Where Was This Taken

作者 useosint06243a5620b0无许可证收录于 2026年10月8日更新于 2026年10月8日

End-to-end workflow to establish where and when a photo or video was captured and whether it is authentic — evidentiary handling, metadata extraction, reverse image search for provenance, visual geolocation, chronolocation from shadows, and manipulation checks, ending in a location finding with a stated confidence radius. Use when asked to verify where an image was taken, confirm or refute a claimed location or date, or authenticate media before relying on it. Applies to insurance claims, litigation evidence, disinformation analysis, and conflict and human-rights documentation. Reference at useosint.com/skills/where-was-this-taken.

AI 生成的概览

核实照片或视频的拍摄地点、时间及真实性,并给出带置信度的定位结论。

功能
该技能编排一套端到端的媒体核实流程:先固定并哈希原始副本,再提取元数据、通过反向图片搜索追溯来源、依据画面线索进行地理定位、利用阴影推算时间,并检查是否经过篡改。最终产出带置信半径的地点、时间窗口、真实性评估以及各自的证据链。它还规定了授权范围、发布精度与交接步骤,并将具体技法交由配套技能完成,而非在此重复实现。
适用场景
当需要核实某张图片或视频的拍摄地点、确认或推翻所声称的地点或日期,或在采信媒体前验证其真实性时使用。适用于保险理赔、诉讼证据、虚假信息分析以及冲突与人权记录等场景。
运行要求
需要一张图片或视频文件,或指向它的链接,并需访问用于元数据、来源追溯、地理定位、真实性判断和简报撰写的配套技能。它引用 yt-dlp、sha256sum、反向图片搜索引擎、卫星与街景影像、太阳位置计算器和天气档案等外部工具,并期望存在 ETHICS.md 文件和案件档案。该技能不附带脚本,仅为操作说明。

Where was this taken

Input: an image or video file, or a URL to one. Output: a location with a confidence radius, a time window, an authenticity assessment, and the evidence chain for each.

This workflow orchestrates. The technique detail lives in secrets-in-file-metadata, find-the-original-image, geolocate-from-pixels and is-this-photo-real — run those, don't reimplement them here.

The order matters more than anything else in this file. Metadata before analysis, because analysis destroys metadata. Provenance before geolocation, because the original's caption often is the location. Authenticity checks before you commit, because geolocating a composite gives you a confident answer to the wrong question.

Step 1 — Authorized scope

Read ../../ETHICS.md. Then state, in writing, before you open the file:

  • Subject — what the media is, and who appears in or is affected by it.
  • Objective — verification, disinformation research, missing persons, threat assessment, due diligence, litigation support, or showing someone their own exposure. If you cannot name a legitimate objective, stop.
  • In and out of bounds — specifically: are you permitted to publish a precise coordinate, or only a region? Is face search permitted? Is anyone in the frame a private individual?
  • Jurisdiction — yours, the subject's, and the platform's. Precise historical location data about an identifiable person is regulated personal data in most of them.
  • Publication floor — decide now what precision you will publish, before you know the answer. Geolocating a private individual's home from their own photos is the mechanic of stalking regardless of your intent, and conflict imagery can make the people in frame a target. Rounding a coordinate is a decision to make cold.

Done when subject, objective, bounds, jurisdiction and publication floor are written down in the case file.

Step 2 — Secure a pristine copy

Everything downstream is worthless if you contaminate the original.

  • Work from the file, not a screenshot of it. For platform video, pull the best rendition with yt-dlp and keep the sidecar JSON.
  • Hash it immediately and record the hash: sha256sum evidence.jpg. A second algorithm costs nothing and pre-empts an argument.
  • Set the original read-only, store it unmodified, and do all work on copies. Name derivatives so the transform is legible: evidence_crop-sign.png, evidence_flop.jpg.
  • Record provenance of your own acquisition: the URL, the timestamp you fetched it, who gave it to you, and the platform it came from. Archive the source page before it changes.
  • Note whether the file is an original capture, a platform re-encode, or a screenshot. This single fact determines which later tests are valid at all, and you will need it in the report.

Done when the original is hashed, read-only, and its acquisition path recorded, and every subsequent step is operating on a named copy.

Step 3 — Metadata

Run secrets-in-file-metadata before any transformation. Cropping, rotating, upscaling or even opening the file in some editors rewrites tags.

