cisagov / ioc-scanner

Search a filesystem for indicators of compromise (IoC).

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Support hashes besides MD5

dav3r opened this issue Β· comments

commented

πŸš€ Feature Proposal

Add the ability to scan for other hash types besides MD5, such as SHA-1 and SHA-256.

Motivation

When we are asked to scan for Indicators of Compromise (IOCs), we occasionally are given SHA-1 and SHA-256 hashes, in addition to MD5 hashes.

Example

Sample IOC hashes:

SHA256: b509f8545501588ecd828f970d91afc7c4aa6e238e838bd6a08ee2cd920fbe98
SHA-1:  31B54AEBDAF5FBC73A66AC41CCB35943CC9B7F72
SHA-1:  50973A3FC57D70C7911F7A952356188B9939E56B
SHA-1:  244EB62B9AC30934098CA4204447440D6FC4E259
SHA-1:  5C8F83CC4FF57E7C67925DF4D9DAABE5D0CC07E2

Pitch

It will give us more comprehensive scanning capabilities.