Why the Terminal Still Wins for Video Asset Management
A single generative video session can leave you with dozens of clips, each named something like output_9f3a2b_final_v3.mp4. Multiply that by a week of work and you have hundreds of files: some duplicates, some one frame away from being the good take, and no reliable way to tell which is which. A graphical file browser is fine for looking at one file. It is terrible at answering questions like "which of these 400 renders is missing an audio track?" or "did the file I copied to the archive drive change on the way over?"
The command line answers those questions in seconds, and it answers them identically every time. That repeatability is the real value. A rename script is documentation of your naming convention. A hash manifest is a receipt that proves an archive copy still matches the original. A metadata dump is a searchable catalog you can query months later when a client asks for the version you delivered in the spring.
This guide walks through the practical command-line layer of a serious video workflow: folder design, batch renaming, bulk moves, metadata extraction, checksum verification, and post-render validation hooks. Everything here works with plain Windows Command Prompt, PowerShell, bash, or zsh, and everything is built around tools you likely already have installed: ffmpeg and ffprobe, MediaInfo, robocopy, certutil, sha256sum, shasum, and 7-Zip.
A Folder Blueprint That Scales With Your Library
Before any command matters, the folder structure matters. Most chaos comes from mixing immutable source files with files that are still being edited, transcoded, or thumbnailed. Separate them physically and most scripts become trivial.
A structure that survives a few years of growth:
projects/
proj-014-launch-film/
00_source/ # camera originals, generated clips, downloads
10_assets/ # audio, graphics, logos, fonts
20_working/ # project files, proxies, scratch renders
30_selects/ # approved takes only
40_exports/ # deliverables, versioned
90_admin/ # notes, manifests, logs, contracts
archive/
originals/ # read-only, hashed, never edited in place
manifests/ # checksum and metadata logs
Three rules make this work:
- Originals are read-only. If you need to edit, copy the file into
20_workingfirst. Commands that recurse across a tree are far less dangerous when the source tree is never a write target. - Names sort meaningfully. Prefix folders with two-digit group numbers so file listings group by stage, not alphabetically. Use
YYYY-MM-DDprefixes on session folders if you need chronology. - One writer per tree. If a file is being written by a renderer, do not run a hash job on it. Wait for the process exit code, then verify.
Batch Renaming and Pattern Standardization
Preview first, rename second
Never run a rename loop blind. The first pass should always print what would happen:
for %f in (*.mp4) do @echo %f
Inside a .bat file, loop variables need double percent signs, so the same line becomes %%f. That single detail trips up more beginners than any other part of Windows scripting. If you paste a one-liner from a website into a batch file and it silently does nothing, this is almost always why.
Once the listing looks right, apply a prefix with a project code:
for %f in (*.mp4) do @ren "%f" "PRJ014_%~nf.mp4"
%~nf expands to the filename without extension, and %~xf gives you just the extension. Those two modifiers handle most pattern work. Quoting every path matters because video filenames love spaces, parentheses, and hashtags.
Normalizing version numbers and shot IDs
The goal is a name that sorts correctly and reads unambiguously. Three habits do most of the work: zero-pad counters (shot_007, not shot_7), keep version suffixes machine-parsable (_v03), and avoid spaces entirely.
PowerShell handles regex renaming more gracefully than CMD because it works with objects instead of text:
Get-ChildItem *.mp4 |
Rename-Item -NewName { $_.Name -replace 'final_v(\d+)', 'v$1_final' }
Add -WhatIf to preview. Add -Confirm only when the batch is small; for hundreds of files, a dry run is faster to audit.
Bulk Moves, Copies, and Safe Deletion
robocopy for resilient transfers
When moving terabytes between drives, robocopy is the right tool on Windows. It retries on failure, logs verbosely, and preserves timestamps:
robocopy "D:\renders" "E:\archive\renders" /E /COPY:DAT /DCOPY:DAT /R:2 /W:2 /LOG+:E:\logs\copy.log /TEE
Two flags deserve special caution. /MIR mirrors a source to a destination and deletes anything in the destination that is not in the source. It is perfect for syncing a working drive to a backup, and catastrophic if source and destination are reversed. /MOV deletes source files after a successful copy; use it only when the destination has already been verified.
Crucially, robocopy checks that bytes were written, not that they are correct. It is not a content verification tool. Hash the destination afterward if the material matters.
