Command library / Get-FileHash
Get-FileHash
Compute a file's cryptographic hash
Calculates a file's hash, SHA256 by default, so you can check that a download matches its published checksum, or record evidence and later prove it hasn't changed. Changing even one bit of the file produces a completely different hash.
Practice Get-FileHashUsage
Get-FileHash [-Path] <string> [-Algorithm <SHA256|SHA384|SHA512|SHA1|MD5>]
Options and flags
-PathFILEthe file(s) to hash; wildcards allowed (first positional parameter)
-AlgorithmNAMESHA256 (the default), SHA384, SHA512, SHA1 or MD5
Examples
Get-FileHash setup.exeThe file's SHA256 hash.
Get-FileHash tools.zip -Algorithm SHA512A SHA512 hash, to match a SHA512 checksum.
Get-FileHash C:\Evidence\*A hash for every file in the folder at once.
Common mistakes
Get-FileHash tools.zip -Algorithm SHA-512 Get-FileHash tools.zip -Algorithm SHA512
The algorithm names have no hyphen: SHA256, SHA512 and so on.