Analysis

Image viewer

The Image viewer opens, in its own window, every format that matters in an examination, from JPEG to camera RAW, and has the features of a good viewer — zoom, loupe, measurements, histogram, slideshow — without any feature that alters the evidence. Next to the image, the data a common viewer does not show: where the image really ends and what follows it, the dates compared, the history of the programs that touched it, the Content Credentials with their binding to the file, and forensic maps laid over the photo.

What it does

What the Image viewer module does

Formats

JPEG, PNG/APNG, GIF, WebP, multi-page TIFF, BMP, HDR, EXR and more; JPEG XL, PSD, DICOM, SVG (no external resources), HEIC/AVIF through the system decoder and camera RAW files actually developed (tested on Nikon NEF and Fujifilm RAF). Animations with their timing.

View, loupe and measurements

The photo fits the window and follows it when it changes; zoom around the cursor, pixel grid, 2× to 32× loupe, distance and angle measurement, rotations and flips of the view only. Colour inspector under the cursor in HEX, RGB, HSL, CMYK, CIELAB, with the exact count of distinct colours.

Histogram over every pixel

Of the image or the selection, linear or logarithmic, with minimum, maximum, mean, median and standard deviation per channel and the clipped pixels at 0 and 255.

Cropping without altering

Lossless PNG with the original pixels and bit depth, or JPEG without recompression: the DCT blocks are copied, no quality loss. Next to the crop a provenance .json file with source file, coordinates, method and hashes. The original is never overwritten.

Data a common viewer does not show

Trailing data after the image (a file appended past the end is found and named), dates compared across EXIF, GPS, XMP and file system with inconsistency findings, embedded images with their distance from the image, JPEG structure, programs and XMP history, perceptual hashes.

C2PA: does the manifest belong to this file?

Signature, certificates, declared actions and the full manifest tree, cloud manifests included. Above all the binding to the file: the hash declared in the manifest is recomputed over the image bytes. A valid signature on a photo modified after signing comes out as “does not match”.

Forensic maps overlaid

ELA, JPEG Ghost, residual noise and duplicated regions (copy-move within the same image), with adjustable opacity. The duplicate search is tuned not to raise false alarms on repeated textures: zero on fifteen real test photos.

Comparison and PDF report

Two images in the same window: side by side with synchronised zoom, wipe, overlay, amplified difference, alternation, with differing pixels and PSNR. The “Image details” report gathers technical data, C2PA, GPS map and the work done in the window, with crop hashes re-checked at print time.

Step by step

How it works

  1. Open an image: from the module, with “Open with Probatio” or with a double click if Probatio is the default app.
  2. Examine: File, Camera, Metadata, GPS and C2PA panels; forensic maps; comparison with a second image.
  3. Crop without altering and generate the PDF report.
FAQ

Frequently asked questions

Can the viewer alter the photo?
No. Rotations, adjustments and zoom affect the view only. Cropping creates a new file, next to a provenance file with the hashes; the original is never overwritten.
What does JPEG crop without recompression mean?
The crop copies the DCT blocks of the original JPEG instead of decoding and re-encoding the image: no quality loss and no new compression that would confuse a later ELA analysis.
Do the forensic maps prove manipulation?
No: they are clues to interpret. ELA, JPEG Ghost, noise and duplicated regions show where the image behaves differently; the duplicate search is tuned not to flag repeated textures.