Avoiding destructive mistakes
Most data loss in video work is self-inflicted. Guard against it with a few cheap habits:
- Run every delete or move command once with
echoin place of the action word, and read the output. - Keep a
whereorGet-ChildItemlisting next to the destructive command so you can see the exact file set. - Prefer a recycle-bin-aware tool over
delfor anything you might need back. Plaindeldoes not go to the Recycle Bin. - Version your scripts in a text file inside
90_admin. When a script breaks something, you want the previous version.
Extracting Metadata and Building an Audit Log
ffprobe and MediaInfo in scripts
ffprobe ships with ffmpeg and returns machine-readable data about any file. A compact probe that captures the essentials:
ffprobe -v error -select_streams v:0 -show_entries stream=codec_name,width,height,avg_frame_rate -show_entries format=duration,size -of csv=p=0 "clip.mp4"
Wrap it in a loop to inventory an entire folder:
(for %f in (*.mp4) do @ffprobe -v error -select_streams v:0 -show_entries stream=width,height,codec_name,avg_frame_rate -of csv=p=0 "%f") > inventory.csv
MediaInfo provides a richer view, including audio tracks, subtitles, and color metadata:
mediainfo --Output=JSON clip.mp4 > clip.json
Turning logs into a searchable catalog
A CSV is a fine start, but a JSON Lines file is better because each record carries its own filename. Concatenate one JSON object per line and load it into SQLite for querying:
for %f in (*.mp4) do @mediainfo --Output=JSON "%f" >> catalog.jsonl
Now questions become one-liners. Which clips are under three seconds? Which exports are 1920x1080 when they should be 3840x2160? Which files lack an audio stream? A catalog pays for itself the first time you need to prove what you delivered.
Integrity Checks: Hashes, CRCs, and What Each One Proves
A checksum is a fixed-length fingerprint computed from file content. Change one byte and the fingerprint changes. That property makes checksums the backbone of any serious archive, but different algorithms answer different questions.
certutil on Windows
Windows ships with a built-in hashing tool:
certutil -hashfile "clip.mp4" SHA256
To hash a folder and build a manifest, loop it and redirect the output:
(for %f in (*.mp4) do @certutil -hashfile "%f" SHA256 | findstr /v "hash CertUtil") > manifest_sha256.txt
The findstr filter strips the header and footer lines so the output is closer to a plain list of digests. If you plan to verify the manifest later, keep the filenames attached; a digest with no filename is a number you cannot use.
sha256sum and shasum elsewhere
On Linux, sha256sum produces and verifies manifests directly:
sha256sum *.mp4 > manifest.sha256
sha256sum -c manifest.sha256
On macOS, shasum -a 256 is the equivalent. The -c check mode is the single most useful verification command in this entire article: it reads the manifest, rehashes each file, and reports mismatches without touching anything.
CRC32 and why it is not a security tool
CRC32 is a 32-bit checksum designed for transmission errors. It is extremely fast and widely supported, and 7-Zip can compute it across a folder. It is also trivially collision-prone: with only about four billion possible values, two different files sharing a CRC is not a freak event in a large library. Use CRC32 as a quick "did the copy finish" signal, never as proof of identity.
Choosing a hash algorithm
| Algorithm | Speed | Best use |
|---|---|---|
| CRC32 | Fastest | Transfer sanity checks |
| MD5 | Fast | Duplicate detection inside a trusted drive |
| SHA-1 | Fast | Legacy manifests only |
| SHA-256 | Moderate | Default for archives and deliverables |
| BLAKE2 / BLAKE3 | Very fast | Large libraries where throughput matters |
For most creators, SHA-256 is the right default: universally supported, well understood, and fast enough that a nightly verification job is invisible. If you are hashing hundreds of gigabytes of ProRes weekly, a parallel hasher such as BLAKE3 or xxhsum will cut wall-clock time dramatically, at the cost of a less common format.
Automating Post-Render Validation
Writing a validation manifest
Validation is not just "does the file exist." A useful check set answers: did the render complete, is the duration plausible, is the resolution what the pipeline promised, and is the file byte-identical to what the render machine produced?
Build a small expected-values file alongside each batch, for example a CSV with columns for filename, minimum duration, expected width, expected height, and expected SHA-256. The verifier then reads that file and reports pass or fail per row.
