Even if the filename appears correct, it is useful to check that the downloaded package is the same as the released package. SHA-256 comparison is a way to verify file integrity.
Basic approach
A hash is a hash calculated from the file content. The digest of the same file must match the published value. This check is meaningful when compared to the correct value in the trusted source; It does not provide authentication if the file and hash come from the same untrusted location.
Application steps
- Get the installation file from the official download page and extract the SHA-256 value of that version.
- Calculate the file hash with the Get-FileHash -Algorithm SHA256 command in the standard PowerShell environment.
- Compare all characters; If there is a conflict, re-download the package from the official source without running it.
Practical example
Adding (2) to the filename in the download folder does not change the content; The hash of this file may still be the same. In contrast, a one-byte content change produces a different digest. Do not compare by filename.
Interpret the result correctly
Hash matching is not the same as a digital signature or malware inspection. Also check the publisher's signature status. Comparing the hash value to the value of a different version also creates a false alarm.
Source and follow-up reading
Protocol or command details: Microsoft Learn — Get-FileHash. The steps and example scenario are IPScans editorial narrative.