Skip to content
ForensicSpot10 modules

Forensic Audio, Video and Image Analysis

Multimedia forensics covers the authentication and analysis of recorded media: digital images, video, and audio. It provides the scientific and technical methods for detecting forgery, identifying source devices, recovering intelligence from degraded recordings, and presenting media evidence in legal proceedings.

  • 60hours
  • 32topics
  • 10modules
Share
Module 16 hrs3 topics

Foundations: Digital Media and the Forensic Frame

The physical and mathematical basis of digital images, video, and audio, and the principles that allow these media to be analysed as evidence. Establishes what a digital media file actually is before authentication questions are asked.

Start module
  1. Digital Image Fundamentals: Pixels, Sensors, and FormatsEvery digital image is a grid of numbers shaped by the sensor that captured it, the demosaicing algorithm that filled in the gaps, and the format that compressed and stored the result. Those choices leave forensically exploitable signatures in every file.13 min
  2. Video and Audio File Structures: Containers, Codecs, and CompressionVideo and audio files are two-layer structures: a container that organises tracks and timing, and a codec that compresses the actual media data. The interaction between these layers creates characteristic artefacts that forensic examiners use to detect re-encoding, reconstruct timelines, and identify source devices.13 min
  3. Metadata, EXIF, and File-Structure ForensicsEvery digital media file carries structured metadata alongside its pixel or sample data. EXIF, IPTC, XMP, and format-specific structures like MP4 atom hierarchies and WAV RIFF chunks encode timestamps, device identifiers, and editing history that can corroborate or contradict a file's claimed origin.15 min
Module 26 hrs5 topics

Image Authentication and Forgery Detection

Methods for determining whether a digital image is an authentic, unaltered record or has been manipulated. Covers the main classes of forgery and the signal-level techniques used to detect them.

Start module
  1. Image Authentication: Principles and the Forgery TaxonomyImage authentication is the process of deciding whether a photograph has been manipulated and, if so, how. This topic covers the four main manipulation classes, the passive versus active authentication divide, and the evidential question that sits at the heart of every case.12 min
  2. JPEG Compression Artefacts and Double-Compression DetectionJPEG is the dominant image format in forensic casework, and its compression process leaves a distinctive statistical fingerprint that manipulation disturbs. This topic covers DCT block structure, quantisation tables as a camera fingerprint, double-JPEG detection, and the JPEG ghost method for localising pasted regions.12 min
  3. Error Level Analysis (ELA)Error level analysis amplifies the per-pixel difference between an image and a freshly re-saved copy to reveal regions with inconsistent compression history. This topic explains the operating principle, correct interpretation, known limitations, and the confounding artefacts that generate false signals.12 min
  4. Copy-Move and Splicing DetectionCopy-move and splicing are the two most common structural forgeries in digital photographs. This topic covers the block-matching and keypoint-based algorithms for detecting duplicated regions, illumination and chromatic aberration inconsistency for detecting spliced content, and the deep-learning detectors that now supplement classical methods.12 min
  5. Noise and CFA Inconsistency DetectionCamera sensors imprint a characteristic noise signature on every image they produce. Analysing noise level, noise model fit, and CFA interpolation residuals across image regions can localise forgeries and distinguish steganographic modifications from post-capture compositing.13 min
Module 36 hrs3 topics

Source Camera Identification: PRNU

Photo-Response Non-Uniformity noise as a sensor fingerprint. Covers the physics of PRNU, methods for extracting and comparing camera patterns, and the statistical framework for reaching evidential conclusions.

