A checksum is a fingerprint calculated from a file. If your downloaded ISO produces the same SHA-256 value published by the project, the file arrived without accidental corruption or unnoticed modification. Verification takes less time than rebuilding a failed USB drive and is especially important for operating systems, rescue environments, and security tools.
Find the project’s published checksum
Open the official download page from the OnlyCyber ISOs & Utilities directory. Look for SHA-256, checksums, hashes, or verification instructions. Some projects publish a plain text file; others publish a signed checksum list. Confirm that the filename beside the hash exactly matches the file you downloaded. Prefer SHA-256 or SHA-512 over legacy MD5 or SHA-1 values.
If a mirror supplies the ISO but not the checksum, obtain the expected value from the project’s primary website. Do not trust a checksum copied from the same unofficial post that supplied the file.
Verify on Windows
Open PowerShell in the folder containing the ISO. Run the following command, replacing the filename with yours:
Get-FileHash .\download.iso -Algorithm SHA256
PowerShell prints a hexadecimal hash. Compare every character with the published SHA-256 value. You can also store the result with Get-FileHash before moving the file to another computer and compare it again later.
Verify on Linux
Open a terminal in the download directory and run:
sha256sum download.iso
When the project provides a checksum file in the standard format, place it beside the ISO and run sha256sum -c checksums.txt. The command reports whether the named file passed. Confirm that the checksum file refers to the same release and architecture.
Verify on macOS
Use Terminal and calculate SHA-256 with:
shasum -a 256 download.iso
Compare the output with the project’s published value. Finder does not display cryptographic hashes by default, so the command-line result is the most consistent built-in option.
What to do when the values differ
Do not boot or install the image. Delete it, confirm that the expected checksum belongs to the same version, architecture, and edition, then download again from an official mirror. A mismatch often comes from an incomplete download or selecting the wrong checksum line, but it can also indicate tampering.
- Check the filename and file size.
- Try another official mirror.
- Verify the new copy before writing it to USB.
- If signatures are provided, follow the project’s signature-verification guide for stronger publisher authentication.
Related resources
Continue with the focused tools and guides below. Verify important findings against official documentation and preserve the source and date of anything you may need to reference later.