Skip to content

Cryptographic Hash

Definition

A fixed-length digest produced from a file's bytes by an algorithm such as MD5 (128-bit), SHA-1 (160-bit), or SHA-256 (256-bit). Identical files always produce the same hash. Hashes are used to fingerprint malware samples, verify file integrity, and share indicators of compromise without distributing the sample itself.

Common algorithms
MD5 (128-bit), SHA-1 (160-bit), SHA-256 (256-bit)
Property
Identical input always produces the identical hash
Forensic uses
Fingerprinting malware, verifying file integrity, sharing IOCs
Weakness note
MD5 and SHA-1 are broken for collision resistance

Common questions

Why is MD5 still used forensically despite being cryptographically broken?+

MD5's known weakness is that an attacker who controls both inputs can deliberately engineer a collision, but for verifying that an acquired forensic image matches its original bit-for-bit, or for identifying a known malware sample nobody is trying to forge, that specific attack scenario does not apply, so MD5 remains adequate for integrity checks even though SHA-256 is now preferred.

How do investigators use hashes to identify malware without sharing the actual sample?+

A hash uniquely fingerprints a specific file, so analysts can publish just the hash value in a threat intelligence feed, and anyone with the same file can compute its hash locally and compare it, confirming a match without ever transmitting the potentially dangerous file itself.

Why does changing a single byte in a file completely change its hash?+

Cryptographic hash algorithms are designed with an avalanche effect, where any small change to the input cascades through the computation to produce a wildly different, unpredictable output, which is precisely what makes a hash reliable for detecting even the smallest unauthorised modification to a file.

Related terms

C2PA (Coalition for Content Provenance and Authenticity)
An open technical standard that embeds cryptographically signed provenance assertions into media files at the point of capture or editing. A C2PA...
Disassembly
The process of converting raw binary machine code back into human-readable assembly language instructions. Disassembly is always achievable from a binary, unlike...
Import Address Table (IAT)
A section of the PE header that lists every external DLL and the functions the executable calls from each. A malware sample's...
Indicator of Compromise (IoC)
An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
NFT (Non-Fungible Token)
A unique cryptographic token on a blockchain associated with a reference to a media asset. NFTs record ownership transfers and can carry...
Oracle Problem
In blockchain contexts, the gap between what the ledger records and the real-world state it is meant to represent. A blockchain has...
Packer / Packing
A technique in which the original malware code is compressed or encrypted and wrapped in a stub loader that decompresses or decrypts...
Permissioned Ledger
A distributed ledger in which participation is controlled by a known set of validators (for example, Hyperledger Fabric). Unlike public blockchains, a...
Portable Executable (PE)
The binary file format used by Windows executables (.exe), dynamic-link libraries (.dll), and drivers (.sys). The PE header contains a structured metadata...
Provenance Manifest
A structured record, either embedded in a file or stored externally, that documents a media asset's origin, capture conditions, chain of custody,...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.