Digital forensics CSIRT-led

Hashlookup

Look up file hashes in known-file datasets to add context during incident investigation and forensic triage.

By CIRCL and project contributors · Luxembourg

CSIRT-led

Primary sources connect this project to an EU CSIRT as developer or lead.

At a glance

Recorded facts
Response workflow
Digital forensics
Developer or maintainer
CIRCL and project contributors
Recorded country
Luxembourg
Product model
Open source
Deployment
Self-hosted / Public service
Software license
AGPL-3.0
Upstream status
Experimental
Evidence class
CSIRT-led

What the sources establish

Origin note

The server README credits CIRCL, Computer Incident Response Center Luxembourg, and Alexandre Dulaunoy.

Reported capabilities

  • Supports individual and bulk hash lookups through a REST API.
  • Can import NSRL and other supported file-hash datasets.

Scope and limits

A matching hash is context, not a benign or malicious verdict. The server README labels the implementation beta; CIRCL’s public service is best-effort.

Inspect the research evidence 6 source observations
  1. identity / capabilities / deployment

    Upstream documentation describes look up file hashes in known-file datasets to add context during incident investigation and forensic triage. It documents local installation.

    Read source
  2. origin / country

    The server README credits CIRCL, Computer Incident Response Center Luxembourg, and Alexandre Dulaunoy.

    Read source
  3. license

    The upstream license file specifies AGPL-3.0.

    Read source
  4. maintenance

    Repository is not archived; its last recorded push was 2026-01-26. This is an activity signal, not a support guarantee.

    Read source
  5. capabilities / deployment

    CIRCL offers a free best-effort API and explicitly says a match alone does not establish maliciousness.

    Read source
  6. maintenance

    The upstream README explicitly describes the software as beta or experimental.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Plan targeted evidence collection, check acquisition gaps and produce a traceable timeline. Source-linked guidance for Acquire, Dissect and DFIR ORC.

A digital forensics triage and evidence workflow