
Builds forensic file hash sets from disk images, packages, and archives across GCP, AWS, and local sources, with deduplication and PostgreSQL/Spanner export for DFIR workflows.
HashR allows you to build your own hash sets based on your data sources. It's a tool that extracts files and hashes out of input sources (e.g. raw disk image, GCE disk image, ISO file, Windows update package, .tar.gz file, etc.).
HashR consists of the following components:
Currently implemented importers:
Once files are extracted and hashed results will be passed to the exporters, currently implemented exporters:
You can choose which importers you want to run, each one have different requirements. More about this can be found in sections below.
HashR requires Linux OS to run, this can be a physical, virtual or cloud machine. Below are optimal hardware requirements:
HashR can likely run how machines with lower specifications, however this was not thoroughly tested.
In order to build a hashr binary run the following command:
env GOOS=linux GOARCH=amd64 go build hashr.go
In order to run tests for the core hashR package you need to run Spanner emulator:
gcloud emulators spanner start
Then to execute all tests run the following command:
go test -timeout 2m ./...
You can deploy HashR as part of the OSDFIR Infrastructure project This deployment will run HashR as kubernetes cronjobs and allows for an easy integration with Timesketch.
To run HashR in a docker container visit the docker specific guide
HashR takes care of the heavy lifting (parsing disk images, volumes, file systems) by using Plaso. You need to pull the Plaso docker container using the following command:
docker pull log2timeline/plaso
We also need 7z, which is used by WSUS importer for recursive extraction of Windows Update packages, to be installed on the machine running HashR:
sudo apt install p7zip-full
You need to allow the user, under which HashR will run, to run certain commands via sudo. Assuming that your user is hashr create a file /etc/sudoers.d/hashr and put in:
hashr ALL = (root) NOPASSWD: /bin/mount,/bin/umount,/sbin/losetup,/bin/rm
The user under which HashR will run will also need to be able to run docker. Assuming that your user is hashr, add them to the docker group like this:
sudo usermod -aG docker hashr
HashR needs to store information about processed sources. It also stores additional telemetry about processing tasks: processing times, number of extracted files, etc. You can choose between using:
There are many ways you can run and maintain your PostgreSQL instance, one of the simplest ways would be to run it in a Docker container. Follow the steps below to set up a PostgreSQL Docker container.
Step 1: Pull the PostgreSQL docker image.
docker pull postgres
Step 2: Initialize and run the PostgreSQL container in the background. Make sure to adjust the password.
docker run -itd -e POSTGRES_DB=hashr -e POSTGRES_USER=hashr -e POSTGRES_PASSWORD=hashr -p 5432:5432 -v /data:/var/lib/postgresql/data --name hashr_postgresql postgres
Step 3: Create a table that will be used to store processing jobs.
cat scripts/CreateJobsTable.sql | docker exec -i hashr_postgresql psql -U hashr -d hashr
In order to use PostgreSQL to store information about processing tasks you need to specify the following flags: -storage postgres -postgres_host <host> -postgres_port <port> -postgres_user <user> -postgres_password <pass> -postgres_db <db_name>
You can choose the store the data about processing jobs in Cloud Spanner. You'll need a Google Cloud project for that. The main advantage of this setup is that you can easily create dashboard(s) using Google Data Studio and directly connect to the Cloud Spanner instance that allows monitoring and debugging without running queries against your PostgreSQL instance.
Assuming that your gcloud tool is configured with your target hashr GCP project, you'll need to follow the steps below to enable Cloud Spanner.
Create HashR service account:
gcloud iam service-accounts create hashr --description="HashR SA key." --display-name="hashr"
Create service account key and store in your home directory. Set <project_name> to your project name.
gcloud iam service-accounts keys create ~/hashr-sa-private-key.json --iam-account=hashr-sa@<project_name>.iam.gserviceaccount.com
Point GOOGLE_APPLICATION_CREDENTIALS env variable to your service account key:
export GOOGLE_APPLICATION_CREDENTIALS=/home/hashr/hashr-sa-private-key.json
Create Spanner instance, adjust the config and processing-units value if needed: