> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-artifacts-and-assets/investigate-a-file-and-process-hash.md).

# Investigate a file and process hash

Drilldown on a file or process hash on the **Hash View**. On this view you can investigate and take actions on SHA256 hash processes and files, and see information about a specific SHA256 hash over a defined 24-hour or 7-day time frame. In addition, you can drill down on each of the process executions, file operations, incidents, actions, and threat intelligence reports relating to the hash.

How to investigate a file or process hash

1. Open the **Hash View**.

   Identify the file or process hash that you want to investigate and select **Open Hash View**.
2. In the left panel, review the overview of the hash.
   1. Review the signature of the hash, if available.
   2. Identify the WildFire verdict.

      The color of the hash value is color-coded to indicate the WildFire report verdict:

      WildFire color key

      * Blue—Benign
        * Yellow—Grayware
        * Red—Malware
        * Light gray—Unknown verdict
        * Dark gray—The verdict is inconclusive
   3. Add an **Alias** or **Comment** to the hash value.
   4. Review threat intelligence for the hash.

      Depending on the threat intelligence sources that are integrated with Cortex XDR, the following threat intelligence might be available:

      * **Virus Total** score and report.

        <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h4>Note</h4><p>Requires a license key. Go to Settings → Configurations → Integrations → <strong>Threat Intelligence</strong>.</p></div>
      * **IOC** Rule, if applicable, including the IOC **Severity**, **Number of hits**, and **Source** according to the color-coded values:
      * **WildFire** analysis report.
   5. Review if the hash has been added to:
      * **Allow List** or **Block List**.
      * **Quarantined**, select the number of endpoints to open the **Quarantine Details** view.
   6. Review the recent open incidents that contain the hash as part of the incident's **Key Artifacts** according to the **Last Updated** timestamp. To dive deeper into specific incidents, select the Incident ID.
3. In the right hand view, use the filter criteria to refine the scope of the IP address information that you want to visualize.

<details>

<summary>Filter criteria</summary>

| Filter         | Description                                                                                                            |
| -------------- | ---------------------------------------------------------------------------------------------------------------------- |
| **Event Type** | Main set of values that you want to display. The values depend on the selected type of process or file.                |
| **Primary**    | Set of values that you want to apply as the primary set of aggregations. Values depend on the selected **Event Type**. |
| **Secondary**  | Set of values that you want to apply as the secondary set of aggregations.                                             |
| **Showing**    | Number of **Primary** and **Secondary** aggregated values to display.                                                  |
| **Timeframe**  | Time period over which to display your defined set of values.                                                          |

</details>

4. Review the selected data.

   To view the most recent processes executed by the hash, select **Recent Process Executions**. To run a query on the hash, select **Search all Process Executions**.
5. (Optional) Perform actions on the hash.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-artifacts-and-assets/investigate-a-file-and-process-hash.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