Prioritise: GPS coordinates and GPSHPositioningError; GPSImgDirection, which gives you the camera's bearing and lets you reproduce the exact view; GPSDateStamp/GPSTimeStamp in UTC as the only timezone-anchored clock; the timestamp triplet; device make, model and serial; the software chain; and the embedded thumbnail for comparison against the main image.

If GPS is present you have a lead, not an answer. It is a writable field. Continue to step 5 and verify it visually; a metadata coordinate that a visual check confirms is a far stronger finding than either alone.

Done when metadata is extracted and recorded, or confirmed absent — and you have written "no EXIF present" rather than "EXIF removed".

Step 4 — Provenance

Run find-the-original-image. For video, extract keyframes first and search several of them.

You are looking for an earlier appearance, a different caption, a photographer credit, and a date you can corroborate independently through read-deleted-pages. Open the match pages and read them — the caption on the earliest copy frequently names the place outright, which collapses steps 5 and 6 into a verification exercise instead of a search.

If the media is older than the claim, or from a different country than the claim, you have your answer and it is a stronger answer than a coordinate.

Done when you have either an earliest-known publication with its date and caption, or a documented null across at least three engines including crops and a mirrored search.

Step 5 — Visual geolocation

Run geolocate-from-pixels. Inventory clues before searching, rank them by geographic specificity, fix the country from language, plates, driving side and road markings, then narrow to a site and confirm in satellite and street-level imagery.

If step 3 gave you coordinates, do this anyway as an independent test rather than navigating straight to the coordinate and confirming what you were told. Use GPSImgDirection to reproduce the camera bearing and check that the view matches what a camera at that position pointing that way would see. A bearing that points at a blank wall means the coordinate is wrong.

Done when you have a candidate location with a stated radius and a written list of the specific features you matched — or a documented region-only result with the reason you could not narrow further.

Step 6 — Chronolocation

Still in geolocate-from-pixels, using its chronolocation reference. Shadow azimuth for the sun's bearing, shadow-length ratio for its elevation, then solve against a sun-position calculator for the confirmed location. Expect two date bands, not one, and break the tie with foliage, snow, crop stage, or a dated object in frame. Corroborate against a weather archive and note which station you used and how far away it is.

Reconcile the result against the metadata timestamps from step 3. Agreement between an unanchored EXIF datetime and an independently derived sun position is one of the strongest corroborations available in this whole workflow, because the two have no common failure mode.

Done when you have a time-of-day range and a date band, each graded, with the discriminator you used named — or an explicit statement that the date remains two-banded.

Step 7 — Authenticity

Run is-this-photo-real. At minimum: the physical-consistency checks — shadow convergence across multiple objects, reflection geometry, perspective and scale — and the internal-consistency sweep against your own step 5 findings.

The specific failure this step is here to catch: you have just geolocated a scene that was assembled from two photographs, or generated. A composite geolocates beautifully and means nothing. If shadow convergence fails or an element carries no optical signature, your location finding applies to the background plate only, and you must say so.

Done when manipulation and synthesis are assessed, each graded, with signal-level tests either run or explicitly marked invalid for the copy you hold.

Step 8 — Decide whether the claim is corroborated

Lay the independent lines of evidence side by side and ask what agrees.

The standard: three mutually independent non-transient features matching reference imagery makes a location. Independence is the requirement people fudge. Three photographs of the same sign is one feature. A building footprint, a utility pole line and a ridgeline profile are three. Metadata GPS plus a visual match plus a sun-position-consistent shadow are three, and they are independent because forging all three coherently is hard.

Then run the falsification test you should have written in step 5: name the single observation that would kill your candidate, go look for it, and record that you did. A finding nobody tried to break is not a finding.

Grade the composite honestly:

  • Confirmed — three independent features align, the falsification test was run and failed to break it, and no line of evidence contradicts another.
  • Probable — two independent features, or three with one resting on undated or low-resolution reference imagery.
  • Region only — country or province established, no site. A respectable result.
  • Excluded — you can affirmatively rule out the claimed location. Needs only one hard contradiction, and is often more useful than finding the true site.
  • Unresolved — say so. An honest gap beats a confident guess that gets rebutted.

Done when each of location, time and authenticity carries a grade and the evidence it rests on, and any contradiction between lines of evidence is stated rather than reconciled away.

