IPED is an open source software implemented in Java by digital forensic experts from the Brazilian Federal Police since 2012, offering command line data processing, multiplatform support, portable cases, an intuitive analysis interface, high multithread performance, and support for large cases. It uses the Sleuthkit Library to decode disk images and file systems, supporting RAW/DD, E01, and ISO9660 image formats.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A library for read-only access to QEMU Copy-On-Write (QCOW) image files, supporting multiple versions and compression formats for digital forensics analysis.
A library to access and parse Windows XML Event Log (EVTX) format, useful for digital forensics and incident response.
A comprehensive incident response tool for Windows computers, providing advanced memory forensics and access to locked systems.
A command-line tool for creating hex dumps, converting between binary and human-readable representations, and patching binary files.
A library to access the Windows New Technology File System (NTFS) format with read-only support for NTFS versions 3.0 and 3.1.
A digital artifact extraction framework for extracting data from volatile memory (RAM) samples, providing visibility into the runtime state of a system.
A library for accessing and parsing Extensible Storage Engine (ESE) Database Files used by Microsoft applications like Windows Search, Exchange, and Active Directory for forensic analysis purposes.