Knowledge
Restreaming Piracy Explained
A restream rebroadcasts a live feed as it airs, from linear channels to concerts and esports. How to read which licensed feed was captured, map the relays behind it, and spot restreams disguised on mainstream platforms.
Restreaming is the live rebroadcast of someone else's feed without permission. It differs from a re-upload, where a recording is posted after the fact, and from leeching, where a pirate site plays the rights holder's own stream from the rights holder's own servers. In a restream the pirate captures the feed, encodes it and broadcasts it again in near real time. Sport draws most of the attention, but linear channels running around the clock, concerts, award shows, pay-per-view fights and paid esports broadcasts are restreamed in exactly the same way.
Reading which feed was captured
Every restream carries traces of the feed it came from, and those traces tell the rights holder where the leak is.
- On-screen graphics. Channel logos, score bugs, tickers and promos identify the broadcaster. Pirates often crop or blur the logo, but the rest of the graphics package usually survives.
- Commentary and audio. The language and the commentator identify the territory and often the specific channel.
- Ad breaks. When the original feed goes to adverts, a restream shows those adverts, a holding slate or another channel. Regional adverts are a strong territorial clue.
- Latency. Comparing the restream's delay with the licensed feeds narrows down the type of source, since a capture from satellite or cable behaves differently from a capture of an OTT stream.
- Watermarks. A forensic or session watermark in the original feed is the most precise identifier, pointing to the account or device that played it.
Knowing the source matters because the broadcaster whose feed was captured can often act on it directly, for example by suspending the subscription involved.
The relay behind the page
A single capture rarely serves only one site. The capturing operator pushes the stream to a restream server, which relays it to further servers, which are in turn embedded by many pages or loaded into IPTV playlists. Two pages in different languages showing the same commentary, with identical timing and the same cropped logo, are almost certainly fed by the same capture.
Analysts map this fan-out by recording the stream source behind each page: the iframe or player URL, the stream host, the server hostnames visible in the manifest. Grouping pages by shared source shows where the hubs are. A notice to the host of a hub server, or revocation of the capturing account, removes the stream from every page it feeds. Notices to each page separately leave the hub running. The general principle is discussed in source takedown vs link removal.
Restreams on mainstream platforms
Social and video platforms with live features are an attractive outlet: no infrastructure to run and a large potential audience. They also run content matching on live broadcasts, so restreamers use evasion techniques:
- mirroring, rotating, zooming or cropping the picture;
- placing the feed in a small window inside a larger frame, or overlaying static images;
- replacing or muting the audio so that audio matching fails;
- titling the stream as something unrelated and switching to the feed once viewers arrive;
- starting many short streams across throwaway accounts.
These tricks defeat automated matching to different degrees, which is why human review remains part of live protection. Audio and video matching each have blind spots, and audio vs video fingerprinting explains where each one fails. Platforms usually offer live-specific reporting routes, and a report should identify the protected broadcast, the account and the live URL while the stream is still running.
Linear channels around the clock
Restreams of linear channels follow a different rhythm from event piracy. A pirate copy of a premium film or entertainment channel runs continuously, often as one entry in an IPTV playlist. There is no single peak, so the work is sustained rather than intense: identifying the relays carrying the channel, sending notices to their hosts, tracing the capture where a watermark allows it, and checking again regularly, because the channel tends to reappear on a fresh server.
Confirming the result
A restream notice is finished only when the stream has stopped. Checking the stream URL after the host responds, and checking the pages that embedded it, shows whether the action worked or whether the page simply switched to a backup source. The backup becomes the next target. In DigiGuardians' monitoring, the in-house software Sherlock searches the way a viewer would, analysts verify every detection before a notice is filed, and reappearances are tracked and handled as they surface.
- Streaming
- Knowledge


