Within Verify Claims
Can Metadata Rescue a Hacked UFO Claim?
Metadata cannot prove a UFO claim by itself, but it can reveal whether a file fits the system, date, software, and source being claimed.
On this page
- Hashes, dates, paths, and software traces
- How metadata can mislead
- What matching metadata still cannot prove
Page outline Jump by section
Introduction
Metadata cannot prove that a hacked file contains evidence of UFOs, secret spacecraft, or “non-terrestrial officers”. What it can do is test whether the file is consistent with the story being told about it. In cases associated with UFO-focused hackers such as Gary McKinnon, the public problem is that the alleged files themselves have generally not been released in a form that allows forensic examination. As a result, the claims remain largely anecdotal rather than independently verifiable. [WIRED]wired.comufo hacker tells what he foundWIRED'UFO Hacker' Tells What He FoundJun 21, 2006 — The search for proof of the existence of UFOs landed Gary McKinnon in a world of trou…
That makes metadata especially important. If an alleged NASA image, military spreadsheet, or database export were ever produced, investigators could compare its timestamps, software traces, directory paths, file structure, and cryptographic fingerprints against known characteristics of the systems it supposedly came from. Metadata cannot reveal whether aliens exist, but it can help determine whether a file plausibly originated where and when its advocates claim. [SWGDE - SWGDE+2NIST]swgde.orgBest Practices for Digital Video AuthenticationSWGDEBest Practices for Digital Video Authentication - SWGDEThe purpose of this document is to provide the background, technical…
Can Metadata Rescue a Hacked UFO Claim?
The strongest role of metadata is not to confirm extraordinary content but to test provenance: the history of a file’s creation, storage, modification, and transfer. Modern digital-forensic practice treats provenance as a central question because a file can be copied, renamed, edited, exported, or fabricated while retaining a convincing appearance. [SWGDE - SWGDE+2SWGDE - SWGDE]swgde.orgBest Practices for Digital Video AuthenticationSWGDEBest Practices for Digital Video Authentication - SWGDEThe purpose of this document is to provide the background, technical…
In a hypothetical UFO-related leak from a government network, investigators would ask:
- Does the file format match the software used at the claimed organisation?
- Do the timestamps fit the relevant mission, programme, or period?
- Does the directory structure resemble known system layouts?
- Do embedded properties identify expected authors, workstations, or applications?
- Is there evidence that the file passed through later editing tools before publication?
Each of these questions is testable in ways that a witness recollection is not. [NIST+2Fastio]nist.govprovenience based cross verification digital forensic artifacts applied ntfsProvenience-based cross-verification of digital forensic…by A Nelson · 2024 — This work focuses on a model of a file system where…
Hashes, Dates, Paths, and Software Traces
Hashes: The First Authenticity Check
A cryptographic hash is a mathematical fingerprint of a file. If investigators obtain multiple copies of an alleged UFO document, matching hashes indicate that the files are bit-for-bit identical. Different hashes indicate that something changed, even if the visible content appears the same. [SWGDE - SWGDE]swgde.orgSWGDEBest Practices for Maintaining the Integrity of ImageryIntegrity Verification: The process of confirming that the imagery pr…
In a hacked-UFO scenario, an early hash recorded immediately after acquisition would be valuable because it allows later copies to be compared against the earliest known version. Without that baseline, it becomes harder to determine whether alterations occurred before public release. [Fastio]fast.iometadata extraction for digital forensicsioMetadata Extraction for Digital Forensics in 2026 | FastioLearn how forensic investigators extract and preserve file metadata as ev…
Dates and Timeline Consistency
Creation, modification, and access times can reveal whether a file fits its claimed history. A spreadsheet supposedly viewed on a military network in 2001 but showing metadata generated by software released years later would immediately raise questions. Likewise, a document claimed to originate from one period but carrying traces of later editing activity may indicate copying, migration, or manipulation. [NIST+2Medium]nist.govprovenience based cross verification digital forensic artifacts applied ntfsProvenience-based cross-verification of digital forensic…by A Nelson · 2024 — This work focuses on a model of a file system where…
Timeline analysis is often more powerful when several files are examined together. Related files may show coordinated creation patterns, archive operations, backups, or user activity that either support or contradict the alleged narrative. [NIST]nist.govprovenience based cross verification digital forensic artifacts applied ntfsProvenience-based cross-verification of digital forensic…by A Nelson · 2024 — This work focuses on a model of a file system where…
Directory Paths and System Context
A filename alone provides little evidence. A complete path can be far more informative.
