EBOXLAB is a terminal-based digital forensics and eDiscovery platform for managing cases, evidence, chain of custody, and examiner workflows. Built in C++17, it runs natively on Windows and macOS as a single standalone executable — no database server, no internet connection, no runtime dependencies.
Designed for forensic examiners and legal professionals who need a fast, reliable, air-gapped case management tool.
- Clients — Manage client organizations with contact details
- Cases — Track cases with status, priority, type, and assigned examiner
- Evidence — Catalog evidence items with acquisition details and hash values
- Chain of Custody — Record custody transfers with timestamps and actions
- Examiners — Manage forensic examiner profiles and certifications
- Custodians — Track data custodians linked to cases
- Activity Log — Automatic audit trail of all actions, sorted most-recent-first
- File Manager — Norton Commander-style file browser with directory navigation, sorting by name/size/date, and drive selection
- Hash Calculator — SHA-256 and MD5 hash computation for any file, with full file attributes (size, timestamps, permissions)
- Cross-entity search across all 7 modules
- Mouse and keyboard navigation
- Two themes: Classic Blue and Retro Green (toggle with F3)
- Demo data auto-seeded on first launch
- Binary flat-file storage — portable, no database required
- Air-gapped operation — zero network dependencies
- Download
EBOXLAB_Setup_v1.0.exefrom the Releases page - Run the installer — it creates Start Menu and Desktop shortcuts
- Launch EBOXLAB from the shortcut
- Download
eboxlab.exefrom the Releases page - Run it directly — no installation needed
- Data is stored in
%APPDATA%\EBOXLAB\
- Download
EBOXLAB_v1.0.dmgfrom the Releases page - Double-click the DMG to mount it
- Drag
EBOXLAB.appinto the Applications folder - Important — First Launch Security Steps:
- Double-click
EBOXLABin Applications - macOS will show: "EBOXLAB can't be opened because it is from an unidentified developer"
- Click OK (do not move to Trash)
- Open System Settings > Privacy & Security
- Scroll down to the Security section — you'll see: "EBOXLAB was blocked from use because it is not from an identified developer"
- Click Open Anyway
- Enter your Mac password when prompted
- A confirmation dialog appears — click Open
- EBOXLAB will launch in a Terminal window
- Double-click
- After the first launch, macOS remembers your choice — future launches work normally with a double-click
- Demo data is automatically loaded on first launch
- Data is stored in
~/Library/Application Support/EBOXLAB/
Tip: You can also right-click (or Control-click) the app and select Open from the context menu — this bypasses the security warning directly on the first attempt.
Prerequisites: MinGW-w64 (g++ with C++17), PDCurses (WinCon port)
# Install compiler
winget install BrechtSanders.WinLibs.POSIX.UCRT
# Build PDCurses
cd PDCurses/wincon
mingw32-make -f Makefile WIDE=Y
# Build EBOXLAB
cd ../..
mingw32-makeProduces eboxlab.exe — a statically linked standalone executable.
Prerequisites: Xcode Command Line Tools, ncurses (via Homebrew)
# Install dependencies
xcode-select --install
brew install ncurses
# Build
NCURSES_PREFIX=$(brew --prefix ncurses)
make -f Makefile.macos \
CXXFLAGS="-O2 -Wall -std=c++17 -I${NCURSES_PREFIX}/include" \
LDFLAGS="-L${NCURSES_PREFIX}/lib -lncurses"Produces eboxlab binary.
To create a DMG installer:
chmod +x create_dmg.sh
./create_dmg.sh| Key | Action |
|---|---|
| 1-8 | Quick select modules 1-8 |
| 9 | File Manager |
| 0 | Hash Calculator |
| Q | Exit application |
| Arrow keys | Navigate menus and lists |
| Tab / Shift+Tab | Cycle through items |
| Enter | Select / confirm |
| Escape | Go back / cancel |
| F2 | Save form |
| F3 | Toggle theme (Blue / Retro Green) |
| Mouse | Click items, scroll lists |
| Key | Action |
|---|---|
| Enter | Open directory / view file details + hash |
| Backspace | Go up one directory |
| F5 / F6 / F7 | Sort by Name / Size / Date |
| F8 | Toggle ascending / descending |
| F9 | Compute hash of selected file |
| D | Drive selection |
| Page Up/Down | Scroll by page |
| Home / End | Jump to first / last file |
All data is stored in binary flat files:
| File | Contents |
|---|---|
clients.dat |
Client records |
cases.dat |
Case records |
evidence.dat |
Evidence items |
chain.dat |
Chain of custody entries |
examiners.dat |
Examiner profiles |
custodians.dat |
Custodian records |
activity.dat |
Activity log entries |
- Windows:
%APPDATA%\EBOXLAB\ - macOS:
~/Library/Application Support/EBOXLAB/
Backup: Copy all .dat files to preserve the entire database.
Automated builds run via GitHub Actions on every push to main. Tagged releases (v*) automatically publish Windows installer, Windows portable exe, and macOS DMG to the Releases page.
- Web: www.eboxlab.com
- Email: info@eboxlab.com
- Phone: 888-714-6292
Planning & Project Oversight: Law Stars - Trial & Legal Services Colorado LLC
Proprietary software developed for Law Stars - Trial Lawyers and Legal Services Colorado LLC. All rights reserved.




