Skip to content

File Hashing

Generating cryptographic hashes for evidence integrity and threat intelligence lookups.

Why It Matters

A hash identifies a file exactly. It proves evidence has not changed since collection, and it is the fastest way to check a file against threat intelligence or search for the same file across every endpoint.

Reference

Algorithms

Algorithm Use
SHA256 Default choice for evidence integrity and threat intel lookups
SHA1 Still used by some tools and indicator feeds; known collisions
MD5 Still common in older tools and feeds; known collisions, not suitable for integrity on its own

Commands

Task Windows Linux
Hash a file (SHA256) Get-FileHash .\file.exe sha256sum file
Other algorithms Get-FileHash -Algorithm SHA1 .\file.exe or -Algorithm MD5 sha1sum file, md5sum file
Hash from the command prompt certutil -hashfile file.exe SHA256
Hash a text string echo -n 'This is the text' | sha256sum
Hash every file in a folder Get-ChildItem -Recurse -File | Get-FileHash find . -type f -exec sha256sum {} +
Verify against a list sha256sum -c hashes.txt

How I Use It

I hash every file I collect at the time of collection and record the hash with the evidence notes. For suspicious files, the SHA256 is the first thing I look up in VirusTotal and the first thing I search across EDR to see where else the file exists.