For example, investigators would want to know:
- The drive or server where the file resided.
- Parent folders and neighbouring files.
- User accounts associated with the file.
- Access permissions and ownership information.
- Links to databases, archives, or mission directories.
Digital-forensics research emphasises that a file’s metadata, directory placement, and stored contents form interconnected evidence. Removing the file from its original environment often removes much of the context needed to assess authenticity. [NIST]nist.govprovenience based cross verification digital forensic artifacts applied ntfsProvenience-based cross-verification of digital forensic…by A Nelson · 2024 — This work focuses on a model of a file system where…
Software and Application Traces
Many file types contain hidden information about the software that created or edited them. Documents may store author names, software versions, template identifiers, revision histories, and export settings. Images and videos can contain information about encoding tools, processing software, and file-generation workflows. [securitymagazine.com+3SWGDE - SWGDE+3SWGDE - SWGDE]swgde.orgBest Practices for Digital Video AuthenticationSWGDEBest Practices for Digital Video Authentication - SWGDEThe purpose of this document is to provide the background, technical…
If a purported NASA image contained metadata showing it was last saved by consumer editing software shortly before publication, that would not automatically prove fabrication. It would, however, create a new question about how the file moved from its claimed source to the released version. [SWGDE - SWGDE]swgde.orgBest Practices for Digital Video AuthenticationSWGDEBest Practices for Digital Video Authentication - SWGDEThe purpose of this document is to provide the background, technical…
How Metadata Can Mislead
Metadata often appears objective, but investigators treat it cautiously because it can be incomplete, altered, or misunderstood.
A common mistake is assuming that a timestamp records the moment a photograph or document was originally created. In reality, many timestamps record later events such as copying, exporting, uploading, or migration between systems. Moving a file between storage platforms can change some timestamps while preserving others. [LinkedIn]linkedin.comOpen source on linkedin.com.
Metadata can also disappear. Screenshots, social-media uploads, image recompression, and format conversions frequently strip embedded information. A dramatic image circulated online may therefore contain far less forensic value than the original file stored on the source system. [TrueScreen - Trust as a Service]truescreen.ioTrust as a ServiceHow to Preserve Digital Evidence for Court29 Mar 2026 — EXIF metadata (timestamp, GPS coordinates, device…
Another problem is intentional manipulation. Digital-forensics specialists have long recognised that timestamps and other metadata fields can sometimes be altered. This is why forensic analysis relies on multiple artefacts rather than a single property field. Independent traces from logs, directory entries, filesystem records, and related files are generally more persuasive than one timestamp viewed in isolation. [TrueScreen - Trust as a Service+2NIST]truescreen.ioforensic metadata acquisitionTrust as a ServiceDigital Evidence Preservation: Standards ComparedMay 15, 2026 — A file can be copied without leaving a tra…
A McKinnon-Specific Problem: Missing Artefacts
The metadata question becomes difficult when the alleged evidence is unavailable.
Gary McKinnon publicly described viewing what he believed was an unusual NASA image and a spreadsheet referring to “non-terrestrial officers”, but the public record does not contain original copies that can be examined. Without the files themselves, investigators cannot verify hashes, inspect embedded properties, reconstruct timelines, or compare metadata against known NASA or military systems. [IEEE Spectrum+3WIRED+3Wikipedia]wired.comufo hacker tells what he foundWIRED'UFO Hacker' Tells What He FoundJun 21, 2006 — The search for proof of the existence of UFOs landed Gary McKinnon in a world of trou…
This illustrates a broader lesson for hacked-UFO claims. Metadata analysis only becomes possible when the underlying artefact survives in a sufficiently original form. Once the evidence exists only as memories, interviews, descriptions, or retellings, the most valuable forensic tests become unavailable. [WIRED]wired.comufo hacker tells what he foundWIRED'UFO Hacker' Tells What He FoundJun 21, 2006 — The search for proof of the existence of UFOs landed Gary McKinnon in a world of trou…
What Matching Metadata Still Cannot Prove
Even a perfect metadata match would not establish that a UFO claim is true.
Suppose an alleged document displayed:
- Consistent timestamps.
- Plausible government directory paths.
- Expected software traces.
- A verifiable chain of custody.
- Matching cryptographic hashes across copies.