Step 9 — Express the finding

  • Coordinates plus a radius in metres, always. A bare six-decimal coordinate claims sub-metre precision you do not have. Derive the radius from what actually bounds you: GPSHPositioningError if the finding rests on metadata, the resolution of the reference imagery if it rests on a satellite match, the size of the area consistent with your matched features if it rests on visual work.
  • Camera position and bearing, separately from the subject's position. These are different places and reports routinely conflate them.
  • Time as a range in local clock time, saying whether you converted from solar time and what offset you applied.
  • Date as one or two bands, naming the discriminator that dropped the second — or reporting both if nothing did.
  • The specific features you matched, listed, with links to the reference imagery and its capture dates.
  • Your assumptions: assumed object heights, ground flatness, which reference bearing you used, which weather station.
  • Apply the publication floor from step 1. If it says region-only, round the coordinate before it leaves your notes, not after someone asks.

Done when the finding is written with a radius, a grade, its matched features and its assumptions, at the precision step 1 authorised.

Step 10 — Handoff

Run write-the-intel-brief with the graded findings, the evidence chain, the hashes from step 2, and the archived reference links.

New selectors this workflow produces, and where they go: business names and municipal bodies to x-ray-a-company; phone numbers from signage to whose-number-is-this; domains on signs or vehicles to who-owns-this-domain; named or credited individuals to find-anyone; posting accounts to hunt-a-handle and pattern-of-life-from-socials; aircraft or vessels in frame to track-planes-and-ships; several related locations to graph-the-network.

Done when the brief is delivered, the case file retains the original hash and the derivative chain, and data you no longer need for the stated objective is deleted.

来源与署名

来源:useosint/skills位于skills/where-was-this-taken提交06243a5

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架

更多来自 useosint/skills 的技能

Write The Intel Brief

useosint

Turn findings into a defensible intelligence product — BLUF key judgements, standardised estimative probability language, per-claim sourcing with timestamps and archived copies, separated observation, inference and assessment, documented negative findings and gaps, chain of custody and hashing, and redaction of uninvolved parties. Use when writing an intelligence report, due-diligence memo, evidence pack or executive summary, or when asked to write up an investigation so it survives challenge. Applies to regulated compliance reporting, litigation and disclosure, board and investment committee reporting, and law-enforcement referral. Reference at useosint.com/skills/write-the-intel-brief.

待分类2026年10月8日

X Ray A Company

useosint

Corporate due-diligence workflow — resolve a brand or website to its registered legal entity, map group structure and beneficial ownership, profile officers and directors, enumerate the digital estate, and screen litigation, insolvency, procurement, sanctions, PEP and adverse media. Use when asked to check out, vet or research a company, verify a supplier or counterparty before signing or paying, or assess whether a business is real. Applies to vendor and third-party risk, KYC and KYB onboarding, M&A and investor diligence, procurement integrity, and shell-company assessment. Reference at useosint.com/skills/x-ray-a-company.

待分类2026年10月8日

Whose Number Is This

useosint

通过 E.164 规范化、线路类型与运营商查询、应用注册检查及反向查询来源来调查电话号码。

Research & Analysis2026年10月8日

Who Owns This Domain

useosint

Establish who registered and who operates a domain using WHOIS, RDAP and DNS. Use when running a whois lookup, querying RDAP, digging A, AAAA, MX, NS, TXT, SOA or CAA records, reading SPF includes, DKIM selectors or DMARC rua addresses, finding the registrar, registrant or nameservers, doing reverse DNS, PTR, ASN or netblock lookups, or hunting historical WHOIS and passive DNS. Applies to phishing and brand-abuse takedown, domain-dispute and UDRP evidence, vendor verification before payment, and infrastructure attribution. Reference at useosint.com/skills/who-owns-this-domain.

待分类2026年10月8日

Who Really Owns It

useosint

Research companies, directors, shareholders and ultimate beneficial ownership in official corporate registries, filings and offshore datasets — OpenCorporates, UK Companies House and the PSC register, SEC EDGAR, US Secretary of State registries, EU business registers, GLEIF LEI records, OpenOwnership, OpenSanctions and the ICIJ Offshore Leaks database. Use when asked who owns or controls a company, to find a person's other directorships, or to unpick a group structure. Applies to KYB and UBO verification, AML and sanctions screening, nominee and shell-company detection, procurement integrity, and M&A diligence. Reference at useosint.com/skills/who-really-owns-it.

待分类2026年10月8日

Track Planes And Ships

useosint

解析飞机与船舶标识,并解读 ADS-B 与 AIS 追踪数据以支持调查。

Research & Analysis2026年10月8日