# Sherloq: an open source image forensics toolset for inspecting traces yourself

> Sherloq is a digital image forensic toolset by Guido Bartoli, licensed GPL-3.0, with a Qt GUI and a long list of analysis modules. It is an educational workbench, not a verdict machine, and the README says so plainly.

**GuidoBartoli/sherloq** — An open-source digital image forensic toolset

- Repository: https://github.com/GuidoBartoli/sherloq
- Stars: 3,217 · Forks: 315
- Language: Perl
- License: GPL-3.0
- Published: 2026-09-24 · Updated: 2026-09-24 · Language: en
- Canonical page: https://hysenlabs.com/projects/guidobartoli-sherloq

## What Sherloq is for, and who it is not for

Sherloq is a personal research project that implements an integrated environment for digital image forensics. The README quotes the Scientific Working Group on Imaging Technologies definition of the field, which covers photogrammetry, photographic comparison, content analysis and image authentication. The stated purpose is narrower than that list suggests: Sherloq is a companion for experimenting with algorithms from recent research papers and workshops, not a tool that decides whether an image is forged. The author writes that such an automatic tool probably will never exist, which is a useful thing to read before downloading anything.

The audience follows from that. It suits engineers, students and researchers who want to run error level analysis, wavelet decomposition or PRNU identification on a file and look at the output themselves. It also suits people who cannot get access to commercial forensic suites, which the README describes as expensive and often restricted to law enforcement and government agencies. The author argues against security by obscurity in forensic services, and positions an open toolset as the alternative.

It does not suit anyone who needs a defensible yes or no answer from a single button. Nothing in the description promises that, and the README explicitly frames the repository as a way to track development of an educational tool rather than to distribute a finished product. Expect bugs, unpolished code and missing features, in the author's own words.

## The architecture: a Python GUI over a set of independent analysis modules

The current incarnation is a Python application built on PySide2, Matplotlib and OpenCV, according to the history section. That is the third rewrite. A 2015 version was a C++11 command line utility built with CMake against OpenCV, Boost and AlgLib. A 2017 version added a Qt multi-window GUI compiled with Qt 5 and OpenCV 3. The 2020 port moved everything to Python for easier development and deployment, and the README describes this as likely the final form unless someone volunteers to build a web application.

The repository layout matches that story. The top level holds sherloq.py, a gui directory, a docs directory, logo and screenshots directories, a LICENSE and a .python-version file. The single entry point plus a gui package suggests the analyses are launched from a shared shell rather than as separate command line programs. The feature list is organised by category: general, metadata, inspection, detail, colors, noise, JPEG, tampering and various. Each category contains named tools such as File Digest, Thumbnail Analysis, Luminance Gradient, PRNU Identification, Quality Estimation and Copy-Move Forgery.

One structural detail matters more than the rest. The README marks functions that are not yet implemented in italics inside the program, and the feature list itself is described as what the toolkit will provide once beta stage is reached. So the list is partly a roadmap. A module appearing in the README is not proof that it runs in the code you clone.

## Installing Sherloq and opening a first image

The README has an Installation section in its table of contents, but the portion available here does not include the commands. What can be confirmed from the repository is the shape of the project: sherloq.py at the top level, a gui package beside it, and a .python-version file indicating the interpreter version the author develops against. The README does not document a package manager install, a container image or a release archive, and there are no retrieved releases.

So the realistic path is to clone the repository and run the entry point with a Python interpreter that satisfies the dependencies named in the history section: PySide2, Matplotlib and OpenCV. Check the .python-version file first, because it records the version the project expects.

```bash
git clone https://github.com/GuidoBartoli/sherloq.git
cd sherloq
cat .python-version
python sherloq.py
```

The first two commands put you in the project directory and print the expected interpreter version. The third starts the GUI. If PySide2 or OpenCV are missing from your environment, the application will fail at import time rather than showing a helpful dialog, and the README does not describe a dependency manifest to install from. That is the main friction point of the setup.

Once the window opens, load an image. The README lists the supported formats as JPEG, PNG, TIFF, BMP, WebP, PGM, PFM and GIF. A sensible first analysis for a JPEG is Quality Estimation, which the README says extracts quantization tables and estimates the last saved quality. Run it, then export the result, since the README states both visual and textual results can be exported. Comparing the quantization tables of two files from the same camera is a good way to learn what the module actually reports before trusting it on a disputed image.

## Where the toolkit breaks down, and when to reach for something else

The most honest limitation is written into the introduction. Sherloq does not decide whether an image is forged. Every module produces a visualisation or a statistic that a human has to interpret, and interpreting compression artifacts or noise residuals requires knowing what the algorithm does. A user who cannot explain why an error level analysis map looks the way it does will get nothing from it.

The second limitation is completeness. The feature list is aspirational in places, and the README says italics inside the program mark functions that are not yet implemented. Because the port to Python is described as just begun in the history section, with previous code still to be moved over, some tools that worked in the C++ or Qt versions may be absent or partial in the current tree. The README does not say which ones, so the only way to know is to try each module.

