Learn · Multimedia forensics

Pictures are files too

An image viewer shows you pixels. The file around them records which device wrote it, when and where, which software touched it last, and sometimes bytes that no viewer ever shows. These pages take image files apart byte by byte.

1 Anatomy of a camera JPEG

A JPEG from a camera is a chain of segments. Each one starts with a two-byte marker (FF + type). Most of them carry a length, so a parser can jump from one to the next. The layout of the sample photo used on these pages:

SOIFF D8
APP1 Exifa complete TIFF structure: IFD0, Exif IFD, GPS IFD, IFD1 + thumbnail
DQT · SOF · DHTquantisation tables, size, Huffman tables
SOSscan header
Entropy-coded datathe compressed pixels
EOIFF D9

Only the scan holds the picture. Everything else is either needed to decode it (tables, size) or describes it (metadata). Both kinds are evidence: the metadata says what the device claims, the decoding tables say which encoder actually wrote the file.

Metadata of the sample photo (exiftool-style listing)

2 Four questions

Most multimedia work on a seized device comes down to four questions. Each page covers one of them:

3 Working with images as evidence

About the samples: every image here is synthetic (shapes, gradients and the word SAMPLE) and built by generator/build_learn_media.py. The cameras (Lumora LX-7, Corvane C-200) do not exist; the GPS positions are public squares. The "tool" listings imitate exiftool, binwalk and pngcheck and are generated by the same script.

4 Warm-up

Two quick checks before you start. Everything needed is on this page or in Storage Foundations.

Which two bytes does every JPEG file start with? Type them in hex.

Look at the first box of the layout in section 1: the SOI marker.

FF D8 is SOI, "start of image". Do not confuse it with FF D9 (EOI), which ends the image, or with 89 50 4E 47, the start of a PNG signature. Carving tools search for FF D8 FF.

A TIFF header inside EXIF starts with 49 49 ("II"). What does that tell you?

"I" stands for Intel, "M" (4D 4D) for Motorola.

II = Intel byte order = little-endian: the magic number 42 is stored as 2A 00, and every offset and count after it has its least significant byte first. MM (4D 4D) means big-endian, with the magic stored as 00 2A.