That would strengthen the case that the file is authentic as a digital artefact. It would not automatically validate the document’s contents. A genuine file can contain errors, misunderstandings, jokes, draft material, speculative analysis, or unconventional terminology. Authenticity and truth are separate questions. [SWGDE - SWGDE+2SWGDE - SWGDE]swgde.orgBest Practices for Digital Video AuthenticationSWGDEBest Practices for Digital Video Authentication - SWGDEThe purpose of this document is to provide the background, technical…
The most metadata can establish is that a file likely originated from a particular system, at a particular time, and followed a traceable path to the present. Determining whether the file’s claims actually describe extraterrestrial technology, secret spacecraft, or hidden programmes requires additional corroboration from records, witnesses, technical analysis, and independent evidence. Metadata may rescue a digital claim from pure anecdote, but it cannot carry an extraordinary UFO claim on its own. [SWGDE - SWGDE+3SWGDE - SWGDE+3SWGDE - SWGDE]swgde.orgBest Practices for Digital Video AuthenticationSWGDEBest Practices for Digital Video Authentication - SWGDEThe purpose of this document is to provide the background, technical…
Amazon book picks
Further Reading
Books and field guides related to Can Metadata Rescue a Hacked UFO Claim?. Use these as the next step if you want deeper reading beyond the article.
Guide to Computer Forensics and Investigations
Covers timestamps, artefacts and evidence validation.
Incident Response & Computer Forensics, Third Edition
Relevant to analysing file histories and logs.
Endnotes
-
Source: wired.com
Title: ufo hacker tells what he found
Link: https://www.wired.com/2006/06/ufo-hacker-tells-what-he-found/Source snippet
WIRED'UFO Hacker' Tells What He FoundJun 21, 2006 — The search for proof of the existence of UFOs landed Gary McKinnon in a world of trou...
-
Source: Wikipedia
Title: Gary Mc Kinnon
Link: https://en.wikipedia.org/wiki/Gary_McKinnonSource snippet
Gary McKinnonGary McKinnon (born February 1966) is a Scottish systems administrator and hacker who was accused by a US prosecutor in 2...
Published: February 1966
-
Source: swgde.org
Title: Best Practices for Digital Video Authentication
Link: https://www.swgde.org/documents/published-complete-listing/23-v-001-best-practices-for-digital-video-authentication/Source snippet
SWGDEBest Practices for Digital Video Authentication - SWGDEThe purpose of this document is to provide the background, technical...
-
Source: nist.gov
Title: provenience based cross verification digital forensic artifacts applied ntfs
Link: https://www.nist.gov/publications/provenience-based-cross-verification-digital-forensic-artifacts-applied-ntfsSource snippet
Provenience-based cross-verification of digital forensic...by A Nelson · 2024 — This work focuses on a model of a file system where...
-
Source: nist.gov
Link: https://www.nist.gov/itl/ai/digital-forensicsSource snippet
s software and hardware...
-
Source: swgde.org
Title: 2024 03 07 SWGDE Best Practices for Digital Video Authentication 23 V 001 1.2
Link: https://www.swgde.org/wp-content/uploads/2024/03/2024-03-07-SWGDE-Best-Practices-for-Digital-Video-Authentication-23-V-001-1.2.pdfSource snippet
SWGDESWGDE 23-V-001-1.2 Best Practices for Digital Video...7 Mar 2024 — The purpose of this document is to provide the backgroun...
-
Source: swgde.org
Link: https://www.swgde.org/documents/published-complete-listing/17-i-001-best-practices-for-maintaining-the-integrity-of-imagery/Source snippet
SWGDEBest Practices for Maintaining the Integrity of ImageryIntegrity Verification: The process of confirming that the imagery pr...
-
Source: medium.com
Link: https://medium.com/%40cyberengage.org/understanding-ntfs-timestamps-timeline-analysis-0f90c10c19a7Source snippet
Understanding Filesystem Timelines in Digital ForensicsThis technique allows forensic analysts to reconstruct events by examining file me...
-
Source: swgde.org
Link: https://swgde.org/wp-content/uploads/2024/06/Section_14_Best_Practices_for_Image_Authentication.pdfSource snippet
SWGDEDisclaimer:... metadata that is recorded in the file. Metadata may be readable in software designed to read metadata, some i...
-
Source: securitymagazine.com
Title: 102019 how does metadata help in digital forensic investigations
Link: https://www.securitymagazine.com/articles/102019-how-does-metadata-help-in-digital-forensic-investigationsSource snippet
How Does Metadata Help in Digital Forensic Investigations?25 Nov 2025 — Application metadata can reveal program usage, installation, date...
