Deepfake Detection Service: OSINT Checks on Manipulated Media
A deepfake detection service should tell you how far a piece of media can be trusted and why, not just print a score. We combine detection tools with provenance data and open-source checks on the world around the file: who first posted it, whether the place and time fit, and whether the person shown could have been there.
- Video, voice and images
- Detectors as one input, not the verdict
- Provenance and Content Credentials
- Context checked against the world
A deepfake detection service assesses whether video, audio or images were generated or altered by AI. OSINT-S runs several detection tools, checks provenance data such as C2PA Content Credentials, and tests the content against public facts: its earliest source, location, timing and the subject's known whereabouts. Results are graded, because current detectors produce errors that only independent evidence can resolve.
What a Deepfake Detection Service Can and Cannot Tell You
Detectors give probabilities with real error rates. A useful answer combines them with evidence a forger cannot easily control.
NIST's 2024 review of synthetic content techniques notes that detectors "are often tied to and may only perform well on specific generators", and that they "tend to exhibit substantial error rates, particularly after post-processing" such as compression or resizing (NIST AI 100-4).
So we never report a single score as a finding. Our conclusions use three labels: indications of manipulation (specific artifacts or contradictions found), no indication found (tests passed, which is not proof of authenticity), and inconclusive (the file is too degraded or the tests disagree). Each comes with the evidence for it.
Types of Manipulated Media We Examine With OSINT
Face swaps, cloned voices, fully generated images and simple edits each fail in different ways, so each needs different checks.
| Type | Typical misuse | What tends to give it away |
|---|---|---|
| Face swap and lip sync video | Fake executive statements, fake endorsements, remote interviews and video calls | Edges of the face, teeth and eyes, lighting that does not match the scene, mouth out of step with speech |
| Cloned voice | Urgent payment calls and voice notes "from" a CEO or relative | Flat breathing and emotion, odd pauses, background that does not fit; above all, a request that fails a call-back |
| Fully generated images | Fake profile photos, fake identity documents, invented incident photos | Text and hands, repeated textures, faces that match galleries of AI faces, no earlier source anywhere |
| Edited real media | Altered damage photos, removed objects, spliced audio | Inconsistent shadows and noise, compression differences, earlier unedited copies online |
Deepfake Fraud: What Regulators Warn About
US authorities report rising deepfake fraud against financial institutions and list red flags that open-source checks can test.
In November 2024 FinCEN issued an alert on fraud schemes using deepfake media, stating that "beginning in 2023 and continuing in 2024" it had observed an increase in suspicious activity reports describing suspected deepfakes, particularly forged identity documents used to get past verification (FinCEN Alert FIN-2024-Alert004). Its red flags include a customer photo that shows visual signs of alteration, a third-party webcam plugin used during a live check, and "a reverse-image lookup or open-source search of an identity photo" that "matches an image in an online gallery of GenAI-produced faces".
Several of those flags are open-source checks, which is where our work helps fraud and onboarding teams. For hiring, see remote candidate identity verification; for payment and impersonation losses, fraud investigations.
C2PA Content Credentials in OSINT Media Checks
Content Credentials are strong supporting evidence when present and intact, but they are often missing or stripped, so they never decide a case alone.
"Content Credentials" is the C2PA specification's preferred non-technical name for a C2PA manifest, the signed record of how a file was made and edited (C2PA specification 2.2). Platforms often strip it on upload, but the specification provides a fallback: if a manifest is removed but a copy survives in a provenance store elsewhere, soft bindings such as watermarks or fingerprints can be used to find it again. We check for embedded and recoverable credentials and record the result; authenticity is still decided by content and context.
How Our OSINT Deepfake Checks Work
Preserve, trace, check provenance, run detectors, review by eye and ear, test against the world, then grade.
- Get the best copyWe ask for the original file or the first link, and hash it. Every re-share and screen recording removes evidence.
- Trace the sourceReverse image, keyframe and audio searches find earlier versions, which may be the unedited original or the source clip a face was taken from.
- Check provenanceMetadata and any Content Credentials are read and recorded, knowing both can be missing or altered.
- Run several detectorsCommercial and open-source tools for image, video and voice are run; disagreements between them are recorded, not averaged away.
- Expert reviewAn analyst examines frames and audio for the artifacts listed above and compares the subject with verified reference footage.
