PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
IPED is open-source software for processing digital evidence into searchable cases and then examining the indexed results. A typical workflow is to select a processing profile, provide evidence and a case-output location, run processing, and open the resulting case in IPED’s analysis interface. Supported formats and enabled features vary by release, input type, and profile.
What IPED does
IPED stands for Indexador e Processador de Evidências Digitais, or Digital Evidence Processor and Indexer. The project describes it as software for processing and analyzing digital evidence, including evidence handled in law-enforcement and corporate investigations. It was implemented in Java and, according to the project, originated with Brazilian Federal Police digital-forensics experts in 2012; the project says its code was officially published in 2019.
IPED is more than a file viewer. It can process evidence in batches to create a case, index and classify items, and provide an integrated interface for searching and reviewing results. Project-documented functions include hashing and hash-set lookup, file-signature analysis, categorization, recursive expansion of containers, content and metadata indexing, file carving, OCR, encryption detection, filtering, and timeline analysis. The available functions depend on the release and processing profile; listing a capability does not mean it is enabled in every run.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What forensic image formats does IPED support?
The project repository names RAW/DD, E01, ISO9660, AFF, VHD, VMDK, EX01, VHDX, UDF, AD1, and UFDR among the formats it supports. The Beginner’s Start Guide lists DD/RAW, E01, EX01, AFF, ISO, VHD, VHDX, VMDK, and AD1, and separately mentions UFDR reports. The repository says IPED uses The Sleuth Kit library to decode disk images and filesystems.
#1 Best Overall
- The PBN-TEC Digital Investigation Kit is a comprehensive eight-tool investigation system trusted by law enforcement agencies, private investigators, IT security professionals, legal teams, and even concerned parents. One kit covers mobile device extraction, computer investigations, evidence collection, illicit content detection, audio monitoring, and secure file deletion — no additional software purchases required.
- The iRecovery Stick extracts and investigates data from iPhone and iPad devices, the Phone Recovery Stick handles Android phones and tablets, and the SIM Card Seizure analyzes data from virtually any GSM SIM card. Together these three tools provide complete mobile device investigation coverage from a single kit, including contacts, messages, call logs, and photos.
- The Data Recovery Stick recovers deleted files from any Windows OS, the Voice Logger installs an audio monitoring application onto any Windows computer, and the Data Shredder Stick securely deletes files and wipes storage when the investigation is complete. All three tools work on Windows XP or newer with no additional software required.
- The Capturra Action Drive 1TB automatically collects targeted file types from virtually any device, serving as both an evidence storage drive and a targeted file collection tool for focused investigations. The XXX Detection Stick then scans the collected evidence for illicit content, categorizing results into Low Suspect, Suspect, and Highly Suspect for review.
- The Digital Investigation Kit includes everything needed to begin an investigation immediately — a Data Cable Kit with iPhone, USB-C, and Micro USB cables, a universal SIM Card Adapter compatible with all SIM card sizes, and a Softshell Compartmentalized Protection Case to organize and transport all eight tools securely.
These are project-documented formats, not a guarantee that every release handles every variant or input in the same way. Check the documentation for the specific release and evidence type you plan to process. The project also lists MD5, SHA-1, SHA-256, SHA-512, and eDonkey hash support; it says PhotoDNA is available to law enforcement.
How the processing workflow works
Prepare the evidence and destination
The Beginner’s Start Guide describes processing an image by supplying the evidence image and an output folder for the case. It says the destination folder should be absent or empty. Keep the original evidence and case output organized according to your investigative procedures, and verify the command syntax against the current release before use.
Choose a profile and process the case
Profiles determine which processing work IPED performs. The User Manual distinguishes default, forensic, fastmode, triage, and other profiles. The forensic profile enables additional carving and unallocated-space processing; fastmode is intended for preview. The manual describes triage as experimental and cautions that it may be unstable on computers with limited resources. These descriptions do not establish a universal speed ranking: processing time depends on the workload, configuration, and system.
After processing, the guide explains that the analysis application can be launched from the case output. It also documents adding multiple images and appending an image to an existing case. Consult the applicable guide for the exact commands and options for your release.
Rank #3
Search and review results
Use the analysis interface to search and filter indexed items, inspect categorized results and metadata, and examine timelines. Hash lookup, signature analysis, OCR, carving, and container expansion can help surface evidence, but their availability and results depend on the profile and input. IPED is a processing and analysis tool; using it alone does not establish that evidence handling, integrity verification, or legal admissibility requirements have been met.
Account for timestamps when processing FAT evidence
The Beginner’s Start Guide documents a timezone option for processing an image with a FAT filesystem. If the relevant timezone differs from the host computer’s local timezone, specify the appropriate timezone; otherwise the guide says the local system timezone is applied. This is a configuration consideration, not automatic knowledge of the evidence’s original timezone. Record the setting used and interpret resulting timestamps in the context of the source and investigative procedure.
Rank #4
- The Cellphone Investigation Kit is a complete solution for accessing and preserving data from virtually any mobile device. One kit covers iPhones, Android phones, GSM SIM cards, and photo backup — giving investigators, IT professionals, and parents everything they need in a single package.
- The included iRecovery Stick accesses data directly from iPhones and iPads running up to iOS 26.x, pulling contacts, text messages, call logs, saved passwords, WiFi networks, photos, the Deleted Photos folder, and more. Runs entirely on your Windows PC — no software is installed on the target device and no trace is left behind.
- The Phone Recovery Stick analyzes Android devices, recovering contacts, messages, photos, call logs, and more from a wide range of Android smartphones and tablets. Connect the target Android device to your Windows PC alongside the stick to begin extraction and data analysis.
- The SIM Card Seizure reader pulls data stored directly on GSM SIM cards, including contacts, SMS messages, call history, carrier information, and SIM serial numbers. Compatible with SIM cards from any carrier — including older flip phones and prepaid devices — making it essential for cases involving old phones that store data on SIM cards.
- The Photo Backup Stick completes the kit with fast photo and video backup from phones, tablets, and even computers, preserving visual evidence without requiring a PC or special software. All four tools work together to give you comprehensive mobile device coverage from a single professional investigation kit.
Cases, portability, and storage
The User Manual describes a portable-case option that stores relative evidence paths so a case can be opened from another computer or mount point. In the workflow described by the manual, the evidence and case have a same-drive constraint. Treat portability as dependent on that documented setup rather than assuming any case can be moved freely between systems.
Free tools Windows power users keep installed
One-click scans. No signup required.
IPED uses an output folder for case data, so storage capacity, interface, security, and handling procedures matter to a particular workflow. The documentation does not prescribe a drive type, model, or capacity. External storage is an optional operational choice, not a required IPED component or a substitute for evidence-handling policy.
Best Value
Performance claims and system requirements
The IPED repository reports processing speeds of up to 400 GB per hour on modern hardware. This is the project’s upper-bound claim, not an independently verified benchmark or a promise for a particular computer, evidence set, or profile. The repository also reports that a multi-case contained 135 million items as of December 12, 2019; that is a dated project capacity statement, not a current performance benchmark.
The project describes testing on Windows and Linux. Its repository notes Java 11 plus JavaFX for building from source and warns that the master branch is for development, recommending release tags when a stable build is desired. Runtime needs and installation details can change between releases, so check the selected release’s own instructions before installing or building.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