-
Source: linkedin.com
Link: https://www.linkedin.com/pulse/understanding-metadata-digital-forensics-html-vfsvc -
Source: truescreen.io
Title: forensic metadata acquisition
Link: https://truescreen.io/articles/digital-evidence-preservation-standards/Source snippet
Trust as a ServiceDigital Evidence Preservation: Standards ComparedMay 15, 2026 — A file can be copied without leaving a tra...
Published: May 15, 2026
-
Source: truescreen.io
Link: https://truescreen.io/articles/evidence-preservation-guide/Source snippet
Trust as a ServiceHow to Preserve Digital Evidence for Court29 Mar 2026 — EXIF metadata (timestamp, GPS coordinates, device...
-
Source: wired.com
Title: terrorist or ufo truth seeker
Link: https://www.wired.com/2006/04/terrorist-or-ufo-truth-seeker/Source snippet
?Apr 28, 2006 — But Briton Gary McKinnon says he is just an ordinary computer nerd who wanted to find out whether aliens and UFOs exist...
-
Source: spectrum.ieee.org
Link: https://spectrum.ieee.org/the-autistic-hackerSource snippet
IEEE SpectrumGary McKinnon: The Autistic HackerIn fact, McKinnon claimed that UFOs were the reason for his hack. Convinced that the gover...
-
Source: nist.gov
Title: cftt presentation error mitigation analysis e3016
Link: https://www.nist.gov/document/cftt-presentation-error-mitigation-analysis-e3016Source snippet
There is an ASTM Standard for that: E3016 – 18 Standard Guide for...
-
Source: wired.com
Title: WIRE D
Link: https://www.wired.com/Source snippet
The Latest in Technology, Science, Culture and...We bring you the future as it happens. From the latest in science and technolog...
-
Source: wired.com
Title: british ufo hac
Link: https://www.wired.com/2008/07/british-ufo-hac/Source snippet
ker Gary McKinnon Is Coming to AmericaJul 30, 2008 — Threat Level extends its warmest welcome to hacker Gary McKinnon, who just lost his...
-
Source: swgde.org
Title: 2025 12 10 Best Practices for Digital Forensic Video Analysis 18 V 001 2.0
Link: https://swgde.org/wp-content/uploads/2025/12/2025-12-10-Best-Practices-for-Digital-Forensic-Video-Analysis-18-V-001-2.0.pdfSource snippet
Best Practices for Digital Forensic Video Analysis10 Dec 2025 — SWGDE documents are developed by a consensus process that involves the be...
-
Source: swgde.org
Title: 2025 03 03 Best Practices for Image Authentication 18 I 001 2.0
Link: https://www.swgde.org/wp-content/uploads/2025/03/2025-03-03-Best-Practices-for-Image-Authentication-18-I-001-2.0.pdfSource snippet
Best Practices for Image Authentication3 Mar 2025 — SWGDE documents are developed by a consensus process that involves the best efforts o...
-
Source: swgde.org
Title: 2024 11 20 Best Practices for Maintaining the Integrity of Imagery 17 I 001 1.1
Link: https://www.swgde.org/wp-content/uploads/2024/11/2024-11-20-Best-Practices-for-Maintaining-the-Integrity-of-Imagery-17-I-001-1.1.pdfSource snippet
Best Practices for Maintaining the Integrity of Imagery20 Nov 2024 — Disclaimer Regarding Use of SWGDE Documents. SWGDE documents are dev...
-
Source: nist.gov
Title: statistical methods for change detection over time in digital forensics data
Link: https://www.nist.gov/system/files/documents/2016/12/05/statistical_methods_for_change_detection_over_time_in_digital_forensics_data.pdfSource snippet
Statistical Methods for Change Detection over Time in...5 Dec 2016 — Quantify answers to specific questions. – Is there evidence of a si...
-
Source: tsapps.nist.gov
Link: https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=926069Source snippet
Unmountable Media with the Digital Forensics...For instance, timeline analysis and file signature recognition only need limited metadata...
-
Source: nvlpubs.nist.gov
Title: NIST.IR.8354 draft
Link: https://nvlpubs.nist.gov/nistpubs/ir/2022/NIST.IR.8354-draft.pdfSource snippet
Investigation Techniques: A NIST Scientific Foundation...9 May 2022 — Common methods include deleting relevant files, creating bogus art...
