Find a Person by Their Photo: Reverse Image Search and Forensic Analysis
Detect AI, deepfake and manipulation · Uncover the subject: ID, social media, facial biometrics and digital traceability
Upload an image or enter its URL to run a complete online forensic image analysis: AI detection with Hive and GPT-5.4 Vision, EXIF with GPS and device data, ELA, perceptual hashing, steganography, OCR and digital tracing with SauceNAO and Google Vision. The report lets you find out if a photo has been edited or generated by models like DALL-E or Midjourney.
▶ See a full sample report
Real result of a forensic analysis: 4D risk scoring (authenticity, privacy, exposure, content), executive verdict with AI/deepfake detection, geocoded GPS coordinates, device EXIF metadata, ELA analysis, steganography, perceptual hashing, OCR and digital tracing via reverse image search.
What is forensic image analysis + identity investigation?
IntelMind’s Forensic Image tool provides a thorough online forensic image analysis from a digital forensic intelligence (OSINT) and synthetic-content detection perspective.
It doesn’t just say whether an image «looks real»: it combines AI detection (Hive + GPT-5.4 Vision), ELA analysis, full EXIF metadata with GPS geocoding, perceptual hashing and copy detection to reconstruct the complete forensic chain from the original device to the current file.
What you get with every analysis
- AI/Deepfake detection: Hive API V3 (visual moderation + AI detection) + GPT-5.4 Vision with a combined score.
- Full EXIF metadata: device, date, camera, settings, geocoded GPS with a map.
- Forensic chain: reconstructs the origin — where it came from, where it’s been, what software touched it.
- ELA analysis: detects JPEG edits, manipulated regions and an estimate of re-saves.
- Copy detection: identifies whether the image is a copy of another (social app, compression, resizing) and locates the original.
- OCR + Steganography: extracts visible text, detects data hidden in the least significant bits.
- Facial detection: counts faces, type (frontal/profile), occupancy ratio — useful for portraits and documents.
- Automatic reverse search: Google Vision and Yandex locate where the image appears online and compare it with the original.
Quick FAQ
Does this tool uncover the identity of the person in the photo?
Yes. If the image is published online (or can be recovered via visual reverse search), we extract legal name, validated national ID, age, place of birth, residence, occupations, own company, personal domains, social media profiles with real metrics (LinkedIn, Twitter/X, Instagram, Facebook, YouTube, TikTok, Telegram, Threads, Reddit, GitHub and 14 more platforms under a strict cross-confirmation policy), facial biometrics cross-checked against their profiles, and the Wayback historical archive. All information comes from legitimate public sources (legal notices, public profiles, reverse image search). If there’s no verifiable match, we don’t invent one: we flag it as «unconfirmed».
Does it detect if an image is AI-generated or a deepfake?
Yes. We apply multi-source consensus with a strict cross-confirmation policy: Hive API V3 (models specialized in AI and deepfake detection) + GPT-5.4 Vision (semantic analysis) + sd_mj_exif (10 generators: Stable Diffusion, MidJourney, DALL-E, Firefly, Leonardo, Imagen, Runway, NightCafe, Kling, Flux) + PNG chunk and metadata analysis. We only claim a specific generator when ≥2 sources agree; a single signal is flagged as «isolated indicator, not conclusive».
How many credits does the forensic image analysis cost?
30 credits per analysis. The cost reflects running 28 correlated forensic scripts, generative AI (gpt-5.4 with 20 control rules), external APIs (Hive, Google Vision, SauceNAO, TinEye, Wayback), identity attribution via web scraping, internal cross-referencing with IntelMind’s own email/domain/social/phone tools, an internal pHash cluster (links previous SaaS cases), and an RFC 3161 chain of custody. It’s IntelMind’s most complete tool in terms of expert value and compute time (4-5 minutes per analysis, ≈280 seconds).
What does the forensic image analysis PDF include?
