TLSH - A Locality Sensitive Hash

Introduction

TLSH is a fuzzy matching program and library. Given a file (min 50 bytes), TLSH generates a hash value which can be used for similarity comparisons. Similar files will have similar hash values which allows for the detection of similar objects by comparing their hash values TLSH has been adopted by a range of bodies and malware repositories including:

TLSH is becoming a standard choice for threat hunting and related security processing because of 2 key properties:

News