How to Build the IPED Digital Forensic Tool from Source
Build the IPED project by cloning the sepinf-inc/IPED repository and running mvn clean install to compile the multi-module Java 11 Maven project into a ready-to-run forensic distribution.
IPED is an open-source digital forensic platform maintained by SEPINF that processes disk images, mobile extractions, and loose files through a modular Java architecture. Whether you need the Swing-based desktop UI or the RESTful Web API, building from source requires Maven 3.6+, Java JDK 11 with JavaFX support, and—on Linux—the SleuthKit native libraries. This guide walks through the exact steps verified against the repository's pom.xml and build configuration.
Prerequisites and Environment Setup
Before compiling, ensure your environment matches the specifications defined in the root pom.xml:
| Requirement | Details |
|---|---|
| Git | Required to clone the multi-module repository. |
| Maven 3.6+ | Build automation and dependency resolution. |
| Java JDK 11 (with JavaFX) | IPED relies on JavaFX for its user interface; distributions like Liberica OpenJDK 11 Full are recommended. Set JAVA_HOME to the JDK root. |
| SleuthKit (Linux only) | Native libraries for disk image handling must be compiled separately; see the repository wiki for libewf and libtsk setup. |
Understanding the Maven Module Structure
IPED is organized as a parent Maven project with eight distinct modules. The top-level pom.xml declares Java 11 as the compiler version and manages dependencies for Tika, PDFBox, Lucene, and SleuthKit across:
iped-api– Core interfaces and data models.iped-utils– Shared helper utilities.iped-parsers– File format parsers for PDF, video, browser data, and proprietary formats.iped-viewers– UI components for displaying extracted content.iped-carvers– File carving engine.iped-geo– Geolocation support modules.iped-engine– Processing engine, hash database, graph generator, and optional Web API server.iped-app– Main desktop application packaging the Swing UI.
Building from Source
Follow these commands to compile all modules and generate the distribution bundle.
1. Clone the repository:
git clone https://github.com/sepinf-inc/IPED.git
cd IPED
2. Compile and package:
mvn clean install
This command resolves transitive dependencies, compiles each module in dependency order, runs unit tests, and assembles the final distribution under target/release/iped-4.4.0-SNAPSHOT (version defined in the parent POM).
3. Verify the output:
After a successful build, the release directory contains:
target/release/iped-4.4.0-SNAPSHOT/
├── lib/ # All required JARs and dependencies
├── tools/ # Helper scripts for processing
├── conf/ # Default configuration files
└── iped-app.jar # Main application entry point
Running the Application
IPED provides two primary entry points depending on your use case.
Launch the Desktop UI:
The Swing interface entry point is iped.app.ui.AppMain. Start it from the built distribution:
java -jar target/release/iped-4.4.0-SNAPSHOT/iped-app.jar
Or run directly from the source tree using Maven:
mvn -pl iped-app exec:java -Dexec.mainClass=iped.app.ui.AppMain
Start the Web API Server:
For headless processing, use the RESTful API entry point in iped.engine.webapi.Main. This requires a JSON configuration file defining your case sources:
java -cp $(mvn -q -Dexec.executable=echo -Dexec.args='%classpath' --non-recursive exec:exec -pl iped-engine) \
iped.engine.webapi.Main --sources=/path/to/cases.json --host=0.0.0.0 --port=8080
The processing logic utilized by both interfaces is implemented in Manager.java within the engine module.
Linux-Specific Build Considerations
On Linux systems, the build requires manually compiled SleuthKit native libraries before running Maven. The project wiki details the necessary autotools commands to build libtsk and libewf. Once installed in standard library paths, the Maven build automatically links these dependencies during the iped-engine compilation phase.
Summary
- IPED is a multi-module Maven project requiring Java 11 and Maven 3.6+ to build the digital forensic platform from source.
- The root
pom.xmlorchestrates eight modules, fromiped-api(core models) toiped-app(desktop UI), producing a distribution intarget/release/. - Entry points: Use
iped.app.ui.AppMainfor the Swing interface oriped.engine.webapi.Mainfor the REST API server. - Linux builders must compile SleuthKit native libraries separately before the Maven build will succeed.
Frequently Asked Questions
What Java version is required to build IPED?
IPED requires Java JDK 11 with JavaFX support. The pom.xml explicitly sets the compiler source and target to version 11, and the Swing UI components depend on JavaFX classes available in full JDK distributions like Liberica OpenJDK 11 Full.
Where is the main entry point for the desktop application?
The desktop application launches through iped.app.ui.AppMain, located in the iped-app module. This class initializes the Swing interface and loading sequence, as referenced in the Maven exec:java configuration and the packaged iped-app.jar manifest.
How do I run the IPED Web API without building the full distribution?
You can start the Web API directly from source using Maven's classpath resolution. Execute the iped.engine.webapi.Main class with the --sources= argument pointing to a JSON catalog of forensic cases, which starts the server on your specified host and port without requiring a manual JAR invocation.
Why does the Linux build fail with missing native library errors?
The Linux build requires SleuthKit native libraries (libtsk, libewf) that are not bundled with the Java source. You must compile these C libraries from the SleuthKit project first, then ensure they are available in LD_LIBRARY_PATH so that the Maven build for iped-engine can link against them during compilation.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →