SSDEEP
Category: Hashing
Status: Registered and callable in the CyberChef 11.3.0 compatibility inventory.
Input / output: string → string
Background: https://forensics.wiki/ssdeep
What it does
SSDEEP is a program for computing context triggered piecewise hashes (CTPH). Also called fuzzy hashes, CTPH can match inputs that have homologies. Such inputs have sequences of identical bytes in the same order, although bytes in between these sequences may be different in both content and length. SSDEEP hashes are now widely used for simple identification purposes (e.g. the ‘Basic Properties’ section in VirusTotal). Although ‘better’ fuzzy hashes are available, SSDEEP is still one of the primary choices because of its speed and being a de facto standard. This operation is fundamentally the same as the CTPH operation, however their outputs differ in format.
Note
Status here means the operation name is implemented and callable. It does not by itself promise byte-for-byte parity for every upstream option. See Compatibility and current status for the verified scope and known boundaries.
Arguments and options
This operation takes no positional recipe arguments.
Recipe template
Important
This is a call template built from the documented defaults. Replace placeholder values such as empty keys, paths, patterns, or lookup data before running it.
from pychef import bake
input_value = "example"
args = []
result = bake(input_value, ['SSDEEP'])
print(result)
Pipeline example
from pychef import Pipeline
args = []
transform = Pipeline().then('SSDEEP')
result = transform("example")
Dedicated operation module
The registered entry point lives in
pychef.operations.by_operation.ssdeep. Direct calls
receive the input value and a positional argument tuple:
from pychef.operations.by_operation.ssdeep import run
result = run("example", tuple([]))
- pychef.operations.by_operation.ssdeep.run(value, args)
Run this operation using its shared internal implementation.
- Parameters:
value (str | bytes)
args (Sequence[Any])
- Return type:
str | bytes