What External Services Does IPED Depend On?

IPED functions as an offline-first forensic platform where every external service—from Discord API calls to remote processing endpoints—remains strictly optional and disabled by default.

The sepinf-inc/IPED repository hosts a digital forensics engine designed to process evidence without mandatory internet connectivity. While the core analysis pipeline operates entirely on local resources, the platform can optionally reach out to web services for report enrichment or distributed computing. Understanding these external dependencies allows examiners to deploy IPED in secure air-gapped environments while selectively enabling cloud features only when required.

Discord API and CDN Integration

When analyzing Discord exports, IPED can contact Discord's REST API to resolve user metadata for HTML report generation. The DiscordParser.java class constructs a request to https://discord.com/api/v9/users/@me to fetch the current user's profile identifier.

// DiscordParser.java executes this request during parsing
private static final String ME_URL = "https://discord.com/api/v9/users/@me";

This call occurs at line 84 of iped-parsers/iped-parsers-impl/src/main/java/iped/parsers/discord/DiscordParser.java. Following metadata retrieval, the parser builds avatar URLs pointing to Discord CDN endpoints:

// Avatar URL construction for the HTML report
String avatarUrl = "https://cdn.discordapp.com/avatars/" + userId + "/" + avatarHash + ".png";

The avatar download logic resides at line 226 of the same file.

Mapping and Geolocation Services

IPED supports interactive map rendering through two optional providers, configured via the graphical interface.

Google Maps JavaScript API

To enable Google Maps visualization, users must supply an API key in the IPED UI. The MapCanvasOpenStreet.java class injects this key into the map initialization script at line 257:

html = html.replace("{{googlemaps_scripts}}",
    "<script id=\"mapsapi\" src=\"https://maps.googleapis.com/maps/api/js?key=" + apikey + "\" async defer></script>\n"
    + "<script src=\"https://unpkg.com/leaflet.gridlayer.googlemutant@latest/dist/Leaflet.GoogleMutant.js\"></script>");

OpenStreetMap Tile Server

When the Google Maps option is disabled, IPED falls back to OpenStreetMap tile servers. The JMapOptionsPane.java file defines the default tile URL at line 50:


https://tile.openstreetmap.org/{z}/{x}/{y}.png

Remote Processing Endpoints

For compute-intensive tasks, IPED can offload processing to user-defined HTTP services rather than consuming local resources.

Remote Image Classification

The RemoteImageClassifierTask.java component sends image data to a configurable remote endpoint. When enabled, the task constructs POST requests to user-specified hosts:

// URLs built from the GUI configuration
urlZip = "https://" + config.getUrl() + "/zip";
urlVersion = "https://" + config.getUrl() + "/version";

This implementation at line 268 of iped-engine/src/main/java/iped/engine/task/RemoteImageClassifierTask.java requires explicit activation through Menu → Options → Remote Image Classifier.

Remote Speech-to-Text Transcription

Similarly, audio transcription can delegate to external services via RemoteTranscriptionService.java. Located at line 40 of iped-engine/src/main/java/iped/engine/task/transcript/RemoteTranscriptionService.java, this class manages HTTP communication with remote transcription servers configured under Menu → Options → Remote Transcription.

Report Rendering CDN Dependencies

Discord HTML reports incorporate animated elements via the Lottie-player library loaded from a CDN. The DiscordHTMLReport.java class includes this dependency at line 84:

// Script tag generation for Lottie animations
"https://unpkg.com/@lottiefiles/lottie-player@latest/dist/lottie-player.js"

This external reference only affects report aesthetics and does not impact forensic processing.

Test-Only Network References

Certain test utilities access external repositories for build dependencies. The RepoToolDownloader.java test class downloads Maven artifacts from GitHub or GitLab URLs during unit test execution. These calls occur exclusively in the test suite and do not influence normal case analysis or the runtime behavior of the forensic engine.

Summary

  • Core functionality requires no internet: The IPED analysis engine processes all evidence formats without external connectivity.
  • Discord integration: Optional API calls to discord.com and CDN fetches from cdn.discordapp.com occur only when parsing Discord exports.
  • Mapping flexibility: Users choose between Google Maps (requires API key) or OpenStreetMap tiles, or disable maps entirely.
  • Configurable remote processing: Image classification and transcription services only activate when administrators explicitly set remote endpoints in the GUI.
  • Test isolation: Network calls in RepoToolDownloader.java remain confined to the testing framework.

Frequently Asked Questions

Can IPED run completely offline?

Yes. The forensic analysis engine operates entirely on local resources. All external service calls—including Discord API lookups, mapping tiles, and remote processing—are opt-in features disabled by default. You can process cases, generate reports, and perform indexing without any network connectivity.

Is Discord data extraction mandatory when parsing Discord exports?

No. While DiscordParser.java contains code to query the Discord API and fetch avatars from the Discord CDN, these calls enhance report aesthetics rather than extract evidence. If the workstation lacks internet access, the parser continues processing chat data normally, simply omitting the user's avatar and display name resolution.

How do I configure remote image classification?

Navigate to Menu → Options → Remote Image Classifier in the IPED GUI. Enter the HTTPS URL of your compatible classification service (e.g., https://classifier.example.com). The RemoteImageClassifierTask will then POST image data to https://<host>/zip and check service availability at https://<host>/version before processing begins.

Are there privacy concerns with the mapping services?

Only if enabled. Google Maps requires an API key tied to your Google account and sends geolocation coordinates to Google's servers. OpenStreetMap tile requests expose approximate geographic regions to the tile server operators. For sensitive cases, disable both options in JMapOptionsPane to keep geolocation data strictly local.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →