Only the first is defensible. Understanding how to enhance CCTV footage properly – and where that shades into fabrication – is the single most useful thing an investigator can learn about video evidence, and it builds directly on the acquisition and authentication discipline covered in our practitioner’s guide to forensic video analysis.
The rule that governs everything
Forensic enhancement clarifies information that is already present in the recording. It does not create new information.
A frame contains a fixed amount of captured detail. Processing can redistribute contrast so that detail becomes visible to the eye, correct distortions introduced by the lens or the compression, or combine multiple frames that each captured slightly different samples of the same scene. All of these operate on data that was genuinely recorded.
Generative upscaling does something categorically different. It looks at a low-resolution face, consults what faces generally look like, and synthesises a high-resolution face consistent with the blur. The result is sharp, convincing and evidentially worthless. It is a model’s inference about what a person might look like, presented in the visual language of a photograph.
Courts are increasingly alert to this. Present a generatively upscaled face as evidence and you are not merely risking exclusion of that image; you are handing defence counsel a reason to question every other technical exhibit you have produced.
Before you process anything
Work from the best available source. Enhancement applied to a WhatsApp-forwarded copy of a screen recording of a DVR monitor cannot recover what those three generations of loss destroyed. Go back to the DVR and export natively. The single largest quality gain available in most cases comes from acquisition, not processing.
Hash the file and work on a copy. Record the hash in your documentation before the first operation.
Check the frame rate and the compression. Heavily compressed footage carries blocking artefacts that several enhancement operations will amplify into features that look like real detail. Knowing the codec and bitrate tells you which operations are safe.
How to enhance CCTV footage: the defensible steps
Contrast and level adjustment
Under-exposed or washed-out footage often contains far more detail than a monitor displays. Adjusting levels, gamma and local contrast redistributes what was captured into a visible range. Nothing is added. This is the highest-yield operation in routine casework and the least controversial.
Frame averaging and multi-frame integration
Where a subject or scene is static across several frames, combining those frames reduces random sensor noise and can meaningfully increase legible detail – most usefully on number plates and static text. Each frame captured a slightly different noise pattern over the same underlying signal; averaging suppresses the noise and reinforces the signal.
This is genuine super-resolution in the forensic sense, and it is defensible precisely because every contributing pixel came from the recording.
Deblurring by deconvolution
Where blur was caused by a known, modellable process – uniform motion in one direction, or a specific defocus – a deconvolution filter can partially reverse it. The key word is modellable. Applied with a correctly estimated point spread function, deconvolution recovers real detail. Applied blindly with aggressive parameters, it generates ringing artefacts that an untrained eye reads as characters on a number plate.
Geometric and lens correction
Wide-angle and fisheye cameras distort geometry substantially. Correcting for known lens characteristics is necessary before any measurement – subject height, vehicle position, distance – and is straightforward to document.
Stabilisation
Camera shake across frames can be corrected by registration. This helps both human viewing and subsequent multi-frame operations.
Frame extraction and interlacing correction
Older analogue systems record interlaced fields. Extracting and correctly de-interlacing fields can double the effective temporal resolution of a sequence, which matters when the decisive event lasted a fraction of a second.
Steps that will damage your case
Generative upscaling and AI face restoration. Already covered, and worth repeating because consumer tools now market these as one-click features. If a tool can produce a sharp face from an eight-pixel-wide head, it is inventing.
Sharpening applied repeatedly until something appears. Iterative sharpening creates edges. Given enough passes, an examiner can produce almost any character sequence on a number plate. This is the mechanism behind a large share of misidentifications.
Any processing without a log. An operation you cannot reproduce is an operation you cannot defend. If your tool does not record parameters automatically, record them manually.
Processing the original. Obvious, routinely violated.
Setting expectations honestly
There is a hard information limit. If a face occupies twelve pixels of width, no processing recovers identity, because the identifying detail was never sampled. If a number plate is illuminated to saturation by headlights, the characters were not recorded and cannot be retrieved.
Telling an investigating officer this early is more valuable than producing an ambiguous image that sends a team down a wrong line of inquiry for three weeks. The professional answer to an unrecoverable image is that it is unrecoverable.
Where footage is genuinely marginal, the productive move is usually lateral rather than technical: find another camera. A subject unidentifiable in one frame is frequently identifiable two cameras earlier, and modern video analysis platforms are far better at locating that second camera view than at rescuing the first. For the pixel thresholds that govern what is and isn’t recoverable, see our guide to identifying persons from low-resolution CCTV.
Documenting the work
A defensible enhancement record contains the source file and its hash, the tool and version, every operation in order with its parameters, the output and its hash, and a plain-language statement of what the processing was intended to achieve and what it does not establish.
That last sentence – the statement of limits – is what separates an examiner’s exhibit from an investigator’s screenshot.