Hook scripts after renders
A batch hook that runs after a render finishes can do a surprising amount:
@echo off
setlocal
set RENDERDIR=%~1
echo Verification run %DATE% %TIME% > "%RENDERDIR%\_verify.log"
for %%f in ("%RENDERDIR%\*.mp4") do (
ffprobe -v error -show_entries format=duration -of csv=p=0 "%%f" >> "%RENDERDIR%\_verify.log"
certutil -hashfile "%%f" SHA256 >> "%RENDERDIR%\_verify.log"
)
endlocal
The hook should exit with a non-zero code when a check fails, so an orchestrator or scheduled task can stop the next stage. On Windows, register recurring verification with schtasks; on Linux and macOS, a cron entry or a systemd timer does the same job.
Cross-Platform Notes: PowerShell, bash, and macOS
PowerShell works with objects, so Get-FileHash -Algorithm SHA256 *.mp4 returns structured records you can export directly to CSV. That is cleaner than parsing text, and it makes PowerShell a strong choice even on a team that otherwise lives in CMD.
Bash handles weird filenames best with null delimiters:
find . -name '*.mp4' -print0 | xargs -0 sha256sum > manifest.sha256
Without -print0 and -0, a single apostrophe in a filename will break the pipeline.
macOS differences worth knowing: shasum rather than sha256sum, stat -f instead of stat -c, ditto for metadata-preserving copies, and BSD find flags that occasionally differ from GNU versions. Windows Subsystem for Linux is a practical middle ground for teams that want bash tooling without leaving Windows, but path translation between /mnt/d/... and D:\... needs care in scripts that pass paths back and forth.
A Maintenance Routine for Long-Term Archives
Hashing once is a snapshot. Storage media degrade, and a drive that was perfect two years ago can develop unreadable sectors without warning. A workable routine:
- Hash every new archive folder on ingest and store the manifest in a separate location from the media.
- Re-verify manifests on a schedule: quarterly for active projects, twice a year for cold archives.
- Track verification results in a simple log, including dates and mismatch counts, so you can see a drive trending toward failure.
- Maintain at least three copies on different media, with one offsite.
- Check drive health alongside checksums. PowerShell exposes
Get-PhysicalDiskandGet-Disk; on Linux,smartctl -agives you reallocated-sector counts that predict failures.
One subtlety: a mismatched hash does not automatically mean corruption. It can also mean the file was legitimately edited, transcoded, or restored from a different source. The manifest tells you that something changed; your version history tells you why.
Common Mistakes and How to Avoid Them
- Running destructive commands with no dry run. A five-second
echopass has saved entire afternoons. - Forgetting
%%in batch files. One-liners use%f; scripts use%%f. - Unquoted paths. Any filename with a space will silently truncate an argument.
- Hashing a file that is still rendering. You will record a digest of an incomplete file and never trust it again.
- Storing the manifest on the same drive as the media. A single failure takes both.
- Trusting file size alone. Two files of identical size can differ entirely.
- Reversing a mirror command. Read the source and destination arguments out loud before pressing Enter.
- Assuming a hash proves authorship. It proves content identity, nothing more. If you need tamper evidence, you need signing, not hashing.
FAQ
Is MD5 useless now?
No. It is unsuitable for security because collisions can be engineered, but it remains a fast and reliable way to detect accidental corruption or spot duplicates inside your own library.
How often should I re-verify an archive?
Quarterly for projects still in play, twice a year for cold storage, and always immediately after a large transfer. Verification is cheap compared with re-rendering a deleted shot.
Can I verify a file that is still being written?
You can, but the digest will be meaningless. Wait for the producing process to exit, then hash.
What is the fastest verification on Windows?
certutil -hashfile is available everywhere but slow on huge files. For volume work, install a parallel hasher such as BLAKE3 or use PowerShell's Get-FileHash in a runspace pool. The bottleneck is disk throughput, not CPU, so an external SSD will beat any algorithm change.
Do generated video files carry useful metadata?
Sometimes, but never rely on it. Formats from AI video tools vary wildly in what they embed. Build your own catalog with ffprobe or MediaInfo so you own the record.
Can I do all of this without touching a command line?
Partly. Media asset managers handle cataloging and some checksum work. What they rarely give you is a portable, plain-text manifest you can verify on any machine, years later, with tools that will still exist. That is the durable part, and it is worth the hour it takes to learn six commands.
Where should I start if I am new to all this?
Learn four things in order: ffprobe for metadata, a loop for listing files, certutil or sha256sum for digests, and -WhatIf or echo for previewing destructive actions. Everything else in this guide is a variation on those four.