Published: May 2022
-
Source: linkedin.com
Title: metadata mac times modified accessed created
Link: https://www.linkedin.com/learning/digital-forensics-essentials/metadata-mac-times-modified-accessed-createdSource snippet
This video highlights the role of metadata in digital forensic focusing on marked times...
-
Source: fast.io
Title: metadata extraction for digital forensics
Link: https://fast.io/resources/metadata-extraction-for-digital-forensics/Source snippet
ioMetadata Extraction for Digital Forensics in 2026 | FastioLearn how forensic investigators extract and preserve file metadata as ev...
-
Source: GOV.UK
Title: recovery and aquisition of video evidence v30
Link: https://www.gov.uk/government/publications/recovery-and-acquisition-of-video-evidence/recovery-and-aquisition-of-video-evidence-v30Source snippet
and Acquisition of Video Evidence v3.015 Jun 2022 — It is intended to facilitate extraction of video data (and associated metadata, for e...
Additional References
-
Source: researchgate.net
Link: https://www.researchgate.net/publication/382816264_Comparison_Study_of_NIST_SP_800-86_and_ISOIEC_27037_Standards_as_A_Framework_for_Digital_Forensic_Evidence_AnalysisSource snippet
Comparison Study of NIST SP 800-86 and ISO/IEC 27037...21 Mar 2026 — The primary goal of this report is to conduct an in-depth compariso...
-
Source: crime-scene-investigator.net
Link: https://www.crime-scene-investigator.net/best-practices-for-image-authentication.htmlSource snippet
Best Practices for Image AuthenticationFor further information on digital image integrity, refer to SWGIT document “Best Practices for Ma...
-
Source: vps.net
Link: https://www.vps.net/blog/historic-hacks-gary-mckinnon/Source snippet
Historic Hacks: Gary McKinnon – BlogIn our Historic Hacks segment, we like to look back at internet events that shocked, surprised, or ho...
-
Source: malicious.life
Link: https://malicious.life/episode/us_vs_gary_mckinnon/Source snippet
The US vs. Gary McKinnonGary McKinnon, a British hacker with Asperger's, broke into NASA & U.S Army networks - to find evidence of UFO co...
-
Source: spreaker.com
Title: gary mckinnon the hacker who found nasa s ufo non terrestrial officers 70473181
Link: https://www.spreaker.com/episode/gary-mckinnon-the-hacker-who-found-nasa-s-ufo-non-terrestrial-officers–70473181Source snippet
Gary McKinnon: The Hacker Who Found NASA's UFO &...5 Mar 2026 — This episode is a casual, banter-filled deep dive into Gary McKinnon's N...
-
Source: welivesecurity.com
Title: gary mckinnon reveals detail on nasa data breach and extraterrestrial life
Link: https://www.welivesecurity.com/2015/12/08/gary-mckinnon-reveals-detail-on-nasa-data-breach-and-extraterrestrial-life/Source snippet
Gary McKinnon reveals detail on NASA data breach and '...Dec 8, 2015 — IT expert and so-called hacker Gary McKinnon has claimed in an in...
-
Source: youtube.com
Link: https://www.youtube.com/watch?v=WFd7XzTf6_kSource snippet
David Grusch & NASA Hacker Gary McKinnonThe story of how a hacker breached NASA security with the intention of proving that NASA is hidin...
-
Source: youtube.com
Link: https://www.youtube.com/shorts/OFfQo4HkGp0Source snippet
NASA Hacker Found Alien Officers List...Gary McKinnon, the hacker who broke into NASA, claimed to have found evidence of UFOs and a secr...
-
Source: primeauforensics.com
Title: use scientific methodology to authenticate ring video in court
Link: https://www.primeauforensics.com/use-scientific-methodology-to-authenticate-ring-video-in-court/Source snippet
Authenticate Ring Video in Court with Scientific Methodology27 Oct 2023 — Digital video authentication is a complex process to establish...
-
Source: athenaforensics.co.uk
Title: SWGD E Digital & Multimedia Evidence Glossary Authentication
Link: https://athenaforensics.co.uk/wp-content/uploads/2019/01/SWGDE-Digital-Multimedia-Evidence-Glossary-062316.pdfSource snippet
The process of substantiating that the data is an accurate representation of what it purports to be. Capture. The process of recording da...
Topic Tree