Start module
  1. PRNU: Physics and the Camera FingerprintPhoto Response Non-Uniformity arises from unavoidable manufacturing variation in image sensors, giving every camera a unique pixel-level pattern that persists across its lifetime and can link an image to the device that captured it.13 min
  2. PRNU Extraction, Matching, and the PCE StatisticPRNU camera attribution requires a denoising step to isolate the sensor residual, averaging many residuals to build a reference pattern, and then computing the Peak-to-Correlation Energy statistic to decide whether a query image came from a specific camera.13 min
  3. PRNU in Casework: Limitations and ReportingPRNU camera attribution has significant limitations in practice: compression, social-media re-encoding, and device-sharing all suppress or complicate the fingerprint signal, and rigorous reporting must address false-positive risk and uncertainty quantification.15 min
Module 46 hrs4 topics

Deepfake and AI-Generated Media Detection

Detection of synthetic media produced by generative AI: face swaps, full face synthesis, voice cloning, and generative image models. Covers the generation mechanisms, current detection methods, and the limitations of the field.

Start module
  1. Deepfake Generation: GANs, Diffusion, and Face-Swap PipelinesA technical walkthrough of how deepfakes are made, covering GAN-based face swapping, diffusion model synthesis, neural talking heads, and voice cloning, and why understanding these generation artefacts is the first step in detecting them.13 min
  2. Deepfake Detection: Signal, Physiological, and Semantic MethodsA structured survey of how deepfake videos are detected, from spectral frequency-domain analysis and CNN residual detectors to physiological signals like eye-blink rate, facial geometry irregularities, and the generalisation challenge across unseen generators.13 min
  3. AI-Generated Image Detection and ProvenanceHow forensic scientists and provenance systems detect whether an image was captured by a camera or generated by an AI, covering GAN fingerprints, diffusion model spectral signatures, C2PA cryptographic manifests, and the limitations of binary classifiers on unseen generators.14 min
  4. Synthetic Media in Casework and Legal ProceedingsHow courts handle the authentication burden when a party alleges deepfake, covering chain-of-custody for digital exhibits, expert testimony on generation probability, OSINT verification, jurisdictional positions across the UK, USA, and EU, and the NIST MIDAS benchmark.13 min
Module 56 hrs3 topics

Image Enhancement and Photogrammetry

Scientific limits of image enhancement, and how geometric information in images can be extracted to produce measurements of real-world dimensions, height, distance, and position.

Start module
  1. Image Enhancement: Principles and the Resolution BarrierWhat image enhancement can and cannot do, grounded in the physics of spatial resolution, optical blur, and the hard limit on information that was never captured.13 min
  2. Photogrammetry and Metric Analysis from ImagesHow projective geometry, camera calibration, and reference objects allow forensic analysts to extract real-world measurements from photographs and CCTV footage with quantified uncertainty.11 min
  3. Height Estimation from CCTV FootageThe methods, measurement workflows, and mandatory uncertainty reporting for estimating a person's stature from surveillance footage, including the Forensic Science Regulator's guidance and a comparison of reference-object and vanishing-point approaches.12 min
Module 66 hrs3 topics

CCTV, DVR, and Video Analysis

Acquisition, authentication, and analysis of video evidence from CCTV systems and digital video recorders. Covers the technical characteristics of surveillance systems that affect evidential quality and the methods used to analyse footage.

Start module
  1. CCTV and DVR Systems: Architecture and Evidence AcquisitionCCTV and DVR systems record differently depending on whether they are analogue, IP-based, or hybrid, and each architecture demands a tailored acquisition strategy to preserve evidential integrity. This topic covers the hardware and storage formats investigators encounter, the methods for extracting video without altering the original, and the chain-of-custody obligations that govern video exhibits.13 min
  2. Video Authentication and Integrity VerificationVideo authentication establishes whether a recording is original and unmodified, using hash verification, metadata cross-referencing, frame-level discontinuity detection, and bitrate analysis to expose tampering. This topic covers how compression artefacts, frame duplication, and re-recording signatures reveal manipulation even when the image content looks superficially intact.11 min
  3. Video Frame Analysis and EnhancementVideo frame analysis transforms raw surveillance footage into evidence that can survive courtroom scrutiny, using de-interlacing, multi-frame averaging, super-resolution, and colour calibration to improve clarity while keeping every processing step auditable. This topic covers the science behind each technique, the transparency obligations that accompany enhancement, and how multiple camera streams are temporally synchronised for trajectory and tracking analysis.14 min
Module 76 hrs2 topics

Facial Image Comparison

Methods for comparing faces in CCTV and other images with known reference photographs. Covers morphological analysis, the role and limits of automated recognition, and the standards governing expert facial comparison evidence.

