Compute cryptographic checksums for any file or text and verify them against a known value. Use it to confirm a download was not tampered with, or to match a file against a malware indicator of compromise (IOC). Everything is computed locally — files never leave your device.
—All hashing runs in your browser via the Web Crypto API. File contents and text are never transmitted or stored.
A cryptographic hash is a fixed-length fingerprint of a file. Change a single byte and the hash changes completely, so comparing a computed checksum against the value published by a vendor proves the file arrived intact and unaltered. Incident responders use the same technique in reverse: threat-intelligence feeds publish SHA-256 hashes of known malware, and matching a suspicious file against those IOCs confirms an infection. Prefer SHA-256 or stronger; SHA-1 is included for legacy IOC matching only and is no longer collision-resistant. For help operationalizing IOC matching across your estate, talk to our team.
No. Hashing is performed entirely in your browser using the Web Crypto API. File contents and text are read locally and never transmitted, logged, or stored.
Use SHA-256 for general integrity verification; it is the modern standard. SHA-384 and SHA-512 offer larger digests. SHA-1 is provided only for matching older IOC feeds and should not be relied on for security, as it is vulnerable to collisions.
Compute the file's hash here, then paste the checksum published by the software vendor into the verify field. A match confirms the file is authentic and unmodified; a mismatch means you should not trust the file.
An indicator of compromise hash is a checksum of a known-malicious file shared by threat-intelligence providers. Matching a suspicious file's hash against IOC feeds is a fast way to confirm whether it is known malware.