Main Window Layout
The IPED interface uses a docking framework with customizable panels that can be arranged, resized, and minimized based on your workflow preferences.
Key Interface Components
Navigation Panel
Browse case evidence by:
- File system structure
- Categories (file types)
- Bookmarks and tags
- AI-generated filters
Results Area
View search results in:
- Table view with sortable columns
- Gallery view for visual items
- Timeline view for temporal analysis
- Graph view for relationship analysis
Viewer Panel
Preview evidence with built-in viewers:
- Hex viewer
- Text viewer with hit highlighting
- Image/video viewer
- HTML/email viewer
- Metadata viewer
Detail Tables
Related item information:
- Subitems (extracted/carved items)
- Parent containers
- Duplicates by hash
- Cross-references
Top Toolbar
The main toolbar provides quick access to essential functions:- Search Controls
- Options
- Checkbox Counter
- Search Box: Enter Lucene queries, regex patterns, or metadata searches
- Search Button: Execute the current query
- Filter Dropdown: Select predefined filters or manage custom filters
- Filter Duplicates: Toggle automatic hash-based duplicate filtering
Navigation Trees
Evidence Tree
Browse the original file system structure:- Recursive Listing: Toggle to show all descendants when selecting a folder
- Tree Nodes: Represent evidence sources, disk images, and directory structure
- Icons: Visual indicators for file types and status
Categories Tree
Files are automatically categorized by type and properties:- Hierarchical organization with parent/child relationships
- Click to filter results to that category
- Expandable to show subcategories
Bookmarks Tree
Manage and organize tagged evidence:- Custom bookmarks: Create named bookmarks for evidence organization
- Color coding: Assign colors to bookmark categories
- Comments: Add notes to bookmark groups
- Keyboard shortcuts: Assign hotkeys for quick bookmarking
- Counters: See item counts per bookmark
Press Ctrl+B to open the Bookmarks Manager for creating and managing bookmark categories.
Results Views
Table View
The default results table displays items with customizable columns: Available Columns:- Name, Path, Type, Size, Modified Date, Hash
- Category, Deleted Status, Carved Status
- Custom metadata fields
- Score (for search relevance)
- Column Sorting: Click headers to sort (shift-click for multi-column)
- Column Filtering: Right-click column headers for quick filters
- Column Selection: Show/hide columns via Options menu
- Row Selection: Single/multi-select for actions
- Context Menu: Right-click for item-specific actions
Gallery View
Visual grid display optimized for images and videos:- Thumbnail Display: Automatic thumbnail generation
- Video Frames: Toggle between first frame and multiple frames
- Grid Size: Adjustable thumbnail size (+ / - buttons)
- Filters: Grayscale and blur filters (Ctrl+W / Ctrl+Q)
- Similar Search: Find similar images or faces from gallery
Gallery Shortcuts
- Ctrl+Q: Toggle blur filter
- Ctrl+W: Toggle grayscale
- Arrow keys: Navigate thumbnails
- Space: Check/uncheck item
Gallery Actions
- Similar image search
- Similar face search
- Increase/decrease thumbnail size
- Toggle video frames mode
Timeline View
Chronological analysis of events:- Time-based sorting: Items organized by timestamp metadata
- Event filtering: Filter by date ranges and event types
- Visual timeline: Chart view showing event distribution
- Multiple timestamps: Modified, created, accessed dates
Enable timeline view using the clock icon button in the table toolbar.
Status Bar
The bottom status bar displays:- Current operation status and progress
- Total items in current result set
- Selected/checked item counts
- Case information and warnings
Customizing the Layout
The docking framework allows extensive customization:- Drag tabs to reposition panels
- Stack tabs by dragging one onto another
- Minimize panels to save screen space
- Detach panels to separate windows
- Save layouts for different analysis workflows
Keyboard Shortcuts
Search and Navigation
Search and Navigation
Item Actions
Item Actions
- Space: Check/uncheck selected items
- R: Check items recursively
- P: Select parent items
- F: Select referenced items
- D: Select items that reference selected
- Ctrl+A: Select all in current view
Bookmarking
Bookmarking
- Ctrl+B: Open Bookmarks Manager
- Ctrl+1-9: Quick bookmark with assigned shortcuts
- Alt+1-9: Remove from bookmark (when shortcut assigned)
View Controls
View Controls
- Ctrl+Q: Toggle blur filter (gallery/viewer)
- Ctrl+W: Toggle grayscale (gallery/viewer)
- Arrow Keys: Navigate items
- Page Up/Down: Scroll through results
Performance Considerations
Working with Large Cases
IPED is optimized for cases with millions of items:- Lazy Loading: Results loaded on-demand
- Index-based: Fast searches via Lucene indexing
- Efficient Caching: Thumbnails and previews cached
- Portable Cases: Can run from external drives
Resource Management
- Memory Usage: Automatically managed, adjust via Options if needed
- Disk Cache: Thumbnails and temp files stored in case directory
- Multi-threading: Parallel processing for responsiveness
Next Steps
Searching
Learn advanced search techniques with Lucene queries and regex
Filtering
Master filtering and grouping capabilities
Built-in Viewers
Explore the integrated file viewers
Bookmarks
Organize evidence with bookmarks and tags