> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blinkops.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Search Hash

Get threat intelligence details for a file hash from Kaspersky Threat Intelligence Portal.

The response includes a `Zone` verdict: `Green` (safe), `Yellow` (adware or suspicious), `Orange` (not trusted, may host malicious objects), `Red` (malicious), or `Grey` (not enough data).

<Note>
  External Documentation

  To learn more, visit the [Kaspersky Threat Intelligence Portal documentation](https://opentip.kaspersky.com/Help/Doc_data/en-US/HashLookupAPI.htm).
</Note>

## Parameters

<div className="integrations-table">
  | Parameter | Description |
  | - | - |
  | Hash | The MD5, SHA1, or SHA256 hash of the file to investigate. |
</div>

## Example Output

```json theme={"dark"}
{
	"Zone": "Red",
	"FileGeneralInfo": {
		"FileStatus": "Malware",
		"Sha1": "<string>",
		"Md5": "<string>",
		"Sha256": "<string>",
		"FirstSeen": "2023-01-15T10:30:00Z",
		"LastSeen": "2023-06-20T14:45:00Z",
		"Signer": "<string>",
		"Packer": "<string>",
		"Size": 524288,
		"Type": "PE executable",
		"HitsCount": 1000
	},
	"DetectionsInfo": [
		{
			"LastDetectDate": "2023-06-20T14:45:00Z",
			"DescriptionUrl": "https://threats.kaspersky.com/en/threat/Trojan.Win32.Generic",
			"Zone": "Red",
			"DetectionName": "Trojan.Win32.Generic",
			"DetectionMethod": "Heuristic analysis"
		}
	],
	"DynamicAnalisysResults": {
		"Detections": [
			{
				"Zone": "Red",
				"Count": 3
			}
		],
		"SuspiciousActivities": [
			{
				"Zone": "Red",
				"Count": 5
			}
		],
		"ExtractedFiles": [
			{
				"Zone": "Green",
				"Count": 2
			}
		],
		"NetworkActivities": [
			{
				"Zone": "Red",
				"Count": 4
			}
		],
		"DynamicDetections": [
			{
				"Zone": "Red",
				"Threat": 2
			}
		],
		"TriggeredNetworkRules": [
			{
				"Zone": "Red",
				"RuleName": "SNORT.CNC.C2Communication"
			}
		]
	}
}
```

## Workflow Library Example

[Search Hash with Kaspersky Threat Intelligence Portal and Send Results Via Email](https://library.blinkops.com/workflows/search-hash-with-kaspersky-threat-intelligence-portal-and-send-results-via-email)

<div className="iframe-wrapper">
  <div className="iframe-media">
    <img src="https://mintcdn.com/blinkops-2/ojHYuDeYX5FWuN8a/img/Icons/play-box.svg?fit=max&auto=format&n=ojHYuDeYX5FWuN8a&q=85&s=b8af968e71438a9499c3223c9bd29fb2" alt="Workflow Library" width="16" height="16" data-path="img/Icons/play-box.svg" />

    Preview this Workflow on desktop
  </div>

  <iframe className="iframe" src="https://library.blinkops.com/workflows/search-hash-with-kaspersky-threat-intelligence-portal-and-send-results-via-email/canvas" />
</div>
