Recording every camera continuously at full quality consumes enormous storage — a single high-resolution camera with a frame rate of 20-30 FPS (frames per second) can generate tens of gigabytes per day, and a facility may run dozens of cameras. To manage this, most systems are configured for event-based recording; they record only when something they consider an “event” occurs. By far the most common trigger is motion detection.

This single design decision has a consequence that matters enormously in litigation: gaps in recorded footage are a normal, expected artifact of a motion-triggered system. Whether a particular gap reflects tampering or simply reflects how the system was configured is a technical question — one that can be answered by examining the digital video evidence or the original system through generating exemplar (sample) recordings. These exemplar recordings aid in establishing ground truth, an accurate known sample for analysis.

Figure: Continuous recording vs. event-based (motion-triggered) recording.

How Motion Detection Actually Works

A camera does not “see” motion the way a person does. Motion detection is a mathematical comparison: the system examines successive video frames and measures how much the image has changed from one frame to the next. For example, in the Milestone XProtect platform — the VMS at the center of the case study that follows — this analysis happens on the recording server, not in the camera. 

The camera streams video continuously to the server; the server decodes that stream, compares frames, and decides whether “motion” has occurred. This is an important architectural point: the settings that determine whether an event gets recorded live are in the server’s configuration (the Management Client), and a misconfiguration there affects recording regardless of how well the camera performs.

When the server compares frames, the answer to these two questions determines whether it declares motion:

Pixel Changes

Question 1: Did a given pixel change?

Digital video is inherently noisy. Compression artifacts, sensor grain, and subtle lighting shifts cause pixel values to fluctuate constantly even in a completely static scene. The sensitivity setting defines how much an individual pixel's value must change before the system treats it as a genuinely changed pixel rather than noise. Milestone can manage sensitivity automatically or allow it to be set manually per camera.

Motion

Question 2: Did enough pixels change to count as motion?

Once the system knows which pixels changed, it counts them. The threshold setting defines how many changed pixels are required — in effect, how large a disturbance in the image must be — before the system declares a motion event and triggers recording. These are two separate controls, and conflating them is one of the most common mistakes in discussing these systems.

A camera can be perfectly sensitive at the pixel level and still fail to record a person walking through the scene — if the threshold demands that more of the frame change than that person’s movement actually produces. Picture a wide-angle camera covering a large parking lot: a person crossing at the far edge of the view may occupy well under one percent of the image. If the threshold is set above the amount of change that person generates, the system will conclude, mathematically and consistently, that nothing happened.

Figure: How the recording server evaluates sensitivity and threshold before declaring a motion event.

Other Settings That Shape What Gets Recorded

Pre-buffer and post-buffer. When motion triggers recording, the system can prepend a few seconds of video captured immediately before the trigger (temporarily held in memory) and continue recording for a set period after motion stops. These buffers are configurable. If the pre-buffer is short or disabled, recordings begin abruptly when the threshold is crossed — which, to a lay viewer, can look as though the footage was “cut” mid-action.

Figure: Pre-buffer and post-buffer windows around a motion-triggered recording event.

Example: What Miscalibration Looks Like in the Footage

Each configuration error leaves a characteristic signature:

Why Configuration Gaps Get Mistaken for Manipulation

To someone reviewing exported video, the symptoms of miscalibration and tampering can look identical: the recording jumps from one timestamp to another; an event everyone knows occurred appears nowhere in the footage; a clip begins jarringly in the middle of the action. Absent technical context, “someone edited this” is an understandable inference.

A forensic examination distinguishes the two by first asking a different question. Not who removed the footage? — but was the footage ever recorded?

Answering it means going to the system rather than the exported clips: reviewing the VMS configuration (the actual sensitivity, threshold, buffer, and rule settings in effect), examining the system’s logs, checking the stored video database for internal consistency, and — where possible — testing the system’s live behavior against its configured values to demonstrate exactly what level of activity it does and does not capture.

Often, in civil litigation, the absence of recorded evidence in specific regions of a video recording can lead to spoliation claims by either side. In the following case study, we will walk through a great example of how this type of argument can unfold and, ultimately, how it can be defeated using forensic video analysis.

Case Study: Authentication Request

The central dispute concerned the authenticity of two digital video recordings in a proprietary format. The claim in question was that these videos may have been manipulated or edited, potentially undermining their reliability as evidence in a regulatory or legal context. This challenge was advanced by external parties (a federal investigator), who questioned whether the recorded events accurately reflected what occurred in real time—specifically, whether the footage had been altered, tampered with, or artificially constructed.

Primeau Forensics received a request to evaluate several proprietary video recordings, including the proprietary player, to determine whether they could assist in evaluating this evidence. The focus of the request was to determine if opinions regarding tampering could be made solely from the analysis of the proprietary video recordings.

Opposing Theory

The opposing theory, as implied by the investigation’s objective, was that the video evidence may have been manipulated or edited, particularly due to observable anomalies such as sudden jumps or playback disruptions. The underlying concern was that these anomalies could indicate post-recording editing, selective recording, or system misconfiguration used to conceal or distort events. The theory was not based solely on visual artifacts but rested on the broader assumption that digital video evidence from the VMS (video management system) lacked verifiable integrity, given the absence of documented controls and the potential for human error in handling.

