Command library / sha256sum
sha256sum
Compute or verify SHA-256 file checksums
Prints the SHA-256 hash of one or more files — a fingerprint that changes if even one byte does. Use it to confirm a download wasn't corrupted or tampered with, to verify a whole set of files against a checksums list with -c, or to prove forensic evidence hasn't changed since it was collected.
Practice sha256sumUsage
sha256sum -c checksums-file
Options and flags
filefile to hash, or a checksums file when used with -c
-c, --checkread hashes from a file and verify each one against the actual file
--quietwith -c: only print files that FAILED verification
--tagprint in BSD-style tagged format: SHA256 (file) = hash
-b, --binaryread files in binary mode (default on Windows/WSL, irrelevant on Linux text mode)
Examples
sha256sum firmware.binPrint the hash of one file — compare it by eye against a known-good value.
sha256sum -c checksums.txtVerify every file listed in checksums.txt — prints OK or FAILED for each.
sha256sum --tag readme.txtBSD-style output: SHA256 (readme.txt) = <hash>.
sha256sum evidence1.img evidence2.imgHash two pieces of evidence in one pass, for the case file.
Common mistakes
A single dash takes single letters bundled together (-c), not a spelled-out word — that needs two dashes: --check.