ScriptsPowerShellPython Updated October 2026

One-liners for triage

Short snippets I keep within reach during triage. None of them are clever. They are here because they save a search when the clock is running.

Python

Hash a file

Reads in chunks, so it works on large files without loading them into memory.

import hashlib

def hash_file(path):
    hashes = {name: hashlib.new(name) for name in ("md5", "sha1", "sha256")}
    with open(path, "rb") as f:
        for chunk in iter(lambda: f.read(1024 * 1024), b""):
            for h in hashes.values():
                h.update(chunk)
    return {name: h.hexdigest() for name, h in hashes.items()}

print(hash_file("sample.bin"))

Pull URLs out of a file

import re

with open("suspicious.txt", errors="ignore") as f:
    urls = sorted(set(re.findall(r"https?://[^\s\"'<>]+", f.read())))

print("\n".join(urls))

Look up a hash in VirusTotal

Needs an API key. Look up hashes only: uploading a sample makes it available to other VirusTotal users, which may not be acceptable for customer data.

import os
import requests

file_hash = "<sha256>"
response = requests.get(
    f"https://www.virustotal.com/api/v3/files/{file_hash}",
    headers={"x-apikey": os.environ["VT_API_KEY"]},
    timeout=30,
)
stats = response.json()["data"]["attributes"]["last_analysis_stats"]
print(stats)

Bash

Processes whose binary has been deleted

A running process with no file on disk is worth a look.

ls -l /proc/[0-9]*/exe 2>/dev/null | grep '(deleted)'

Listening ports and the process behind each

ss -tulnp

Top sources of failed SSH logins

The log is /var/log/auth.log on Debian and Ubuntu, /var/log/secure on RHEL-based systems.

grep "Failed password" /var/log/auth.log | grep -oE 'from [0-9a-fA-F.:]+' | sort | uniq -c | sort -nr | head

PowerShell

Established network connections with the owning process

Get-NetTCPConnection -State Established |
  Select-Object LocalAddress, LocalPort, RemoteAddress, RemotePort,
    @{Name = "Process"; Expression = { (Get-Process -Id $_.OwningProcess).ProcessName }}

Startup programs

Get-CimInstance -ClassName Win32_StartupCommand | Select-Object Name, Command, Location, User

Local administrators

Get-LocalGroupMember -Group "Administrators"

DNS client cache

Get-DnsClientCache | Select-Object Entry, RecordType, Data

AD users with password expiry dates

Useful for expiry notifications, and for spotting accounts that are overdue. Requires the ActiveDirectory module.

Get-ADUser -Filter 'Enabled -eq $true -and PasswordNeverExpires -eq $false' `
    -Properties DisplayName, 'msDS-UserPasswordExpiryTimeComputed' |
  Select-Object DisplayName, SamAccountName,
    @{Name = "ExpiryDate"; Expression = { [datetime]::FromFileTime($_.'msDS-UserPasswordExpiryTimeComputed') }} |
  Sort-Object ExpiryDate |
  Export-Csv -Path .\password-expiry.csv -NoTypeInformation

Keep your own

A list like this is most useful when it is yours. Keep the snippets in a repository, add a line on what each one is for and when it misleads, and prune the ones you have not used in a year.

← All writing