Author Archives: Marco Fontani

Recaptured Images Are a Good Way to Fool Forensic Analysts… but Not those Equipped with Amped Authenticate!

Hello dear Amped Blog readers, welcome to this week’s Tip Tuesday. Today we’ll be dealing with one of the most sneaky kinds of fakes: recaptured images. A recaptured image is a “picture of a picture”: you display your (possibly forged) image on a screen, or you print it on paper, and then you take a picture of it. This apparently naive approach is much more clever than it seems: the obtained image will be a “camera original” image to all extents, so it will likely pass every test based on metadata/format analysis. Are we left alone against this subtle threat? Of course not, Amped Authenticate is here to help. Let’s find out how.

Continue reading

Amped FIVE’s Motion Detection: the way to skip the noise and focus on the action!

Hi Amped Blog readers, welcome to this week’s Tuesday Tip! Although we do our best to make you love our Amped FIVE, we are still aware that you may have better things to do in your life than enhancing videos… so, what really makes us happy is to help you get the job done in the least amount of time! That’s why this week we’ll focus on how Amped FIVE’s Motion Detection filter can save you lots of time during triage.

Continue reading

Amped Authenticate’s “Show Saturation” Feature Saves You from April Fools!

April Fools’ Day has just passed and we hope you didn’t go through any nasty trick! Alas, for people working with digital evidence, the risk of getting fooled by some ambiguous finding is always around the corner. In the case of digital image forensics, among the most frequent pitfalls, we find false positives produced by forgery localization algorithms (that is, when an algorithm marks as manipulated a region that was not so). Today’s Tuesday Tip deals with them and shows how Amped Authenticate helps you rule out some of them.

Continue reading

Did you know Amped FIVE lets you work with hindsight?

Hello Amped friends, welcome to this week’s Tip Tuesday! Today we’ll focus on a feature that is intrinsically part of Amped FIVE since always but is often overlooked by users. I’m talking about the possibility of changing parameters of a filter that lays at the beginning of a long chain while watching the effect on the final output. The “while” in the previous sentence is not incidental… it can save you lots of time and help you reach much better results! Let’s see what this is about.

Continue reading

Is your image embedded in a PDF file? No worries, Amped Authenticate can handle that!

Welcome to this week’s Tip Tuesday! Today we are showing you an interesting, perhaps a bit hidden, functionality of Amped Authenticate. There is no need to introduce the PDF file format: it is surely the most widespread format for sharing digital documents. Therefore, it may easily happen that you have to deal with a PDF containing images and that some of them get questioned.

What would you do in such a case (after realizing that if you drag-and-drop the PDF into Amped Authenticate, nothing happens, because it’s not an image file)? Would you take a screen capture of the picture and work with that? “Nooo!” – I hope you said! Screenshots are evil for image forensics! Ok, you would get some pixels to work with, but you would lose all metadata, you would lose encoding properties, you could be recompressing data… That means you cannot check image integrity, and finding manipulations becomes much harder. No, there’s a better way of dealing with images embedded in PDFs, and we’ll show you how!

Continue reading

VeriFIVE your files (aka “How to hash-check files in your Amped FIVE project”)

As you smart forensic analysts have undoubtedly noticed, last week there was no Tip Tuesday. Did we forget? Well, not really… We just realized that no Tip could stand the bright light shone by last Tuesday’s great announcement: the launch of Amped Replay, Amped Software’s newest solution for investigators and frontline officers! If you happened to miss that news read more about it here!

After that, you can enjoy this week’s Tip Tuesday!

If you are working in the digital forensic field, you are certainly aware of the importance of data integrity. Ensuring data integrity means to verify that the information you are working on remains unaltered during the whole process (including transmission and storage of data).

Unfortunately, when it comes to digital images and videos, integrity is more threatened than with other types of files. For example, if you rotate an image using your OS default photo viewer and then close it, the file will likely be overwritten without any advice. While in many cases the changes made to pixels may be “negligible”, the file will still change… which means its hash value will be different. And we know this could invalidate your whole analysis (in the end, another analyst cannot know why the hash is different, it’s just different).

At Amped, we take data integrity very seriously. Our software never overwrites nor moves the evidence file you are working with. But there’s more:
Amped FIVE provides you with a seamless way of checking data integrity straight inside your project. And this Tuesday’s Tip tells you how!

Continue reading

Quick Triage with Amped Authenticate’s Batch File Format Analysis Can Save You Lots of Time

Dear Amped friends, welcome to this week’s Tip Tuesday!

In our last Tip we’ve talked about how Amped FIVE users can save time by trimming and cropping the video they’re working on, so to focus the analysis only on interesting parts. Probably, we opted for that topic because February is the shortest month, and it may give you the feeling that time flows away too quickly. Since we can’t stop time, let’s at least save it when possible!

This week is Amped Authenticate‘s turn, so let’s see how we can save time when investigating our digital images. Once more, it’s a matter of focus: to save time, we have to focus the analysis on the right images (i.e., properly select them) and run only the analysis filters that we need on them. We will focus on the first aspect today, and leave the second for a coming-soon Tip.

Continue reading

Trim, Crop and Watch Processing Time Drop!

Digital videos are constantly getting more and more bulky. Nowadays it is not uncommon to work on CCTV footage with resolution above Full-HD, sometimes even 4k. Unfortunately, this huge gain in resolution is often frustrated by extremely aggressive compression (at the end of the day, the video must fit into a DVR hard drive). And there is one more collateral effect of working with hi-res videos: the processing time increases.

Even if you are running Amped FIVE on a powerful computer, you may experience a significant slow-down when applying some filters to your footage. Remember that Amped FIVE processes your video in “live mode”: all filters in the chain are applied on-the-fly, and the result is rendered on the screen. If you feel the video is not playing fast enough, today’s Tuesday Tip is here to help you!

 

Our suggestion is to focus your analysis on the portion of footage that really matters, both in time and space.

Continue reading

Log-Scale: A Great Ally for Plot Interpretation!

Amped Authenticate users know how important it is to understand the processing history of an image, and they (hopefully!) know that “processing history” does not mean just splicing.
For example, there are cases where the image has been scaled or re-compressed, and
when one of these happen you should be aware of it, as they bring important consequences to the rest of your investigation.

Amped Authenticate offers many tools for processing history analysis under the Global Analysis filter category. Some of these, for example the DCT Plot, the Correlation Plot, and the JPEG Ghost Plot are… plots! They should be examined carefully, because we know that artifacts like a “comb-shaped” DCT histogram strongly suggests double JPEG compression, and so does a JPEG Ghost Plot with multiple local minima. The problem is… sometimes it’s just hard to see these artifacts, because they are “hidden” in the plot!

Consider the image below: at a first glance, its DCT Plot for DCT Frequency 4 seems rather “smooth”, and you could easily overlook it.

Continue reading