What is screen recapture: screen recapture explained for teams that collect visual evidence
Screen recapture is the act of pointing a camera at a display and recording what is shown on it, so that an existing photograph or video can be submitted through a live capture flow as though it were being recorded from the real scene. Every part of the device stack is genuine. Only what sits in front of the lens is not.
In biometrics the same manoeuvre is called a presentation attack or a replay attack, and it is one of the oldest tricks in the field. The vocabulary and the test methodology come from the ISO/IEC 30107 series, with ISO/IEC 30107-3:2023 covering how detection performance should be measured and reported.
How does screen recapture work?
Someone displays the material they want to submit on a phone, tablet or monitor, then opens the capture flow on a second device and records the display. The capture session is real. The timestamps are real. The device is real and unmodified. The scene is a picture of a picture.
That is the whole appeal. It requires nothing to be installed and nothing to be tampered with, so it walks straight past checks built around device integrity.
What detection looks for
Re-photographing a display leaves physical traces, because a screen is not a scene. Detection works on the gap between the two.
- Moire patterns: interference between the display's pixel grid and the camera sensor grid, producing banding that has no reason to exist in a real scene.
- Refresh artefacts: rolling bands and flicker caused by the mismatch between display refresh rate and camera shutter behaviour.
- Reflection and gloss: specular highlights across a flat plane, and reflections of the room or the person holding the camera.
- Flatness: a display has no depth. Parallax, focus behaviour and the way highlights move as the camera moves all differ from a three-dimensional subject.
- Frame edges: bezels, cursors, status bars and interface furniture creeping into frame, which is the crudest tell and still a common one.
- Colour and frequency behaviour: emitted light from a panel has a different spectral and frequency-domain signature from light reflected off a car panel or a wall.
Screen recapture explained: a practical example
A vehicle damage submission arrives with clean lighting and a very steady hand. The reviewer notices that a highlight running across the wing does not shift as the camera pans, which is not how a curved metal surface behaves.
The material turns out to be a recording of a previous submission played back on a tablet. Nothing about the device, the network or the timing was unusual, which is exactly why the visual behaviour was the thing that caught it.
How screen recapture differs from a virtual camera
Both routes get pre-made material into a live flow, and they defeat different defences. A virtual camera intercepts inside software, so the frames never travel through optics and carry no physical artefacts at all. Screen recapture keeps every technical detail honest and lies only about the subject.
The practical consequence for anyone specifying remote inspection tooling: device-level signals catch the first and can be blind to the second, while image-level analysis catches the second and can be blind to the first. Ask about both, and look at how the signals feed into control points and case routing rather than treating either as a standalone answer.
Why this stays an arms race
The artefact-based tells all degrade as hardware improves. Higher pixel density reduces moire. Higher refresh rates reduce banding. Matte panels reduce glare. A careful attacker controls the angle, the lighting and the distance to suppress what is left, and detection models trained on yesterday's displays generalise poorly to today's.
So no signal set closes the gap permanently. Detection performance is reported as error rates for a reason: under ISO/IEC 30107-3 the measures are attack presentation and bona fide presentation classification error rates, which is the standards world saying plainly that both false accepts and false rejects exist and always will.
The more durable defence is process rather than any single detector. Guided prompts that ask for movement, specific angles and context that a static recording cannot supply, combined with a verifiable record of receipt, make a recaptured screen expensive to sustain across a full flow. The wider evidence discipline sits under evidence integrity.
Venta Capture, a product of VentaVid, records in real time only, guides the participant step by step through the angles the organisation asked for, and seals the received submission with a SHA-256 hash and a server-side receipt time. That makes filming a screen and passing it off as a live capture harder to carry through a full guided flow. Harder is not impossible, no evidence layer makes deception impossible, and the assessment stays with the qualified human who reviews the case.