Skip to main content

timeglyph

Decode, encode, and identify forensic timestamps — ranked, scored, and cited.

Python bindings for timeglyph, the Rust engine that reads a raw timestamp value every way a system might have written it and returns the results ranked by likelihood, each with the spec citation — honest about the ambiguity instead of guessing one answer. Built for DFIR work in notebooks, plaso, and Timesketch.

Install

pip install timeglyph

A single self-contained extension (stable-ABI wheel, CPython 3.9+). No system dependencies.

Use

import timeglyph

# One raw value → every plausible reading, ranked and cited:
for r in timeglyph.identify("133801920000000000"):
    print(f'{r["score"]:.2f}  {r["format_id"]:10}  {r["rendered"]}  ({r["citation"]})')
0.89  filetime    2025-01-01T08:00:00Z  ([MS-DTYP] §2.3.3 FILETIME)
0.70  ...

Each reading is a dict: format_id, label, rendered, instant, score, citation, assumptions, components, sentinel. A raw value is usually underdetermined, so identify returns all confident readings (16 for the example above) rather than a single verdict — you decide which fits the artifact.

Need the raw payload for a pipeline? timeglyph.identify_json(value) returns the same result as a JSON string.

Learn more

Privacy Policy · Terms of Service · © 2026 Security Ronin Ltd

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

timeglyph-0.9.2-cp39-abi3-win_amd64.whl (312.4 kB view details)

Uploaded CPython 3.9+Windows x86-64

timeglyph-0.9.2-cp39-abi3-manylinux_2_34_x86_64.whl (496.3 kB view details)

Uploaded CPython 3.9+manylinux: glibc 2.34+ x86-64

timeglyph-0.9.2-cp39-abi3-macosx_11_0_arm64.whl (429.2 kB view details)

Uploaded CPython 3.9+macOS 11.0+ ARM64

File details

Details for the file timeglyph-0.9.2-cp39-abi3-win_amd64.whl.

File metadata

  • Download URL: timeglyph-0.9.2-cp39-abi3-win_amd64.whl
  • Upload date:
  • Size: 312.4 kB
  • Tags: CPython 3.9+, Windows x86-64
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for timeglyph-0.9.2-cp39-abi3-win_amd64.whl
Algorithm Hash digest
SHA256 efc4c3d39f1d88fdd63e126416ac2f9b633e4264fdccd339a9ce7b408fa6da26
MD5 63f8c928677e1787f9c1e9688331a548
BLAKE2b-256 dd5cb7949d55a40b5a3a44521534e70bf52e92b8d46d7799c8d6cb1215b48ca7

See more details on using hashes here.

File details

Details for the file timeglyph-0.9.2-cp39-abi3-manylinux_2_34_x86_64.whl.

File metadata

File hashes

Hashes for timeglyph-0.9.2-cp39-abi3-manylinux_2_34_x86_64.whl
Algorithm Hash digest
SHA256 43a68e40ad8f6fcf7e97124f6088757069f20d9f947b2eb92e442ff8c458b9c8
MD5 a51c36810475dbc10dc4411037846d7b
BLAKE2b-256 18bc25e315e7d7cefa632a22964f5677fb557afced517ae1c99c3938f4305843

See more details on using hashes here.

File details

Details for the file timeglyph-0.9.2-cp39-abi3-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for timeglyph-0.9.2-cp39-abi3-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 0c205affd82ed3188e92c174fca08485c34afc1ccdce881c62a58715088af0a9
MD5 c0cd5b34e907f78ce2c2e6d72b22032f
BLAKE2b-256 474d5fd36801e56a32fa995c416ef7ada7e7c30dbb6766c9ce1abfb26ed8f909

See more details on using hashes here.

Release history Release notifications | RSS feed

0.9.5

3 files

0.9.3

3 files

This release

0.9.2 This release

3 files

0.9.1

3 files

0.7.1

3 files

0.7.0

3 files

0.6.0

3 files

0.5.0

3 files

0.4.1

3 files

0.4.0

3 files

0.3.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page