The third is the deployment story. There is no documented package, no container, and no release artefacts. Dependencies are named in prose rather than pinned in a manifest, which means two machines can end up with different OpenCV or PySide2 versions and different behaviour. For a tool whose outputs are pixel-level visualisations, that is a real reproducibility problem. If you need a maintained, scriptable pipeline with pinned dependencies, a general image processing library plus your own scripts will be more predictable than a GUI workbench whose module set is still in flux.

## How it compares to reading the algorithms out of papers yourself

The obvious alternative is not another forensic GUI. It is implementing the specific test you need on top of OpenCV or scikit-image, using the same papers Sherloq draws from. The difference is control. A hand-written script for JPEG ghost maps or resampling detection gives you fixed parameters, a fixed input path and an output you can diff between runs. Sherloq gives you an interactive viewer with real-time pan and zoom, a multi-window layout so several analyses sit side by side, and a magnifier with enhancements for spotting forgery cues. That interactivity is the product, and it is genuinely hard to replicate in a script.

The trade-off runs the other way too. A script is testable, reviewable and cheap to rerun on a hundred files. Sherloq is a GUI, so batch work is not what it is built for, and the README does not describe a command line or an API for driving analyses programmatically. If your task is to triage a folder of images, the interactive environment is the wrong shape. If your task is to understand what a single suspicious image contains, the interactive environment is exactly the right shape, because you can flip between the original, the histogram, the bit planes and the noise residual without writing glue code.

A second alternative is a commercial forensic suite. The README's own argument against them is price and restricted access rather than capability. It does not claim Sherloq matches them feature for feature, and given the beta-stage caveat, it should not be read that way.

## Maintenance, licensing and what an upgrade actually costs

The repository is not archived, and the last push was on 2026-07-16. That is recent enough that the project is not abandoned, but the README's framing as a personal research project matters more than the push date when you plan around it. There is no retrieved release, so there is no version number to pin and no changelog to read before upgrading. An upgrade means pulling the master branch and accepting whatever changed since your last pull.

That has a practical consequence. Because the feature list is partly a roadmap and the Python port is described as incomplete, a pull can change which modules work. If you depend on a specific analysis, keep a copy of the tree you validated and record the commit you validated it at, since the project does not provide releases to anchor to.

On licensing, Sherloq is GPL-3.0. That is a copyleft licence, and it matters if you intend to embed the toolkit in something you distribute. The README also invites contributions and code improvements, which is consistent with the licence. It does not offer any statement about commercial use, support or warranty, and nothing here should be read as legal advice. If you plan to ship a product that includes Sherloq code, have someone qualified review the GPL-3.0 obligations for your distribution model before you build on it.

## Conclusion

Adopt Sherloq if you want to inspect compression history, noise patterns and resampling traces interactively and you are comfortable reading the code when a module misbehaves. Do not adopt it expecting a verdict on whether a photo is forged; the README states it is not an automatic decision tool. Before relying on it in any formal setting, verify which modules are actually implemented in the current tree, since the feature list marks several functions as not yet implemented, and check the GPL-3.0 obligations against how you intend to distribute anything you build on top of it.

## FAQ

### What is Sherloq used for?

It is an open source digital image forensic toolset for experimenting with algorithms such as error level analysis, wavelet thresholding, PRNU identification and copy-move forgery detection. The README states it is not an automatic tool that decides whether an image is forged, but a companion for trying algorithms from research papers.

### Where can I find the Sherloq source code?

The project is hosted on GitHub under GuidoBartoli/sherloq, with the default branch named master. The top level contains sherloq.py, a gui directory, docs, a LICENSE and a .python-version file.

### What image formats does Sherloq support?

The README lists JPEG, PNG, TIFF, BMP, WebP, PGM, PFM and GIF. The interface is described as a Qt-based GUI with multiple tool window management and a viewer with real-time pan and zoom.

### Are all the tools in the Sherloq feature list implemented?

No. The README says functions displayed in italics inside the program are not yet implemented, and describes the feature list as what the toolkit will provide once beta stage is reached. The Python port is also described as just begun, with previous code still to be moved over.

### What language and libraries is Sherloq built with?

The current version is written in Python using PySide2, Matplotlib and OpenCV, according to the README's history section. Earlier versions were a C++11 command line utility and a Qt 5 GUI built with OpenCV 3.

### What licence does Sherloq use?

Sherloq is licensed under GPL-3.0. The README invites contributions and code improvements, and does not state any separate commercial licensing terms.

## Sources

- [GuidoBartoli/sherloq on GitHub](https://github.com/GuidoBartoli/sherloq)
- [Issues](https://github.com/GuidoBartoli/sherloq/issues)
- [License: GPL-3.0](https://github.com/GuidoBartoli/sherloq/blob/master/LICENSE)
- [README](https://github.com/GuidoBartoli/sherloq/blob/master/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/guidobartoli-sherloq