Forensic Methodology

In any investigation where questioned recordings are suspect to manipulation, examination of the evidence to determine if the methodology can be applied is the first step. From there, a testing plan to evaluate the validity of the opposing theory is established. This type of testing plan should apply a structured, standards-based forensic approach rooted in the SWGDE Best Practices for Digital Video Authentication 23-V-001 as follows: 

Assess the Request

Once an examiner has evaluated the request, they should determine whether an authentication examination is suitable for answering the requestor’s questions. In some cases, multiple types of authentication examinations may be needed to address the request. If no suitable examination can address the request, inform the requestor of the findings. The requestor can then modify the request, or submit a request for a different examination.

Once a determination of which questions regarding the video’s authenticity can be made, the examiner should develop a plan, obtain reference videos, and prepare the questioned video for analysis. Assess and document the technical attributes of the video. Follow your evidence-handling standard operating procedures if testing an evidence device is necessary.

NOTE: Some digital/network recording systems can export configuration parameters to retain the evidence device’s configuration state.

If device classification or identification is the primary objective, exemplar files may need to be generated for comparison. Video samples produced by the testing equipment may be exported and acquired using various methods. Evaluation of all possibilities, including double encoding, direct downloading, sharing, or other acquisition methods from these devices, will ensure the most accurate results. 

If device classification or identification is the primary objective, exemplar files may need to be generated for comparison. Video samples produced by the testing equipment may be exported and acquired using various methods. Evaluation of all possibilities, including double encoding, direct downloading, sharing, or other acquisition methods from these devices, will ensure the most accurate results. 

Video Authentication Process

For this type of authentication request, the most accurate approach for an expert in a civil case is to test the theory and ultimately determine if it can be disproved. Creating sample recordings for comparison with the evidence is the most accurate approach. 

A site inspection was recommended, and samples were generated. It is important to confirm with the IT team that the VMS and the IP Cameras had not been changed; thus, sample testing could proceed. The inspection utilized several areas of video forensic methodology. 

Preliminary Digital Analysis

The initial assessment focused solely on digital characteristics within the video files, including metadata, file structure, and visual anomalies (e.g., “jumping” in playback). The jumping was consistent with motion-triggered recording behavior, in which the system engaged and disengaged based on motion detection, inconsistent with editing or tampering. This outcome was evaluated using the Milestone XProtect proprietary player and its manual—an example of motion detection within the Milestone XProtect Smart Client, shown in the image below. 

The green boxes provide a magnified view of the video's timeline on 5/1/2019, highlighting the red blocks that indicate motion-triggered recording events and the standard unrecorded gaps between them.

Exemplar Testing

It was noted that there was evidence supporting pre- and post-event motion activation in the video evidence within the proprietary player. The motion detection threshold was tested by generating samples using the default sensitivity threshold of the IP cameras used to capture the evidence. Through testing minimal movements throughout the space, they were deemed insufficient to arm based on the default motion sensitivity thresholds. In other words, if the movement observed from the camera through the VMS software was not considered high enough, although to the human eye it may have seemed high enough, the threshold wasn’t satisfied. Thus, the encoder didn’t arm to record the events. 

Comparative Analysis of Motion Data

The examiner on this investigation, Michael Primeau, compared the evidence recordings with control samples (pink pre- and post-motion data exemplars). The absence of pink data in the evidence recordings was evaluated for consistency with the exemplars. Thorough sampling from the surveillance system and IP camera was completed to assess whether technical configurations (e.g., motion recording, resolution, compression, FPS) could explain the anomalies without implying manipulation.

Results

Each element of the opposing theory was tested and evaluated against specific evidence:

Figure: Opposing theory claims mapped against the forensic findings that addressed each one.

Claim 1: "The video shows signs of editing or manipulation."

Disproved by an evaluation of the proprietary player, evidence of pre-buffer and post-buffer time periods (motion sensitivity thresholds). No evidence of 3rd-party editing software or tools commonly used to edit or manipulate evidence can be present within a Milestone proprietary video encoding format.

Claim 2: "The 'jumping' in the video is evidence of editing." → Contradicted by motion detection analysis.

The jumping behavior was found to be consistent with motion recording system behavior. It was explained as the result of motion-only recording programming, where the recorder activates only when motion is detected and deactivates when motion stops. This is a known, documented feature of many surveillance systems and does not indicate post-recording manipulation.

Conclusion

The investigative argument concludes that the video evidence extracted from the system is authentic and not manipulated or altered. The opposing theory, that the footage was edited or tampered with, was ultimately inaccurate. This was achievable through generating and comparing samples from the same camera and VMS system with the evidence, using forensic video analysis.

It was explained that the abruptness of movement of subjects within the FOV (Field of View) was due to a limitation of the motion detection sensitivity threshold within the VMS system, ultimately set in a default configuration. The default configuration limited the system’s ability to detect and record consistent human movement within the XML Sitemap.

The video evidence, when evaluated through a peer-reviewed, widely acceptable forensic process, supports the conclusion that the events were recorded as they occurred, with anomalies arising from system design rather than manipulation. This conclusion strengthens the evidentiary value of the recordings. It underscores the importance of adhering to SWGDE best practices, including proper documentation, training, and system audits, to prevent future challenges to digital evidence.

Defend Your Evidence with Scientific Rigor

Unexplained gaps or jumps in surveillance footage can quickly derail a legal strategy if left to assumption. If you are facing challenges regarding the authenticity or integrity of digital video evidence, Primeau Forensics can help. Our forensic experts apply widely accepted, SWGDE-compliant methodologies to establish the ground truth of your multimedia evidence, delivering unbiased analysis and trial-ready testimony that withstands the highest levels of courtroom scrutiny.