timeglyph
Decode any timestamp. Identify the unknown ones. See time itself.
Every examination throws raw timestamps at you — a 133801920000000000 buried in
an artifact — that you need in human-readable time. timeglyph reads that value
every way a system might have written it and reports the results ranked, scored,
and cited — honest about the ambiguity instead of guessing one answer. Convert
in bulk from a CSV, hover the number on screen and read the time live, or lay a
month out as a forensic calendar — DST fold/gap days, leap seconds, GPS week,
format epochs, and the moon's phase, all flagged. No more copying each value into a
converter app. One static Rust binary, plus a live overlay that decodes whatever is
under your cursor.
Try it in your browser → · Full documentation →
The playground runs the real engine as WebAssembly, entirely client-side — paste a value, see every ranked, cited reading; nothing leaves the page.
$ timeglyph 1577836800
# readings consistent with 1577836800 (ranked; a raw value is usually underdetermined — not a single verdict):
[1.00] unix 2020-01-01T00:00:00Z (Unix time (seconds))
[0.94] postgres 2000-01-01T00:26:17.8368Z (PostgreSQL timestamp (µs since 2000))
[0.67] cocoa 2051-01-01T00:00:00Z (Cocoa / CFAbsoluteTime (s since 2001))
[0.67] hfsplus 1953-12-31T00:00:00Z (Apple HFS+ (s since 1904))
...
Install
macOS
Debian / Ubuntu
|
Windows
winget install SecurityRonin.timeglyph
Cargo
On macOS and Windows this also installs the
timeglyph-lens overlay.
Code signing
Free code signing for timeglyph's Windows binaries is provided by
SignPath.io, using a code-signing certificate
from the SignPath Foundation.
What you do with it
Identify an unknown value
Exit codes are pipeline-safe: 0 clear top reading, 2 ambiguous or a sentinel
(review needed), 1 error. Render in any timezone with --tz (UTC, a fixed
offset, or a DST-correct IANA name); nudge readings toward a source family with
--artifact "<hint>".
Decode or encode a known format
Mine artifacts at scale
Convert in bulk: enrich a whole CSV of timestamps in one pass instead of pasting
them into a converter one at a time. carve sweeps a raw blob (a config, a
record, a hex selection) for timestamps at every offset — window- and
score-thresholded — and exports JSONL, ImHex bookmarks, or Timesketch events.
See time itself — the forensic calendar
cal is a calendar built for temporal analysis: per-day UTC offset and DST
fold/gap days, leap-second days and GPS week, ISO week / Julian Day / Unix,
timestamp-format epoch and rollover markers, the Chinese / Hebrew / Islamic dates,
and the moon's phase — every value computed and oracle-validated (date, zdump,
USNO, IERS, JPL).
Use it from an LLM / agent
mcp exposes identify / decode / explain as MCP tools, so an LLM-driven
DFIR workflow gets a cited, reproducible reading instead of a hallucinated epoch
conversion.
TimeGlyph Lens — hover anything, decode time data
Convert live: hover any number on screen and read its time in real time. An always-on-top overlay follows your cursor and shows timeglyph's ranked readings for the number in the UI element under the pointer, so you never copy a value into a converter. Each row carries its confidence, the weekday, and the public holiday for that date in the chosen zone. Pick any display timezone from the footer.
It installs with the CLI on macOS and Windows and reads the element under the cursor through the platform accessibility layer — the Accessibility API on macOS, UI Automation on Windows. (Linux support is in progress.)
Formats
timeglyph decodes and auto-identifies:
- Epoch integers — Unix (s/ms/µs/ns), FILETIME (incl. Active Directory / LDAP), WebKit/Chrome, Cocoa / CFAbsoluteTime (integer, signed double, iOS-11 ns), Apple HFS+, .NET ticks, OLE automation, Excel-1904, PostgreSQL, Mozilla PRTime, SQLite Julian day
- Embedded IDs — KSUID, ULID, UUIDv1 / v6 / v7, MongoDB ObjectId, and Snowflake-class IDs (Twitter/X, Discord, Mastodon, LinkedIn, TikTok)
- Packed on-disk — FAT/DOS date-time words and 128-bit SYSTEMTIME structs
- Strings — ISO 8601 / RFC 3339, RFC 2822 email dates, EXIF, ASN.1 GeneralizedTime & UTCTime
Every reading names the spec it assumes and is scored on window membership,
granularity, magnitude, byte-width, endianness, artifact context, and neighbour
monotonicity. Correctness is checked against primary-spec worked examples and the
MIT time_decode oracle — see
validation.
Why another converter?
Good ones exist (time_decode,
MIT; DCode, proprietary). timeglyph is a single static Rust binary built on a
rigorous, cited model where a reading is evidence, not a verdict: a
POSIX-correct internal spine (never mislabelled UTC), the leap-second family kept
separate, and ambiguity as first-class, scored output. Calendar and timezone
math is reused (jiff), never reinvented. See
the design decisions.
Privacy Policy · Terms of Service · © 2026 Security Ronin Ltd