Video Forensics Studio

By Ned Walsch · Last updated:

Free video forensics software, the counterpart to the Photo Forensics Studio. Load a clip and the studio hashes it, reads the container (encoder, timestamps, codecs, GPS, edit lists), runs temporal checks that only video makes possible (flicker, motion, frozen and duplicate frames) and per-frame spatial passes (ELA, noise, block grid) on any frame you pick, lets you export frames with hashes, and writes it all into a printable evidence report. Everything runs in your browser; the video is never uploaded. An optional on-device AI detector adds a second opinion.

How do I check whether a video has been edited or AI-generated? Start with the file itself: the container records which software wrote it, when, with what codecs and frame timing, and whether audio was stripped or the presentation re-timed — the studio reads MP4/MOV and WebM/Matroska metadata and flags re-encoders, generative-video services and inconsistencies. Then run the temporal checks (frame-to-frame difference, motion magnitude, luminance flicker, frozen or duplicate frames) over 24–96 sampled frames, and the per-frame passes — Error Level Analysis, noise residual and block grid — on the frames the charts single out. An optional AI detector runs on WebGPU when available. No single signal is proof; the report records every flag as a lead with the numbers behind it.

Load video
🎞️
Drop a video here, or click to browse
The file never leaves your device — it is analyzed entirely in this tab.
MP4 · WEBM · MOV · MKV — best results under ~2 min
✔ Free   ✔ No account   ✔ Nothing uploaded — analysed in this tab   ✔ Any length (sampling keeps it fast)
Exhibit details (optional — printed on the report)
What the analysis flagged

A quick read of the automated checks. Amber or red flags are reasons to look closer — not verdicts. Scroll down for the detail behind each.

No single clue is proof — triangulate. Real forensic work combines visual inspection, metadata, geometry, and several independent analyses, and trusts a conclusion only when they agree. Social-media compression erases many of these traces, and authentic footage can trip every filter here. Use this studio to find where to look and what to question, then corroborate. For anything with real stakes, bring in a qualified examiner.

Detection methods at a glance
MethodWhat it detectsHow it is computed hereKnown limits
Container & metadata auditRe-encoding, platform exports, generative-video services, stripped audio, trimming/re-timing, device and location claimsMP4/MOV boxes (ftyp, mvhd, tkhd, mdhd, hdlr, stsd, stts, stss, elst, udta/ilst, XMP uuid, C2PA) and Matroska EBML (Info, Tracks, Tags) parsed from the bytes; encoder strings matched against editors and AI services; layout, timestamps and track lengths cross-checkedMetadata is editable and often stripped by platforms; absence proves nothing
Frame-to-frame differenceInserted, deleted or duplicated frames; hard cutsMean absolute luminance change between consecutive sampled frames at 160 px width; spikes beyond mean + 2.5 SD flaggedScene cuts and fast motion spike legitimately; sampling 24–96 frames can miss single-frame edits
Motion magnitudeWarping, jitter, motion inconsistent with the scene (face swaps, composites)Block matching (8 px blocks, ±2 px search) between sampled frames, averagedCoarse; camera shake and pans dominate
Luminance flickerRelit or synthesized content flickering at a rate the scene does notMean luminance per sampled frameAuto-exposure and lighting changes also flicker
Frozen / duplicate framesLooping, padding, dropped-frame repairConsecutive frames with mean difference below 1.2Static tripod shots duplicate naturally
Per-frame ELA, noise, block gridSpliced regions within a frameRe-grab the frame at up to 480 px, ELA at the chosen quality, Laplacian residual, energy on the 8×8 gridVideo compression is harsher than JPEG; supporting context only
Frame exportPreserves a specific frame as evidenceRendered at native resolution to PNG, SHA-256 of the PNG recorded in the reportDecoder output, not the original compressed frame
AI detector (optional)Synthetic or face-manipulated framesonnx-community/deepfake-detection-model via Transformers.js, on deviceWrong in both directions; a second opinion only
What each check means & honest limitations
Container metadata and the evidence report

Before any pixel is examined the studio hashes the file (SHA-256, SHA-1, MD5) and parses its container. MP4/MOV files record a brand, movie and track creation times, codecs, frame rate, keyframe count, edit lists, rotation, the writing software (©too), device make and model, GPS (©xyz) and sometimes XMP or C2PA boxes; WebM/Matroska files record muxing and writing applications, dates, codecs and tags. Findings such as an FFmpeg encoder string, zeroed timestamps, a fast-start layout, a missing audio track or mismatched track lengths are reported as leads. The report (printable, or JSON) carries the hashes, every finding, the temporal metrics for each sampled frame, the per-frame images you inspected, exported-frame hashes and a method summary.

Where the processing happens

Your browser decodes the video and steps through sampled frames on a canvas. The temporal charts and per-frame passes are plain pixel math — no model, no upload. If you enable the optional AI detector, a model downloads once from a public CDN, is cached, and runs locally too. Nothing is ever sent to a server; you can confirm this in your browser’s network tab.

Temporal checks (flicker, motion, frozen/duplicate)

These exploit the fact that manipulations rarely stay perfectly consistent across time. Inserted or deleted frames break the difference rhythm; face-swaps and composites warp or flicker; loops and padding show as duplicate frames. They are strong leads, but ordinary things — cuts, fast motion, static tripod shots, low frame rates — can mimic them, so read the charts in context.

Per-frame spatial checks (ELA, noise, JPEG grid)

Applied to a single frame, these are the same passes as the Photo Forensics Studio. ELA is familiar but weak — edges glow regardless of tampering and recompression erases it. Noise and grid checks can reveal a spliced region that came from another source. Video compression is harsher than JPEG, so treat these as supporting context, never as standalone proof.

The optional AI detector

It is off by default for a reason: it downloads a model of tens of megabytes and is much slower and more resource-hungry than the canvas checks, especially without WebGPU. It scores frames for how synthetic they look, but it can be wrong in both directions — missing a careful fake and flagging clean footage — and it does not explain itself. Use it as one more voice, not the deciding one.

Methods, parameters and comparisons

Thresholds, verdict rules and references for every check are documented on the forensics methods & limitations page. For how this studio compares with Amped FIVE, Magnet Verify, InVID and MediaInfo, see video forensics software compared; version history is in the changelog.

Responsible use

A flag here is not an accusation. Do not publish a manipulation claim on the strength of these automated signals alone, be careful about conclusions that could harm someone, and remember the tool cannot make a determination. Only analyze footage you have the right to. See Is OSINT legal? and, for provenance signals, C2PA Inspector · how to verify a video · C2PA & content credentials.

Frequently asked questions
Can this tool prove a video is a deepfake?

No. It surfaces signals consistent with manipulation, CGI, AI generation or editing, but no single signal is proof. Compression erases traces and real footage can false-positive. Corroborate across the container findings, the temporal charts and the per-frame passes, and for real stakes consult a qualified examiner.

What does the container metadata tell me about a video?

MP4/MOV and WebM files record which software wrote them, when, with which codecs and frame timing, the device make and model, GPS, rotation and edit lists. An FFmpeg or editor string, zeroed timestamps, a fast-start layout, a missing audio track or a generative-video encoder name all say something about how the file reached you. The studio reads these from the file bytes and lists them as findings.

How does the temporal analysis work?

It samples 24, 48 or 96 frames evenly and compares them over time: mean frame-to-frame difference, block-motion magnitude, mean luminance and near-duplicate detection. Inserted, deleted or duplicated frames break the natural rhythm; face swaps and composites warp or flicker. These clues exist only in video, not in a single image.

Is my video uploaded to a server?

No. Hashing, container parsing, decoding and every analysis run in your browser; the optional AI model also runs on your device after a one-time download. The file never leaves your computer, which you can confirm in the browser’s network tab.

What is in the evidence report?

The file’s SHA-256, SHA-1 and MD5, size and dates, every container finding, the full container metadata, the temporal metrics for each sampled frame with charts and flags, the analysis images of every frame you inspected, the hashes of any frames you exported, the optional AI scores, your case, exhibit and examiner details, and a method summary. It opens as a printable page you can save as PDF, and the same data is available as JSON.

Can I export a frame as evidence?

Yes. Select a frame and export it; it is rendered at the video’s native resolution to a PNG whose SHA-256 is shown and recorded in the report, so the exported picture can be tied to this examination later.

What is the optional AI detector, and why is it off by default?

It runs a neural network over sampled frames to estimate how AI-generated or face-manipulated they look. It is off by default because it downloads a model of tens of megabytes and is much slower and heavier than the built-in checks, especially without WebGPU. Treat its score as one more voice, not the deciding one.