- Test the contextWhere and when was this supposedly recorded, and was the person there? Public schedules, events, weather and geolocation often settle what detectors cannot.
- Grade and reviewA conclusion with a confidence level and the evidence behind it, checked by a second analyst and signed off by a senior reviewer.
When a Deepfake Targets Your Company or You
Stop any payment or action, verify through a known channel, preserve the file, then investigate and report.
- Payment requests by voice or video. Confirm through a channel you already hold, never the one supplied, and preserve the recording and the account it came from.
- Fake statements by executives. Capture the posts and their spread before they are removed, then let communications respond with evidence; executive impersonation covers the accounts behind them.
- Intimate deepfakes. In the US, the TAKE IT DOWN Act of 2025 criminalizes publishing nonconsensual intimate images, including AI-generated ones, and requires covered platforms to remove them within 48 hours of a valid notice; the FTC enforces the removal process (FTC). We help document what is online for the removal notice and for police, with the person's consent.
Timelines, Deliverables and Limits
A first assessment of a single file can often be given within a business day; a defensible report takes from 10 business days.
You receive a short graded verdict, then the evidence: annotated frames, detector outputs, provenance findings, source trail and context checks, with file hashes. A first assessment of one file is often possible within a business day; a full report for litigation or a set of files takes from 10 business days, and larger reviews up to about a month. Urgent delivery adds 50%, the quote is fixed after written scoping, and the fee goes down if we miss the agreed date.
We do not create synthetic media, certify a file as authentic beyond what the evidence shows, or use a deepfake case to unmask someone for retaliation. Deepfake checks sit alongside the rest of our OSINT services for fraud, legal and communications teams.
Not Sure It's Really Them?
Send the file or link, where it came from and what decision rests on it. We give you a first view quickly and a fixed quote for the full check.
Deepfake Detection FAQ
Our finance team got a voice note from what sounded exactly like our CEO asking for an urgent transfer — can a deepfake detection service tell us whether the voice was cloned?
Sometimes, but do not wait for the answer before acting: hold the payment and call the CEO on a number you already have. We then analyze the audio with several voice detectors and by ear, compare it with verified recordings of the CEO, and trace the account and number that sent it. Short, compressed voice notes are hard to judge, so the context checks often matter more.
I ran a video through a free online deepfake detector and it said 87% fake — is that enough to call it a deepfake publicly?
No. A single detector score is a probability with real error rates, especially on compressed or reposted video, and different tools often disagree. Before saying anything publicly, you want evidence you can show: an earlier unedited source, visible artifacts, or facts that contradict the scene. We run several tools, record where they disagree and look for that independent evidence.
A video of our CEO saying offensive things is spreading on social media, and she says she never said it — how quickly can you give us something we can use in a statement?
A first assessment can often be given within a business day: earliest source, any original footage the face or voice was taken from, detector results and whether her known schedule fits the claimed recording. If the evidence supports manipulation, the statement can point to it. We also capture the posts and accounts spreading it before they are deleted.
Someone made a fake intimate image of me with AI and posted it on a forum — can you help me get it removed and find out who did it?
We can help, with your consent and at your direction. We document where the image appears, preserve the evidence for police and for removal notices, and look at the accounts that posted it. In the US, platforms covered by the TAKE IT DOWN Act must remove such images within 48 hours of a valid request. Identifying who made it is possible in some cases and goes to the police or your lawyer.
Our image has no Content Credentials and the metadata is empty — does that make it more likely to be a deepfake in your analysis?
No. Most platforms and messaging apps strip embedded data, and many cameras and apps still do not add Content Credentials, so absence is normal. When credentials are present and valid, they are useful supporting evidence about how a file was made. Our conclusion rests on the content and its context: earlier sources, artifacts and whether the scene fits the claimed place and time.
Sources and Notes
- NIST AI 100-4: Reducing Risks Posed by Synthetic Content (November 2024)
- FinCEN Alert FIN-2024-Alert004: Fraud schemes involving deepfake media targeting financial institutions (November 2024)
- C2PA Technical Specification 2.2 (Content Credentials)
- Federal Trade Commission: TAKE IT DOWN Act
Sources checked 10 October 2026. Figures about third-party firms and tools are as published by them or by the cited source on that date.