TimeGlyph
Decode any timestamp. Identify the unknown ones. See time itself.
Every examination throws raw timestamps at you — a 133801920000000000 buried in
an artifact — that you need in human-readable time. timeglyph reads that value
every way a system might have written it and reports the results ranked, scored,
and cited — honest about the ambiguity instead of guessing one answer. Convert
in bulk from a CSV, hover the number on screen and read the time live, or lay a
month out as a timezone/DST/leap-aware reference calendar — DST fold/gap days, leap seconds, GPS week,
format epochs, and the moon's phase, all flagged. No more copying each value into a
converter app. One static Rust binary, plus a live overlay that decodes whatever is
under your cursor.
Try it in your browser → · Full documentation →
The playground runs the real engine as WebAssembly, entirely client-side — paste a value, see every ranked, cited reading; nothing leaves the page.
$ timeglyph 1577836800
# readings consistent with 1577836800 (ranked; a raw value is usually underdetermined — not a single verdict):
[1.00] unix 2020-01-01T00:00:00Z (Unix time (seconds))
[0.94] postgres 2000-01-01T00:26:17.8368Z (PostgreSQL timestamp (µs since 2000))
[0.67] cocoa 2051-01-01T00:00:00Z (Cocoa / CFAbsoluteTime (s since 2001))
[0.67] hfsplus 1953-12-31T00:00:00Z (Apple HFS+ (s since 1904))
...
Install
One command per platform — each installs both the timeglyph CLI and the
Lens overlay app.
macOS
&&
Windows
winget install SecurityRonin.timeglyph
Debian / Ubuntu
|
You get the CLI on your PATH plus a real launcher for the overlay — a
Launchpad/Spotlight app on macOS (Developer-ID-signed and notarized), a Start Menu
shortcut on Windows, a desktop entry on Debian/Ubuntu (amd64 and arm64).
cargo install and the static musl archive ship the CLI alone — no overlay.
On macOS you can also take the CLI by itself with
brew install securityronin/tap/timeglyph.
What you do with it
TimeGlyph Lens — hover anything, decode time data
The way most people use it: never type a timestamp again. Hover any number on screen and read its time live. An always-on-top overlay follows your cursor and shows timeglyph's ranked readings for the number in the UI element under the pointer — so you never copy a value into a converter. Each row carries its confidence, the weekday, and the public holiday for that date in the chosen zone. Pick any display timezone from the footer.
It comes with the one-command install above, and reads the element under the cursor through the platform accessibility layer — the Accessibility API on macOS, UI Automation on Windows, and AT-SPI on Linux (X11, with assistive technologies enabled).
Identify an unknown value
Exit codes are pipeline-safe: 0 clear top reading, 2 ambiguous or a sentinel
(review needed), 1 error. Render in any timezone with --tz (UTC, a fixed
offset, or a DST-correct IANA name); nudge readings toward a source family with
--artifact "<hint>".
Decode or encode a known format
Mine artifacts at scale
Convert in bulk: enrich a whole CSV of timestamps in one pass instead of pasting
them into a converter one at a time. carve sweeps a raw blob (a config, a
record, a hex selection) for timestamps at every offset — window- and
score-thresholded — and exports JSONL, ImHex bookmarks, or Timesketch events.
See time in context — the reference calendar
cal is a calendar built for temporal analysis: per-day UTC offset and DST
fold/gap days, leap-second days and GPS week, ISO week / Julian Day / Unix,
timestamp-format epoch and rollover markers, seven alternative calendars (Chinese
lunisolar with the 干支 four pillars, plus ROC, Japanese, Buddhist, Hebrew, Islamic,
and Persian), and the moon's phase — every value computed and oracle-validated
(date, zdump, USNO, IERS, JPL).
Use it from an LLM / agent
mcp exposes identify / decode / explain as MCP tools, so an LLM-driven
DFIR workflow gets a cited, reproducible reading instead of a hallucinated epoch
conversion.
Every reading is scored and checked against an independent oracle — each names
the spec it assumes, and correctness is validated against primary-spec worked examples
and the MIT time_decode tool, with
calendar/astronomy values cross-checked against date, zdump, USNO, IERS, and JPL.
So a reading on your weird timestamp is evidence you can cite, not a guess. See
validation.
45 formats, every reading cited
timeglyph decodes and auto-identifies 45 registered formats plus the
self-describing string forms:
- Epoch integers & floats — Unix (s/ms/µs/ns and
double), FILETIME (incl. Active Directory / LDAP), WebKit/Chrome, Cocoa / CFAbsoluteTime (integer, signed double, iOS-11 ns), Apple HFS+/HFS, .NET ticks, OLE automation, Excel-1904, PostgreSQL, Mozilla PRTime, SQLite Julian day, DHCPv6, Modified Julian Day - Embedded IDs — KSUID, ULID, UUIDv1 / v6 / v7, MongoDB ObjectId, GMail message IDs, and Snowflake-class IDs (Twitter/X, Discord, Mastodon, LinkedIn, TikTok, Sonyflake)
- Packed & mobile/broadcast — FAT/DOS and exFAT date-time words, 128-bit SYSTEMTIME structs, Microsoft DTTM, BCD, GSM 7-byte semi-octet, Nokia, DVR, Motorola, Symantec, and SQL Server DATETIME
- Strings — ISO 8601 / RFC 3339, RFC 2822 email dates, EXIF, ASN.1 GeneralizedTime & UTCTime
- Leap-aware scales (
--features leap) — GPS, TAI64, NTP, kept separate from the POSIX spine
Each reading is scored on window membership, granularity, magnitude, byte-width, endianness, artifact context, and neighbour monotonicity — so the ranking reflects the evidence, not format popularity. (Validated against an independent oracle — see the trust note above and validation.)
Why another converter?
Good ones exist (time_decode,
MIT; DCode, proprietary). timeglyph is a single static Rust binary built on a
rigorous, cited model where a reading is evidence, not a verdict: a
POSIX-correct internal spine (never mislabelled UTC), the leap-second family kept
separate, and ambiguity as first-class, scored output. Calendar and timezone
math is reused (jiff), never reinvented. See
the design decisions.
Point it at the timestamp you're stuck on. → cargo install timeglyph, or
try it in your browser —
no install, nothing leaves the page.
Privacy Policy · Terms of Service · © 2026 Security Ronin Ltd