Notes from an adversarial field
Practical writing on detection, digital evidence and what actually survives challenge — including the parts most vendors leave out.
How to Detect a Deepfake Video: What Actually Works in 2026
The visual tells everyone repeats stopped working years ago. A practical guide to what genuinely indicates a manipulated video in 2026, and why a single detector score is not enough.
Read articleIs Deepfake Evidence Admissible in Court? What Examiners Need to Prove
A detection score is not evidence. What actually has to be established for a media authentication finding to survive challenge — custody, methodology, stated limitations and a named examiner.
Read articleVoice Cloning Scams: How They Work and What Investigators Can Recover
Seconds of reference audio is enough to clone a voice. How cloned-voice fraud is actually executed, what forensic evidence survives a phone call, and what to preserve first.
Read articleWhy Deepfake Detectors Fail: Four Failure Modes to Test For
Detectors that score 99% on a benchmark routinely underperform on real casework. The four failure modes behind that gap, and how to test for them before you deploy.
Read articleChain of Custody for Digital Evidence: A Practical Guide
Digital exhibits need more than a signed logbook. What custody has to demonstrate for media evidence, and how hash-chaining makes integrity provable rather than asserted.
Read article