A professional expert summary structured in 2 dense parts: PART 1 — Forensic image analysis (forensic verdict with concrete figures, capture device + dating + location in a table, copies found online with the metadata-richest copy highlighted, chain of custody) and PART 2 — Deep identity investigation (legal owner with validated national ID + age + place of birth + residence + occupations + company + personal domain · social profiles with real metrics · cross-confirmed facial biometrics · other websites and bibliography with ISBN · detected contacts · Wayback timelines · anomalies and recommendations). Includes a 3-line executive summary (decision / risk level / immediate action), multidimensional 5D scoring (Final · Privacy · Authenticity · Exposure · Content) with consistent LOW/MEDIUM/HIGH/CRITICAL levels, the file’s digital fingerprint (pHash + dHash + wHash + aHash + colorHash + combined), detected license plates and document patterns, and a digital chain of custody: SHA-256 + MD5 hash + RFC 3161 timestamp issued by FreeTSA + a public verification URL. Suitable for expert legal testimony, M&A due diligence, verifying news stories and KYC/AML compliance.
Does it detect the image on other websites (reverse search)?
Yes. We combine Google Vision (Web Detection with matching pages and full matches), Yandex Reverse, TinEye, SauceNAO, Bing Visual Search and the Wayback Machine. When it finds matching pages, the system downloads them, extracts the names associated with the image (JSON-LD, meta tags, titles), and only claims an identity when the same name appears on ≥2 different hosts (cross-confirmation policy).
What is the internal pHash cluster?
We store the perceptual hash of every analyzed image in our own PostgreSQL database. When a new image comes in, the system checks whether its pHash matches (distance ≤3) previous cases in the same SaaS. This automatically links separate investigations that share the same visual material — key for private investigators, investigative journalism and SOC teams.
What is the internal cross-reference with other tools?
If the image’s OCR extracts @handles, URLs, emails or phone numbers, the system automatically sends them to IntelMind’s own OSINT tools (email, domain, social media, phone) and brings back the cross-referenced context in the same report. It turns a single image into a chained OSINT dossier.
Can it detect hidden information in every image?
Not always. The steganography module detects genuine anomalous payloads (LSB zsteg + binwalk signatures) and distinguishes standard XMP/IPTC metadata from real findings. Entropy changes are flagged as indicative, not confirmatory, pending manual validation. The real strength is in the combination: stego + ELA + JPEG Ghost + Benford double-compression + PRNU + Q-table fingerprint.
What’s the difference between uploading a file and using a URL?
With a file you get a complete analysis including ELA, perceptual hashing, steganography, PRNU (sensor fingerprint) and exportable 128d face embeddings. With a URL, the system downloads the image and runs the same analysis, while also preserving the source URL as part of the forensic chain.
How long does a full forensic analysis take?
Between 4 and 5 minutes per analysis (≈280 seconds typically). This isn’t a shallow AI check — we download every copy found online, extract its EXIF, validate facial biometrics and cross-check 24 platforms under a strict confirmation policy. The pipeline includes 20 phases — faces + CLIP + YOLO + EasyOCR + JPEG Ghost + PRNU + ELA heatmap + Benford double-compression, external APIs (Hive + GPT-5.4 Vision + Google Vision + Yandex + TinEye + SauceNAO + Wayback), a forensic «killer» module (downloads + EXIF + sha256 + pHash for up to 15 detected copies), legal web scraping for identity investigation, and a professional expert synthesis (40 control rules). The duration reflects the real forensic work delivered, suitable as court evidence.
Is it legal to analyze third-party images with forensic tools?
Forensic image analysis works exclusively with the file’s metadata and technical characteristics. It doesn’t access private accounts or breach systems. Under data-protection law, analyzing files obtained legitimately (published online, submitted in legal proceedings, or voluntarily provided) is lawful. Responsibility lies in how the image was obtained, not in its technical analysis.
What is the RFC 3161 chain of custody for in a forensic report?
The RFC 3161 timestamp certifies that a file existed at a specific moment, issued by an independent Time Stamping Authority (TSA) — FreeTSA in our case. In expert legal testimony, it proves the image wasn’t altered after the seal’s date. It’s the internationally accepted standard for digital evidence in legal proceedings.
How can this tool tell if a photo has been edited?
IntelMind runs multiple technical tests in a cascade: Error Level Analysis (ELA) with a visible heatmap, JPEG Ghost (regions recompressed at a different quality level), Benford’s law double-compression analysis, Q-table fingerprinting, XMP Adobe history (Photoshop/Lightroom chain), C2PA Content Credentials, clone detection (ORB-based copy-move), PRNU sensor mismatch, and AI detection with Hive + GPT-5.4 Vision. Correlating all these signals detects AI-generated deepfakes (DALL-E, MidJourney, Stable Diffusion, Firefly…) and human manipulation (Photoshop, Lightroom) more robustly than any single tool.
The complete guide: forensic analysis + deep identity investigation by image
Online forensic image analysis is a core discipline in OSINT investigations, cybersecurity and digital expert testimony. IntelMind combines 28 correlated forensic scripts to deliver a complete x-ray of any image file: from detecting AI-generated content to reconstructing the forensic chain of custody with an RFC 3161 timestamp.
Detecting AI-generated images and deepfakes
The rise of generative models like DALL-E, Midjourney, Stable Diffusion and StyleGAN has made detecting synthetic images a critical need for investigators, journalists and antifraud teams. IntelMind uses two complementary engines:
- Hive API V3 — models trained specifically to classify AI, deepfake and visual manipulation content. Hive analyzes statistical patterns in texture, frequency and pixel structure characteristic of each generator (Hive documentation).
- GPT-5.4 Vision — semantic image analysis: lighting consistency, anatomy, perspective and visual artifacts typical of diffusion models (fingers, text, odd symmetries).
The combined score weighs both engines and produces a verdict with a confidence level: Original photo, AI-generated, Likely AI, Confirmed deepfake, or Manipulation detected.
EXIF metadata and GPS geocoding
Every digital photograph stores EXIF (Exchangeable Image File Format) metadata that includes the device, camera model, shooting settings (aperture, ISO, exposure), timestamps and, in many cases, the exact GPS coordinates of where the image was taken. IntelMind extracts this data with ExifTool and geocodes the coordinates via Nominatim/OpenStreetMap to show the city, street, postal code and direct links to Google Maps and Street View.
The presence or absence of metadata is itself a forensic signal: an image with no EXIF has likely been processed by a social network, an editor, or a messaging service that strips metadata during compression.
ELA analysis: Error Level Analysis
ELA is a forensic technique that detects regions of a JPEG image that have been re-saved at a different compression level. When an area has been edited (cropped, cloned or added), it shows a JPEG error level different from the rest of the image.
IntelMind generates the ELA map and analyzes it automatically to detect areas with localized manipulation, also estimating the number of JPEG re-saves (each export adds cumulative compression artifacts). A high number of re-saves usually indicates the image has passed through multiple editors or platforms.
Steganography and hidden data
Steganography is the technique of hiding information inside an image without altering its visual appearance. IntelMind runs LSB (Least Significant Bit) analysis with zsteg and binwalk signatures to detect embedded payloads, hidden scripts or compressed files inside the image.
The module distinguishes between standard metadata (XMP, IPTC) and genuine findings: suspicious strings, anomalous entropy and known file signatures. Results are classified by risk level: low (normal metadata), medium (unusual patterns) or high (confirmed payload).
Perceptual hashing and copy detection
Perceptual hashing (pHash, dHash) generates a unique fingerprint for the image that lets it be compared with other versions even after resizing, compression or minor cropping. Unlike a cryptographic hash (SHA-256), perceptual hashing tolerates minor changes and detects whether two images are essentially the same.
IntelMind checks the pHash against SauceNAO and Google Vision Web Detection to find where the image appears online, identify the highest-resolution version (a likely original candidate) and reconstruct the copy lineage: where it was first published, which sites republished it and with what modifications.
Chain of custody and the RFC 3161 timestamp
For legal and expert-testimony use, IntelMind generates a digital chain of custody that includes: the original file’s SHA-256 hash, MD5 hash, size, MIME type, and an RFC 3161 timestamp issued by a TSA (Time Stamping Authority) that certifies the file’s existence at a specific moment (IETF RFC 3161).
