SIH26150 · NTRO · Multi-vendor DVR/NVR forensics

Every frame traced to the bytes it came from.

Sarvadristhi reads recorder disks, USB sticks and exports from any brand, recovers deleted and overwritten footage, puts every camera on one clock, and seals a replayable, custody-logged record a court can check.

RTX 4050
Running Sarvadristhi needs an NVIDIA RTX 4050 GPU (6 GB, CUDA 12.8) on a Windows 11 laptop. This site runs nothing: it is a read-only showcase of every recorded run, report and result, so you can see the entire output here.
8 / 8
planted manipulations caught
12,004
frames recovered, 3 seized items
3 of 3
evidence hashes unchanged
14 / 14
clips rebuilt from the bytes (replay)
44%
AI activity recall, shown honestly

One run, three seized items, eight planted manipulations

A Hikvision-format recorder, a Dahua-format recorder and a USB stick, holding real footage from six surveillance cameras. We poisoned them on purpose and didn't tell the tool.

P1
Recorder formatted after the incident: the recorder's own log says HDD Initialize 16:58:06
P2
Footage overwritten after the format: 4,900 frames recovered beyond the index
P3
Camera clock set back 15 minutes mid-recording, located between 16:52:01 and 16:52:07
P4
Camera clocks drift: +47 s, −312 s, +12 s, measured per camera
P5
Dahua disk partly overwritten: a torn frame at the boundary
P6
Export deleted from the USB: recovered intact, the only surviving copy of 41 s
P7
Export edited: 6.0 s removed (16:51:25–16:51:31), located frame by frame
P8
Video disguised as a text file: maintenance_log.txt is an MP4

Explore the full results

This is the real workbench, opened on the recorded run. Every screen works; actions that would run the system are switched off.

Every recorded run

The same evidence was analysed more than once on the GPU laptop. Each run's custody chain was re-verified when this site was built.

RunEvidenceCaughtFramesCustodyReport
Loading…

How it works

Twelve stages, each written to a hash-chained custody ledger.

01
Acquireimage + MD5 / SHA-256
02
Identifyformat from bytes
03
Recoverindex, carving, deleted files
04
Attributecamera and time
05
Clocksdrift, clock change
06
Clipsexport + hash
07
Provenanceexports vs recorder
08
L1 Motionwhen it moves
09
L2 PerceptionRF-DETR, tracks, faces
10
L3 VLMQwen3-VL, cross-checked
11
L4 Contextlinks, rules, activities
12
ReportPDF, s.63(4) data sheet

Run it yourself

  • Windows 11 laptop with an NVIDIA RTX 4050 GPU (6 GB, CUDA 12.8)
  • Python 3.12, FFmpeg, Tesseract, Ollama with Qwen3-VL 4B: installed by scripts\setup_windows.ps1
  • Then scripts\run_demo.ps1 and open http://127.0.0.1:8770: everything stays on the machine
  • No GPU? The Docker image runs on CPU (much slower for AI analysis)
Source on GitHub → Docker image (v0.1.0) →