Topic hub
Hash Verification & Integrity
How a cryptographic digest demonstrates that a file has not changed, what a matching value does and does not establish, and how chaining records together makes alteration detectable.
About hash verification & integrity
What a digest is
A cryptographic hash function reduces any amount of data to a short, fixed-length value. The same input always produces the same value, a single altered bit produces an entirely different one, and the value cannot be worked backwards into the data it came from. In evidence work that makes it a fingerprint: something you can write down, hand over, and compare again later without disclosing anything about what it describes.
What a match does and does not establish
A digest that re-computes to the value recorded at intake is strong evidence the content has not changed since that value was taken. It says nothing about who produced the file, whether its contents are true, or what it meant. It also says nothing about when the original value was recorded — a digest computed after a dispute began carries far less weight than one recorded at collection, which is why the timing of the record matters as much as the arithmetic.
Chaining records together
Recording the digest of each entry inside the entry that follows it links a log into a sequence. Altering an earlier entry changes its digest, which no longer matches the copy the next entry holds, and the break is visible for every entry after it. The precise claim is that alteration becomes detectable by anyone who re-runs the computation — not that a record cannot be edited. That distinction is the one an opposing expert will press on, and it is worth stating in exactly those terms.
CustodyTrack records the digest of an item as received and re-computes it on demand, with each entry chained to the one before it.
Published guides
Start here
How Cryptographic Hashing Makes Evidence Tamper-Evident
A hash value is a fixed-length string of hexadecimal characters derived from the contents of a digital file or image using a mathematical function, serving as a compact fingerprint of that data at a specific moment in time. Because even a single-bit change in the original data produces a completely different hash, comparing hashes before and after storage or handling provides a tamper-evident record of integrity—a capability that distinguishes digital evidence from ordinary copied files and anchors custody practices to mathematical verification rather than trust.
SHA-256 for Evidence Verification
SHA-256 is a cryptographic hash algorithm that generates a compact fingerprint of a file or forensic image to demonstrate that evidence has not been altered. Its widespread adoption in evidence workflows is grounded in NIST endorsement, minimal collision risk, and recognition by the forensic standards community.
MD5 vs SHA-256 in Digital Forensics
SHA-256 is substantially more resistant to collision attacks than MD5 and aligns with federal cryptographic standards; MD5 remains legally defensible for copy authentication under FRE 902(14) but exposes evidence to cross-examination challenge about its known practical weaknesses.
How to Prove a File Has Not Been Altered
Calculate and record a hash digest of a file at a known time; then independently recompute the hash and compare. If both digests match, that is strong evidence the file has not been altered since the reference hash was recorded. The showing rests on three elements: a cryptographic hash function, a fixed-time reference, and a documented record connecting them.
Explaining Hash Values to a Judge or Jury
Matching hash values are strong evidence that a file has not been altered since acquisition, because hashing produces an identical mathematical output when the same algorithm is applied to the same data. To explain this to lay adjudicators, emphasize reproducibility and deterministic process—not intuitive analogies that mislead about how hashing actually works.
Hash Chains: How a Tamper-Evident Log Works
A hash chain detects alteration of logged records by linking each entry cryptographically to its predecessor; any retroactive change to a record breaks the chain in detectable ways, making tampering auditable on later examination. The mechanism does not prevent alteration, but makes it plain to anyone who audits the chain afterward.
Digital Signature vs Hash Value: What Each Establishes
A matching hash value is strong evidence that a digital object has not been altered since a fixed point in time. A valid digital signature shows both that content has not changed since it was signed and that it was signed with a specific private key. Each answers a different evidentiary question, and conflating them creates both technical and legal risk.
Blockchain for Chain of Custody: What It Adds
Blockchain technology adds distributed consensus to cryptographic hash chains, making it detectable if the system operator unilaterally rewrites history. However, chain of custody does not require blockchain and does not require a distributed ledger — it requires a recorded, verifiable sequence of who handled the evidence and when. Whether blockchain's trade-offs in cost, throughput, and evidence privacy are justified in any given custody context remains a matter of institutional design, not legal requirement.
How to Verify a Forensic Image Hash
To verify a forensic image hash, you re-compute the hash of the acquired image file using the same algorithm that was used during acquisition, and compare the result to the hash value recorded in the acquisition log. If the values match, that is strong evidence the image has not been altered since acquisition; if they differ, something has changed and the cause must be investigated.
Write Blockers: What They Do and What They Demonstrate
A write blocker is a hardware or software tool that prevents any modifying command from reaching a storage device during forensic examination. Its primary function is to keep the original evidence unaltered; it does not guarantee admissibility, but it supports the foundational chain-of-custody showing that evidence was not changed in your hands.
Trusted Timestamps: Proving When a Hash Was Recorded
A trusted timestamp is a digitally signed record from an independent authority that binds a hash value to a specific moment in time, evidencing when data existed—not just that it has not been altered. A matching hash alone is evidence of integrity; a timestamp authority's signature is evidence of timing, which is why the distinction matters in digital evidence.
NSRL Hash Sets: Filtering Known Files in an Examination
The National Software Reference Library maintains a database of cryptographic hashes of known software files, allowing forensic examiners to automatically filter out operating systems, applications, and other known content during an investigation. A hash match shows a file is identical to one in the reference set; it does not show the file is benign, where this copy came from, who placed it there, when, or whether its presence is lawful.
Also planned for this hub
The full outline this subject is being written to, so you can see what is covered and what is still coming. The title below is not yet written and is not a link.
- Chain of Custody in a Digital Forensics Lab Report
Each is listed above as a link once written — subscribe on the guide index to be told when they publish.
Common questions
- Why is SHA-256 preferred over older algorithms?
- Because the older functions have demonstrated collision weaknesses and SHA-256 does not. MD5 and SHA-1 can both be made to produce the same value for two different inputs, which is a fact an opposing expert can raise without having to show it happened in your case. Using the stronger digest removes that line of questioning at no practical cost. SHA-256 for Evidence Verification →
- Is MD5 still acceptable for evidence?
- It is still produced by a great deal of acquisition tooling, and an MD5 recorded years ago is not worthless. It is the weaker of the two values, though, and where both are available the stronger one belongs in the record. Re-computing a modern digest against material still held is usually cheap. MD5 vs SHA-256 in Digital Forensics →
- Why does the timing of the original hash matter?
- A digest shows only that content is unchanged since the moment the value was taken. If that moment came after the dispute arose, it demonstrates considerably less than one recorded at collection. This is the half of the argument most often skipped: the value and the time it was recorded are one fact, not two. How to Prove a File Has Not Been Altered →
- How does a hash chain detect tampering?
- Each entry carries the digest of the entry before it. Change any earlier entry and its digest stops matching the copy the next entry holds, so verification fails from that point on and names where it broke. It makes alteration evident to anyone re-running the check; it does not stop someone editing a row, and the distinction is worth stating plainly. Hash Chains: How a Tamper-Evident Log Works →
Who this comes up for
- Corporate Legal, IT & eDiscoveryIn-house counsel, security and incident-response teams, and the eDiscovery function that inherits their collections.
- Private Investigators & DFIR ConsultantsLicensed investigators, one- and two-person digital forensics shops, and independent examiners retained by counsel.
Related subjects
- Chain of Custody
Who held an item, when, and what the record has to say about each handoff.
- Digital Evidence Admissibility
Authentication, the certification routes, and the exhibit types that draw the most argument.
- Evidence Handling Workflows
Collection through presentation, the guidance behind it, and who is accountable at each stage.
Reading about custody records is not the same as having one.
5 free Authenticated Chain of Custody Forms every month — no card required.