Main Modules in the IPED Maven Project: A Complete Architectural Guide

The IPED forensic platform is organized into eight distinct Maven modules—iped-api, iped-utils, iped-parsers, iped-viewers, iped-carvers, iped-geo, iped-engine, and iped-app—each encapsulating a specific functional layer from core APIs to the desktop UI.

The sepinf-inc/IPED repository follows a strict multi-module Maven architecture that separates forensic processing capabilities into discrete, reusable components. Understanding these main modules in the IPED Maven project is essential for developers contributing to the codebase, extending the platform's functionality, or integrating specific forensic capabilities into external tools.

Overview of the IPED Maven Module Structure

The root pom.xml acts as the parent POM, defining the build order and dependency management for the entire project. According to the source code, the modules section in pom.xml (lines 9-18) declares eight primary artifacts that Maven builds in dependency order:

  • iped-api – Core public API used by all other components
  • iped-utils – Utility classes for logging, compression, and caching
  • iped-parsers – Parsing framework and concrete implementations (including DBF support)
  • iped-viewers – Viewer framework for displaying files, hex views, and text
  • iped-carvers – Data-carving subsystem using Aho-Corasick algorithms
  • iped-geo – Geolocation support for GPS data and map integration
  • iped-engine – Main processing engine handling indexing, search, and AI services
  • iped-app – Full desktop application with UI, graph visualization, and timeline features

Each module maintains its own pom.xml that inherits from the parent, allowing independent development and testing while ensuring cohesive integration during the full build process.

Detailed Breakdown of Each IPED Module

iped-api – The Foundation Layer

The iped-api module contains the core public API that serves as the foundation for the entire platform. All other modules depend on this artifact to ensure consistent interfaces across the forensic suite. When adding new dependencies to the core, you modify iped-api/pom.xml:

<!-- iped-api/pom.xml -->
<dependencies>
    <!-- existing deps … -->
    <dependency>
        <groupId>org.apache.commons</groupId>
        <artifactId>commons-lang3</artifactId>
        <version>3.14.0</version>
    </dependency>
</dependencies>

iped-utils – Shared Infrastructure

Utility classes covering logging, compression, caching, and other cross-cutting concerns reside in iped-utils. This module prevents code duplication by providing common functionality that parsers, viewers, and the engine all require.

iped-parsers – File Format Support

The iped-parsers module aggregates the parsing framework and concrete implementations. It contains sub-modules such as java-dbf and iped-parsers-impl that handle the extraction of text, metadata, and structured data from evidence files.

iped-viewers – Visualization Components

Display capabilities for files, hexadecimal views, and text rendering are encapsulated in iped-viewers. This module provides both the viewer API and its implementations, enabling the desktop application to render forensic artifacts without exposing implementation details to the UI layer.

iped-carvers – Data Recovery

The iped-carvers module implements the data-carving subsystem using Aho-Corasick algorithms. It includes both the carving API and specific implementations for recovering deleted or fragmented files from raw disk images, operating independently of the parsing framework.

iped-geo – Location Intelligence

Geolocation support for processing GPS data and integrating map visualization is handled by iped-geo. This module enables location-based analysis of evidence artifacts, providing geographic context to digital forensic examinations.

iped-engine – The Processing Core

The iped-engine module represents the heavy integration point of the platform. As implemented in iped-engine/pom.xml (lines 10-30), this module pulls together the parsers, carvers, viewers, and utilities while adding third-party integrations with SleuthKit, Lucene, OpenSearch, and AI services. It handles the main processing logic including indexing, search capabilities, and evidence analysis workflows.

iped-app – The Desktop Interface

Finally, iped-app assembles all lower-level modules into the full desktop application. This artifact contains the UI code, graph visualization features, timeline views, and export functionality that forensic examiners interact with directly.

Working with the IPED Maven Build

Compiling the Complete Project

To build all eight modules in the correct dependency order, execute the standard Maven lifecycle from the repository root:

mvn clean install

This command processes each module according to the dependency graph defined in the parent POM, ensuring that iped-api and iped-utils compile before modules that depend on them.

Inter-Module Dependencies

Modules reference each other using standard Maven dependency declarations. The engine module, for instance, declares its dependency on the API using the project version variable:

<!-- Example: iped-engine depends on iped-api -->
<dependency>
    <groupId>iped</groupId>
    <artifactId>iped-api</artifactId>
    <version>${project.version}</version>
</dependency>

Summary

  • The IPED project uses a multi-module Maven architecture with eight primary artifacts defined in the root pom.xml (lines 9-18).
  • iped-api provides the foundational interfaces, while iped-engine integrates external libraries like SleuthKit and Lucene for processing.
  • Functional modules (iped-parsers, iped-viewers, iped-carvers, iped-geo) encapsulate specific forensic capabilities into reusable components.
  • iped-app aggregates all lower-level modules into the final desktop application used by forensic examiners.
  • Each module maintains its own pom.xml inheriting from the parent, enabling independent development while ensuring cohesive builds across the entire platform.

Frequently Asked Questions

What is the purpose of the iped-api module?

The iped-api module contains the core public API used by all other IPED components. It defines the foundational interfaces and contracts that ensure consistency across the parsers, viewers, and processing engine, serving as the base dependency for every other module in the project.

How do I build a specific module instead of the entire project?

Navigate to the specific module directory (e.g., cd iped-parsers) and run mvn clean install. Maven will resolve dependencies against your local repository, though you must first build iped-api and iped-utils if they are not already installed, as most modules depend on these foundational artifacts.

Which module contains the search and indexing functionality?

The iped-engine module handles indexing, search, and AI services. As shown in iped-engine/pom.xml, it integrates with Lucene and OpenSearch while pulling together parsers, carvers, and viewers to process evidence through a unified pipeline.

Can I use IPED's parsing logic in my own application?

Yes. The iped-parsers module is designed as a reusable component. By adding it as a Maven dependency in your project's pom.xml, you can leverage the parsing framework and concrete implementations (such as the DBF parser) independently of the full desktop application.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →