Sherlock Forensics · Metadata Inspector
This image was never edited
The panel on the right is an error level analysis of the panel on the left. Parts of it are blazing. Nothing in this picture has been altered, added, removed or retouched. It was drawn once and analysed once.
The image
Error level analysis
The claim: bright areas have been edited
Texture makes the picture bright, not tampering
Error level analysis re-compresses an image and maps how far the result drifts from the original. The theory is that a region which has been through a different number of compression cycles will drift by a different amount and show up.
The trouble is that everything else moves the needle harder. Edges, fine detail and noise are expensive to encode, so they drift furthest, whether or not anybody touched them. In the picture above, the gravel and the foliage blaze while the sky stays black, and the only difference between those regions is how much detail is in them.
An examiner reading brightness as guilt would convict the gravel.
The claim: it finds spliced content
One ordinary re-save erases it
Tick actually splice something in. A region compressed elsewhere is pasted into the frame, and it does stand out. This is the case the technique is named for, and in that narrow case it works.
Now tick re-save the whole file once as well. The splice is still there. The signal is not.
Recompressing the whole image puts every region back on the same footing. Sending a picture through a messaging app, exporting it from a photo library, or opening and saving it once is enough. So the technique fails precisely when a manipulated image has been handled normally, which is nearly always.
The claim: the result is objective
There is no threshold, and the dial is yours
Drag the analysis quality. The picture changes completely, and nothing in the file tells you which setting is correct. It is chosen by whoever runs the analysis.
There is no published figure separating an edited region from an unedited one. No brightness value means tampering. Two examiners looking at the same output will disagree, and both will be reasoning from an impression rather than a measurement.
That is the difference between this and every other check in a metadata report. A hash either matches or it does not. A restart marker is in sequence or it is not. This is a picture that people read meanings into.
So why does the tool include it at all?
Because it was asked for, and because an examiner is better served by a tool that produces it with the caveats attached than by a website that produces it without them.
In the Metadata Inspector it never runs on its own and never reaches the provenance assessment. It cannot be produced until the operator has read the caveat and ticked a box. The file it writes is named <name>-ELA-NOT-EVIDENCE.png, and the caveat is written to a text file beside it, because an analysis image separated from its caveat is exactly how this gets misused.
What answers the question properly
If what you need to know is whether an image was re-encoded, and by what, the quantization and Huffman tables answer it directly. They are measured values, they can be stated in a report, and they survive metadata stripping. Reach for those.