What Database Does IPED Use? H2 for Case Metadata and SQLite for Forensic Artefacts

IPED stores its case metadata in an embedded H2 database with asynchronous file access, while leveraging the SQLite JDBC driver to read forensic artefacts such as WhatsApp and browser histories.

IPED (Indexador e Processador de Evidências Digitais) is an open-source digital forensic tool developed by the Brazilian Federal Police. Understanding what database IPED uses is essential for forensic investigators and developers extending the platform. According to the sepinf-inc/IPED source code, the application utilizes H2 as its primary embedded data store for case management, alongside SQLite support for parsing third-party evidence files.

Embedded H2 Database for Case Metadata

IPED persists its case metadata and preview data in an embedded H2 database. The PreviewRepositoryManager class located at iped-engine/src/main/java/iped/engine/preview/PreviewRepositoryManager.java manages the lifecycle of this database, constructing JDBC URLs with the jdbc:h2:async: prefix to enable asynchronous file operations.

The H2 driver is declared as a Maven dependency in iped-engine/pom.xml (com.h2database:h2). When a forensic case is initialized, the repository manager creates a connection pool using HikariCP for efficient database access.

Configuring the H2 Connection

The PreviewRepositoryManager.configureWritable() method establishes the database connection for a specific case folder. It generates a JDBC URL pointing to the case directory with optimized parameters for forensic workloads.

// Configure a writable preview DB for a case folder
File caseFolder = new File("/path/to/case");
PreviewRepositoryManager.configureWritable(caseFolder);

// Later, retrieve the singleton repository
PreviewRepository repo = PreviewRepositoryManager.get(caseFolder);

// Use the repository (example: store a preview image)
byte[] previewData = ...;
repo.put(id, previewData);

The resulting JDBC connection string follows this format:


jdbc:h2:async:/path/to/case/previews;CACHE_SIZE=65536;DB_CLOSE_ON_EXIT=TRUE

SQLite for Forensic Artefact Parsing

While H2 stores IPED's internal case data, the application ships with the SQLite JDBC driver (Xerial) to read forensic artefacts stored in SQLite format. This includes WhatsApp databases, Skype logs, and browser histories found on seized devices.

The SQLite driver is declared in iped-parsers/iped-parsers-impl/pom.xml (org.xerial:sqlite-jdbc). Parsers throughout the codebase open jdbc:sqlite: connections to analyse these third-party databases without importing them into IPED's internal H2 store.

Accessing SQLite Evidence Files

Forensic parsers such as LinkExtractor in iped-parsers/iped-parsers-impl/src/main/java/iped/parsers/whatsapp/LinkExtractor.java demonstrate how IPED connects to SQLite artefacts:

// Inside a parser
String dbPath = "/path/to/WhatsApp.db";
try (Connection conn = DriverManager.getConnection("jdbc:sqlite:" + dbPath)) {
    // Run SQL queries on the artefact
    Statement st = conn.createStatement();
    ResultSet rs = st.executeQuery("SELECT name FROM sqlite_master WHERE type='table'");
    // Process results...
}

This approach allows IPED to query evidence files in-place without converting or migrating data to the internal database.

Optional External Database Support

The IPED engine also includes a PostgreSQL driver (postgresql:postgresql) in its Maven dependencies. However, according to the source code analysis, this driver is present only for optional external database support scenarios. None of the core IPED classes instantiate PostgreSQL connections by default, and the primary architecture relies on the embedded H2 solution for case portability and standalone operation.

Summary

  • IPED uses an embedded H2 database with the jdbc:h2:async: protocol for storing case metadata and preview data.
  • The PreviewRepositoryManager class manages H2 connections using HikariCP connection pooling.
  • SQLite JDBC support is included for parsing forensic artefacts like WhatsApp and browser databases via jdbc:sqlite: connections.
  • PostgreSQL drivers are available but unused in core functionality, reserved for optional external database configurations.
  • Key configuration files include iped-engine/pom.xml for H2 and iped-parsers/iped-parsers-impl/pom.xml for SQLite support.

Frequently Asked Questions

Does IPED use PostgreSQL as its primary database?

No. While the PostgreSQL JDBC driver is included as a Maven dependency in iped-engine/pom.xml, the core IPED codebase does not instantiate PostgreSQL connections by default. IPED primarily uses an embedded H2 database for case metadata storage, with PostgreSQL support available only for optional external database configurations.

What is the JDBC URL format for IPED's embedded database?

IPED constructs H2 JDBC URLs using the jdbc:h2:async: prefix followed by the case directory path. A typical URL looks like jdbc:h2:async:/path/to/case/previews;CACHE_SIZE=65536;DB_CLOSE_ON_EXIT=TRUE. The async: prefix enables asynchronous file I/O operations optimized for forensic workloads.

How does IPED parse WhatsApp databases?

IPED uses the SQLite JDBC driver (Xerial) to open read-only connections to WhatsApp's SQLite files via jdbc:sqlite: URLs. The LinkExtractor class in iped-parsers/iped-parsers-impl/src/main/java/iped/parsers/whatsapp/LinkExtractor.java demonstrates this pattern, querying the external database without importing its contents into IPED's internal H2 store.

Is IPED's H2 database file-based or in-memory?

IPED uses a file-based embedded H2 database stored within the case directory. The PreviewRepositoryManager configures persistent storage via the DB_CLOSE_ON_EXIT=TRUE parameter, ensuring case data survives application restarts while maintaining portability across forensic workstations.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →