Skip to main content

timeglyph

Decode, encode, and identify forensic timestamps — ranked, scored, and cited.

Python bindings for timeglyph, the Rust engine that reads a raw timestamp value every way a system might have written it and returns the results ranked by likelihood, each with the spec citation — honest about the ambiguity instead of guessing one answer. Built for DFIR work in notebooks, plaso, and Timesketch.

Install

pip install timeglyph

A single self-contained extension (stable-ABI wheel, CPython 3.9+). No system dependencies.

Use

import timeglyph

# One raw value → every plausible reading, ranked and cited:
for r in timeglyph.identify("133801920000000000"):
    print(f'{r["score"]:.2f}  {r["format_id"]:10}  {r["rendered"]}  ({r["citation"]})')
0.89  filetime    2025-01-01T08:00:00Z  ([MS-DTYP] §2.3.3 FILETIME)
0.70  ...

Each reading is a dict: format_id, label, rendered, instant, score, citation, assumptions, components, sentinel. A raw value is usually underdetermined, so identify returns all confident readings (16 for the example above) rather than a single verdict — you decide which fits the artifact.

Need the raw payload for a pipeline? timeglyph.identify_json(value) returns the same result as a JSON string.

Learn more

Privacy Policy · Terms of Service · © 2026 Security Ronin Ltd

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

timeglyph-0.9.1-cp39-abi3-win_amd64.whl (312.5 kB view details)

Uploaded CPython 3.9+Windows x86-64

timeglyph-0.9.1-cp39-abi3-manylinux_2_34_x86_64.whl (496.3 kB view details)

Uploaded CPython 3.9+manylinux: glibc 2.34+ x86-64

timeglyph-0.9.1-cp39-abi3-macosx_11_0_arm64.whl (429.2 kB view details)

Uploaded CPython 3.9+macOS 11.0+ ARM64

File details

Details for the file timeglyph-0.9.1-cp39-abi3-win_amd64.whl.

File metadata

  • Download URL: timeglyph-0.9.1-cp39-abi3-win_amd64.whl
  • Upload date:
  • Size: 312.5 kB
  • Tags: CPython 3.9+, Windows x86-64
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for timeglyph-0.9.1-cp39-abi3-win_amd64.whl
Algorithm Hash digest
SHA256 69239259fc5db8c93acd0809c77f53e1afd1cda00a38f4ac95ff6c80e4e02a9e
MD5 7d8d3f7be10a6debafc391ecad3acdf7
BLAKE2b-256 ae1a82f3418a05b6b97ff65aea081c5463273e430f8f2acf23f6c0d53c815836

See more details on using hashes here.

File details

Details for the file timeglyph-0.9.1-cp39-abi3-manylinux_2_34_x86_64.whl.

File metadata

File hashes

Hashes for timeglyph-0.9.1-cp39-abi3-manylinux_2_34_x86_64.whl
Algorithm Hash digest
SHA256 cfbea772f4a05b5a2e3ba45cbf6461a345345177cc401db0728ae3e7600babc0
MD5 f58f507a8b126be55b04741c4161b176
BLAKE2b-256 7b7a699c3051993f20f64e13bf135f5a9f68a9f093e4df9877b5289911e2feaa

See more details on using hashes here.

File details

Details for the file timeglyph-0.9.1-cp39-abi3-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for timeglyph-0.9.1-cp39-abi3-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 12d789bc5d689ab6d6d908bab1e077fa02f2f438aaa10a8a345b704fca8057cf
MD5 a948cf430e153adac2614132d84a09b6
BLAKE2b-256 f8c26c4464d99310bbb2d6743a9d174980c294c9689de4486585e14476b7e26d

See more details on using hashes here.

Release history Release notifications | RSS feed

0.9.5

3 files

0.9.3

3 files

0.9.2

3 files

This release

0.9.1 This release

3 files

0.7.1

3 files

0.7.0

3 files

0.6.0

3 files

0.5.0

3 files

0.4.1

3 files

0.4.0

3 files

0.3.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page