This record is useful in legal proceedings, internal audits and due diligence where you need to prove an image existed on a given date with no possibility of retroactive alteration.
4D scoring: Privacy, Authenticity, Exposure and Content
IntelMind’s scoring system evaluates every image across four dimensions with calibrated weighting:
- Privacy (30%) — exposed GPS, device serial number, identifiable software, timestamps
- Authenticity (40%) — AI/deepfake detection, ELA, metadata consistency, JPEG re-saves
- Exposure (20%) — presence in reverse search, number of copies, social media
- Content (10%) — NSFW moderation, detected faces, sensitive OCR text
The final weighted score (0-100) translates into a risk classification: LOW (an original image with no risk), MEDIUM (mixed signals), or HIGH (confirmed AI, manipulation, or exposed privacy).
Use cases: expert legal testimony, due diligence and OSINT verification
Online forensic image analysis has direct applications across multiple professional fields:
- Investigative journalism: verifying image authenticity before publishing, detecting photo composites and deepfakes in disinformation contexts (Bellingcat guides).
- Expert legal and forensic testimony: documenting the chain of custody with an RFC 3161 seal, proving manipulation with ELA, and reconstructing the origin via reverse search.
- Antifraud and insurance: detecting recycled photos in claims, AI-generated images of fictitious damage, or manipulated documents.
- Corporate due diligence: verifying that product, profile or facility images are real and not stock photos or AI-generated.
- OSINT and cyber intelligence: geolocating photos, identifying devices, tracing distribution across social networks.
- Content moderation: automatically detecting NSFW content, deepfakes and synthetic content on platforms.
How to tell if a photo is real, edited, or AI-generated
Verifying an image is an increasingly necessary routine in journalism, antifraud and due diligence work. Faced with a suspicious image, IntelMind runs 28 forensic tests in a cascade: generative-AI detection with Hive and GPT-5.4 Vision, EXIF metadata reading (camera, date, GPS), ELA forensic analysis to detect edited zones, reverse search with SauceNAO and Google Vision to detect reuse, perceptual hashing to locate near-identical copies on other sites, and a steganography review to rule out data hidden in pixels. The result is a professional expert verdict in plain language, structured into 2 parts (Forensic image analysis + Deep identity investigation), delivered in 4-5 minutes. If the question is «is this image real?», this is the full x-ray you need before making an editorial, antifraud or documentary decision.
Detecting AI images, deepfakes and manipulation: DALL-E, Midjourney, Stable Diffusion, Hive and GPT-5
An AI-generated image today is recognized by a combination of signals that aren’t obvious at a glance. Models like DALL-E 3, Midjourney v6 and Stable Diffusion XL leave statistical signatures in the pixels that specialized detectors like Hive Moderation and OpenAI’s own classifiers identify with 90-97% accuracy for typical cases. IntelMind integrates Hive as the primary detector, GPT-5.4 Vision as a second opinion (reading anatomical consistency, reflections, impossible text, oddly perspectived architecture), and combines both into a joint score. Detection isn’t perfect — images partially edited with AI (inpainting a detail onto a real photo) are the most common false negatives. That’s why we always recommend cross-checking with EXIF and reverse search.
Online EXIF + ELA analysis: metadata, GPS, camera, software, dates and sensor fingerprint
Standard forensic image analysis includes ELA (Error Level Analysis), a technique that detects zones recompressed at a different quality level than the rest. What an ELA scan actually shows is very concrete: when an original JPEG photo is edited in one area and saved again, the edited area ends up with a slightly different compression level. ELA visualizes that difference as brighter zones in the analyzed image. It isn’t absolute proof of manipulation (it can also read high in areas with text, sharp edges, or cameras that apply heavy post-processing), but combined with reading EXIF (was it edited in Photoshop? Are there date changes?) and reverse search (does the original image exist online without the altered detail?), ELA is one of the pillars of modern photo forensics.