Start module
  1. Facial Image Comparison: Morphological and Holistic MethodsFacial image comparison is the forensic discipline of examining still or video images to determine whether two faces belong to the same person, using anatomical landmark analysis and holistic assessment under rigorous methodological standards.15 min
  2. Automated Facial Recognition: Role, Accuracy, and LimitationsAutomated facial recognition uses deep neural networks to generate similarity scores between facial images; understanding how these systems work, where they fail, and how their outputs should be used is essential for any forensic practitioner or court that encounters them.17 min
Module 86 hrs4 topics

Audio Forensics: Authentication and Enhancement

Methods for authenticating audio recordings and enhancing speech intelligibility, including the Electric Network Frequency method as a powerful time-stamping tool.

Start module
  1. Audio Authentication and the Electric Network Frequency MethodThe Electric Network Frequency method turns the faint mains hum recorded on any plugged-in device into an involuntary timestamp, letting forensic examiners place a recording in time and detect tampering or splicing.13 min
  2. Audio Enhancement and Speech IntelligibilityForensic audio enhancement recovers intelligible speech from degraded recordings using noise reduction, adaptive filtering, and bandwidth extension, while strict procedural rules protect the integrity of the original evidence.12 min
  3. Gunshot and Event Audio AnalysisForensic gunshot audio analysis deconstructs the muzzle blast, shockwave, and impact signatures of a discharge to establish the number of shots, their sequence, the weapon type, and the shooter's location using acoustic physics and time-difference-of-arrival techniques.11 min
  4. Speaker Comparison: Methods and the Expert's RoleForensic speaker comparison evaluates whether a known speaker and an unknown voice in a questioned recording share a common source, using phonetic-auditory analysis, acoustic-parametric measurement, and automatic speaker recognition systems within a likelihood-ratio evidential framework.12 min
Module 96 hrs2 topics

Steganography and Hidden-Data Detection

Detection and extraction of information concealed within digital media files. Covers spatial and frequency-domain steganography methods, steganalysis techniques, and the investigative context in which hidden data appears.

Start module
  1. Steganography Methods in Images, Audio, and VideoA practical guide to how hidden data is embedded inside digital images, audio recordings, and video files, covering the major spatial, transform-domain, and metadata techniques used in real criminal and espionage cases.15 min
  2. Steganalysis: Statistical Detection MethodsHow forensic examiners detect steganographic content using statistical tests, machine-learning models, and blind detection pipelines, from the chi-squared attack on LSB images to deep-learning steganalysers for JPEG.15 min
Module 106 hrs3 topics

Standards, Chain of Custody, and Court Presentation

The procedural and legal framework governing media evidence: SWGDE and SWGIT guidelines, chain-of-custody requirements, report writing, and the admissibility of multimedia evidence in different legal systems.

Start module
  1. SWGDE and SWGIT Standards for Digital and Imaging EvidenceSWGDE and SWGIT are the US working groups that produced the consensus best-practice documents governing how digital multimedia evidence is acquired, processed, and analysed in forensic investigations.11 min
  2. Chain of Custody for Media EvidenceMaintaining an unbroken, documented chain of custody for digital media evidence, from the moment a device is seized through every processing step to its presentation in court.12 min
  3. Multimedia Evidence: Admissibility and Expert TestimonyHow multimedia evidence is authenticated and admitted in court across major legal systems, the obligations of the expert presenting it, and the landmark cases that set the current standards.14 min

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.