How to Verify SHA-256 on Windows
A SHA-256 hash is a unique fingerprint of a file. If even one byte differs, the hash changes completely. Verifying the hash is the only reliable way to confirm that the file you downloaded matches the one that was published.
Why This Matters
Download mirrors, malicious ads, and network tampering can all serve a modified version of a file. The published SHA-256 hash is the reference point. If your file's hash matches, the file is byte-for-byte identical to the version that was scanned and verified. If it does not match, the file is not what we published — delete it and re-download.
Method 1: PowerShell (Recommended)
This is the fastest method on Windows 10 and Windows 11.
Open PowerShell or Windows Terminal
Press Win + X and select Terminal or Windows PowerShell. You do not need administrator rights for this command.
Run the Get-FileHash Command
Paste this command, replacing the path with the actual location of your downloaded file:
Get-FileHash "C:\Users\YourName\Downloads\wave-executor-NEW-1.5.5.exe" -Algorithm SHA256
Tip: type Get-FileHash " then drag the file from File Explorer into the PowerShell window. Windows will insert the full path automatically.
Read the Output
You will see output like this:
Algorithm Hash Path
--------- ---- ----
SHA256 A3F5C8E91B2D4F7A6C8E0B3D5F7A9C1E2B4D6F8A0C2E4B6D8F0A2C4E6B8D0F2A C:\Users\YourName\Downloads\wave-executor-NEW-1.5.5.exe
The hash is the long string in the middle. It is 64 characters long.
Compare Character by Character
Compare the output hash to the hash published on the download page. PowerShell output is uppercase; our published hash may be uppercase or lowercase. Case does not matter — the letters and digits must match.
If they match: the file is intact. If they do not match: delete the file and download it again from the CDN link.
Method 2: CertUtil (Built Into Windows)
If PowerShell is unavailable, use CertUtil from Command Prompt.
- Press
Win + R, typecmd, press Enter. - Run this command, replacing the path with your file's location:
certutil -hashfile "C:\Users\YourName\Downloads\wave-executor-NEW-1.5.5.exe" SHA256
CertUtil prints the hash on the second line of output. Ignore the spaces — the hash is the same 64-character string with spaces inserted for readability.
Example output:
SHA256 hash of C:\Users\YourName\Downloads\wave-executor-NEW-1.5.5.exe:
a3 f5 c8 e9 1b 2d 4f 7a 6c 8e 0b 3d 5f 7a 9c 1e 2b 4d 6f 8a 0c 2e 4b 6d 8f 0a 2c 4e 6b 8d 0f 2a
CertUtil: -hashfile command completed successfully.
Remove the spaces and compare.
Method 3: 7-Zip (Optional)
If you have 7-Zip installed:
- Right-click the downloaded file
- Select CRC SHA → SHA-256
- The hash appears in a small dialog — you can copy it and compare
7-Zip is not required and you do not need to install it just for hash verification.
Common Problems
"The term 'Get-FileHash' is not recognized"
You are running an older version of PowerShell or a non-Windows PowerShell (for example, PowerShell 2.0). Get-FileHash was added in PowerShell 4.0. Update Windows, or use CertUtil instead.
The hash does not match
This means the file is not what we published. Possible reasons:
- The download was incomplete or corrupted. Re-download the file.
- You downloaded from a different source. Only use the CDN link on our download page.
- The file was modified by something on your system (rare, but possible with certain antivirus products).
Do not run the file if the hash does not match. Report it via our contact page.
The file is locked or in use
Close any application that might have the file open, then run the command again.
Long path issues
If the file path contains spaces or special characters, wrap the path in double quotes as shown in the examples above.
What SHA-256 Does Not Tell You
A matching SHA-256 proves the file is identical to the one whose hash we published. It does not prove that the file is safe, that it does what it claims, or that it is free of bugs. It only confirms integrity and source identity.
To understand what the file does and what risks it carries, read our Safety Center.