Skip to main content

Decode, encode, and identify forensic timestamps — ranked, scored, cited.

Project description

timeglyph

Decode, encode, and identify forensic timestamps — ranked, scored, and cited.

Python bindings for timeglyph, the Rust engine that reads a raw timestamp value every way a system might have written it and returns the results ranked by likelihood, each with the spec citation — honest about the ambiguity instead of guessing one answer. Built for DFIR work in notebooks, plaso, and Timesketch.

Install

pip install timeglyph

A single self-contained extension (stable-ABI wheel, CPython 3.9+). No system dependencies.

Use

import timeglyph

# One raw value → every plausible reading, ranked and cited:
for r in timeglyph.identify("133801920000000000"):
    print(f'{r["score"]:.2f}  {r["format_id"]:10}  {r["rendered"]}  ({r["citation"]})')
0.89  filetime    2025-01-01T08:00:00Z  ([MS-DTYP] §2.3.3 FILETIME)
0.70  ...

Each reading is a dict: format_id, label, rendered, instant, score, citation, assumptions, components, sentinel. A raw value is usually underdetermined, so identify returns all confident readings (16 for the example above) rather than a single verdict — you decide which fits the artifact.

Need the raw payload for a pipeline? timeglyph.identify_json(value) returns the same result as a JSON string.

Learn more

Privacy Policy · Terms of Service · © 2026 Security Ronin Ltd

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

timeglyph-0.7.0-cp39-abi3-win_amd64.whl (312.1 kB view details)

Uploaded CPython 3.9+Windows x86-64

timeglyph-0.7.0-cp39-abi3-manylinux_2_34_x86_64.whl (496.8 kB view details)

Uploaded CPython 3.9+manylinux: glibc 2.34+ x86-64

timeglyph-0.7.0-cp39-abi3-macosx_11_0_arm64.whl (429.1 kB view details)

Uploaded CPython 3.9+macOS 11.0+ ARM64

File details

Details for the file timeglyph-0.7.0-cp39-abi3-win_amd64.whl.

File metadata

  • Download URL: timeglyph-0.7.0-cp39-abi3-win_amd64.whl
  • Upload date:
  • Size: 312.1 kB
  • Tags: CPython 3.9+, Windows x86-64
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for timeglyph-0.7.0-cp39-abi3-win_amd64.whl
Algorithm Hash digest
SHA256 9e874a75c8f6b81156fbc7ada8aebab362db027af3c6c5199ffca2a0a9e2fa40
MD5 ad2fda082eb6d2486e7e2e1aa0f3aacf
BLAKE2b-256 372b8a19a1b8226a1c38efee1bce9374aa284ae7e2d8639f952a596d561c195d

See more details on using hashes here.

File details

Details for the file timeglyph-0.7.0-cp39-abi3-manylinux_2_34_x86_64.whl.

File metadata

File hashes

Hashes for timeglyph-0.7.0-cp39-abi3-manylinux_2_34_x86_64.whl
Algorithm Hash digest
SHA256 bafb2ce422f18facf1a5de5b2911e4325d2547f1640d090e323a6f79ed192de2
MD5 a840cc326ccee061d0ecd943e7cbf826
BLAKE2b-256 5212fd4d43f8157caffd6c5116fa294249cc74175e054cce12a16a52df189ef3

See more details on using hashes here.

File details

Details for the file timeglyph-0.7.0-cp39-abi3-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for timeglyph-0.7.0-cp39-abi3-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 61d6224ae91e33bf34268c5ffe09afc04e9c5c204297c6540a2b8cfcc1213876
MD5 c37ef64ae1e0bd92e76930c9b380160e
BLAKE2b-256 a77e0249a692225a953d442ab9305328ef8c89358c4c465e529aca74be2696b9

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page