Skip to main content

Decode, encode, and identify forensic timestamps — ranked, scored, cited.

Project description

timeglyph

Decode, encode, and identify forensic timestamps — ranked, scored, and cited.

Python bindings for timeglyph, the Rust engine that reads a raw timestamp value every way a system might have written it and returns the results ranked by likelihood, each with the spec citation — honest about the ambiguity instead of guessing one answer. Built for DFIR work in notebooks, plaso, and Timesketch.

Install

pip install timeglyph

A single self-contained extension (stable-ABI wheel, CPython 3.9+). No system dependencies.

Use

import timeglyph

# One raw value → every plausible reading, ranked and cited:
for r in timeglyph.identify("133801920000000000"):
    print(f'{r["score"]:.2f}  {r["format_id"]:10}  {r["rendered"]}  ({r["citation"]})')
0.89  filetime    2025-01-01T08:00:00Z  ([MS-DTYP] §2.3.3 FILETIME)
0.70  ...

Each reading is a dict: format_id, label, rendered, instant, score, citation, assumptions, components, sentinel. A raw value is usually underdetermined, so identify returns all confident readings (16 for the example above) rather than a single verdict — you decide which fits the artifact.

Need the raw payload for a pipeline? timeglyph.identify_json(value) returns the same result as a JSON string.

Learn more

Privacy Policy · Terms of Service · © 2026 Security Ronin Ltd

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

timeglyph-0.4.1-cp39-abi3-win_amd64.whl (309.4 kB view details)

Uploaded CPython 3.9+Windows x86-64

timeglyph-0.4.1-cp39-abi3-manylinux_2_34_x86_64.whl (492.3 kB view details)

Uploaded CPython 3.9+manylinux: glibc 2.34+ x86-64

timeglyph-0.4.1-cp39-abi3-macosx_11_0_arm64.whl (427.4 kB view details)

Uploaded CPython 3.9+macOS 11.0+ ARM64

File details

Details for the file timeglyph-0.4.1-cp39-abi3-win_amd64.whl.

File metadata

  • Download URL: timeglyph-0.4.1-cp39-abi3-win_amd64.whl
  • Upload date:
  • Size: 309.4 kB
  • Tags: CPython 3.9+, Windows x86-64
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for timeglyph-0.4.1-cp39-abi3-win_amd64.whl
Algorithm Hash digest
SHA256 27a2bacd08f604851bb76dd4b6226bd60f31814a1ddff6d154804bede7647c63
MD5 c4e26035924b84bb95c63dbad17321ac
BLAKE2b-256 3946f7a4491ff41b9456ea50a76cac3457130768e299a8289884c782b129e2b2

See more details on using hashes here.

File details

Details for the file timeglyph-0.4.1-cp39-abi3-manylinux_2_34_x86_64.whl.

File metadata

File hashes

Hashes for timeglyph-0.4.1-cp39-abi3-manylinux_2_34_x86_64.whl
Algorithm Hash digest
SHA256 7f40b0722178218b35131d6a4bee7a637c19aecce0f70f4a3040c2fa5d6c446c
MD5 62bd2b164913ed20e865d5d0da797cea
BLAKE2b-256 f91f57540ace10cb46dcf37368a081b3ac96478d84dec063fc09b5b67283e823

See more details on using hashes here.

File details

Details for the file timeglyph-0.4.1-cp39-abi3-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for timeglyph-0.4.1-cp39-abi3-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 af244f0a54d96113cead02a539a2a4c9c2af780a5827d18b8f2378fe39e7b774
MD5 1dcb151cdcbca898bb7b1fd9624fb359
BLAKE2b-256 033e475d821624a069232ce119c48c355f28e30857bbe6308365a423a39e1b8b

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page