | ◐ Expert interpretation |
| RAW files | ◐ Metadata + embedded preview analysed | ✖ | ✖ | ✖ | ✔ |
| Works offline | ✔ After first load | ✖ | ✔ | ✔ Own server | ✔ |
| Maintained | ✔ v2.0.0, October 2026 | ✔ | ✔ | ✖ No release for yearslatest release 0.2.1 | ✔ |
✔ documented capability · ◐ partial · ✖ not offered. Max Intel entries describe engine 2.0.0 (methods & limitations).
Sources (all read 9 October 2026): FotoForensics — fotoforensics.com, FAQ (free for personal use, uploads kept at least three months and used for research, paid Lab version for commercial use) and tutorials (ELA, JPEG %, Metadata, Hidden Pixels, Strings, Digest). Forensically — 29a.ch/photo-forensics and its built-in help (tool list, "all of your images stay on your computer", offline use, C2PA tool added 12 April 2024). Ghiro — GitHub repository, releases and techniques documentation (hashes, EXIF/IPTC/XMP, GPS map, ELA, strings, thumbnail consistency, cases). Amped Authenticate — product page (PRNU tools, JPEG quantization-table database of more than 14k tables, JPEG ghosts, DCT, clones, ELA, noise map, RAW support, batch processing, report, training and support; pricing on request).
Where Max Intel is weaker
- No PRNU camera identification. Linking a photo to a specific camera body by its sensor noise fingerprint needs reference images and heavy computation; Amped Authenticate does this and we do not.
- No quantization-table camera database. We estimate JPEG quality and check for IJG-standard tables, but we do not match tables against a library of camera and software signatures.
- Small pastes and misaligned grids. The ghost sweep needs a pasted region of roughly 200 px or more aligned to the 8×8 grid; most real-world pastes are smaller or misaligned, and then only ELA, noise and copy-move remain.
- RAW is preview-based. We read RAW metadata and analyse the embedded JPEG preview; we do not demosaic sensor data.
- C2PA is detected, not verified. Signature-chain validation needs the trust list; we point you to the verifier rather than pretend.
- No court-validation history. Our methods follow the published literature and are documented with parameters, but the tool has not been through a Daubert-style validation.
Where Max Intel is stronger
- Nothing leaves your device. FotoForensics uploads; Ghiro needs a server. For leaked documents, source protection and anything under legal hold, local processing is not a convenience, it is a requirement.
- Verdicts you can quote. Each method returns no signal / weak / notable with block counts and thresholds, instead of a picture you have to interpret by eye.
- A report a second examiner can reproduce. Hashes before decoding, every parameter, every result image and the full metadata in one printable or JSON document.
- Batch with labels. Queue an evidence folder, label exhibits, export once.
- Current. Versioned engine with a public changelog.
Other tools in this category
Also worth knowing, with one line each from their public descriptions: InVID-WeVerify is a browser plugin for verifying social-media media (keyframes, reverse search, a forensic-filter service) and complements rather than replaces a forensics studio. JPEGsnoop is a Windows utility that decodes JPEG internals and compares quantization tables against a signature database. Jeffrey's Image Metadata Viewer and ExifTool are metadata-first: unmatched for tag-level detail, no pixel analysis. Tungstène is a commercial French authentication suite used by news agencies. Adobe Photoshop can inspect and edit metadata but has no forgery-detection workflow. For a methodology walkthrough see the image forensics guide, and for video the video forensics software comparison.
Frequently Asked Questions
What is the best free photo forensics software?
For local, browser-based analysis with the broadest method set — ELA, JPEG ghost, clone detection, noise, bit planes, thumbnail comparison, full metadata, hashes and an evidence report — Max Intel Photo Forensics Studio covers the most ground without uploading your image. Forensically is a strong free alternative for single images; FotoForensics is free but processes images on its server.
Is FotoForensics or Forensically better?
They overlap on ELA and metadata. Forensically runs locally and adds clone detection, noise analysis, level sweep, PCA and thumbnail analysis; FotoForensics uploads the image and offers its ELA rendering, JPEG quality estimate, hidden pixels and strings. FotoForensics shows a file digest; neither batches exhibits or exports a report.
What does Amped Authenticate do that free tools cannot?
Camera identification by sensor noise (PRNU), a database of camera and software quantization tables, dozens of additional filters and court-oriented reporting, backed by training and support. It is commercial with quote-based pricing and is aimed at forensic laboratories.
Is Ghiro still maintained?
Ghiro is open source and designed for self-hosted, batch image analysis with hashing, metadata extraction, ELA and reports, but it has not seen a release for years. It still works for teams able to host and patch it themselves.
Does Max Intel upload my photos?
No. Hashing, analysis and report generation run in your browser, and the page works offline after it has loaded. That is the main architectural difference from FotoForensics.
Can any of these tools prove a photo is authentic?
No tool can. They detect traces of manipulation; a clean result means no trace was found with that method, not that the image is genuine. Recompression, resizing and generative models can leave no detectable trace, which is why provenance standards such as C2PA matter alongside pixel forensics.