Skip to main content

timeglyph

Decode, encode, and identify forensic timestamps — ranked, scored, and cited.

Python bindings for timeglyph, the Rust engine that reads a raw timestamp value every way a system might have written it and returns the results ranked by likelihood, each with the spec citation — honest about the ambiguity instead of guessing one answer. Built for DFIR work in notebooks, plaso, and Timesketch.

Install

pip install timeglyph

A single self-contained extension (stable-ABI wheel, CPython 3.9+). No system dependencies.

Use

import timeglyph

# One raw value → every plausible reading, ranked and cited:
for r in timeglyph.identify("133801920000000000"):
    print(f'{r["score"]:.2f}  {r["format_id"]:10}  {r["rendered"]}  ({r["citation"]})')
0.89  filetime    2025-01-01T08:00:00Z  ([MS-DTYP] §2.3.3 FILETIME)
0.70  ...

Each reading is a dict: format_id, label, rendered, instant, score, citation, assumptions, components, sentinel. A raw value is usually underdetermined, so identify returns all confident readings (16 for the example above) rather than a single verdict — you decide which fits the artifact.

Need the raw payload for a pipeline? timeglyph.identify_json(value) returns the same result as a JSON string.

Learn more

Privacy Policy · Terms of Service · © 2026 Security Ronin Ltd

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

timeglyph-0.9.5-cp39-abi3-win_amd64.whl (312.5 kB view details)

Uploaded CPython 3.9+Windows x86-64

timeglyph-0.9.5-cp39-abi3-manylinux_2_34_x86_64.whl (496.2 kB view details)

Uploaded CPython 3.9+manylinux: glibc 2.34+ x86-64

timeglyph-0.9.5-cp39-abi3-macosx_11_0_arm64.whl (429.3 kB view details)

Uploaded CPython 3.9+macOS 11.0+ ARM64

File details

Details for the file timeglyph-0.9.5-cp39-abi3-win_amd64.whl.

File metadata

  • Download URL: timeglyph-0.9.5-cp39-abi3-win_amd64.whl
  • Upload date:
  • Size: 312.5 kB
  • Tags: CPython 3.9+, Windows x86-64
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for timeglyph-0.9.5-cp39-abi3-win_amd64.whl
Algorithm Hash digest
SHA256 a75996d4087be6622fd718b3b9ad2e69536361fa44338249fb8982f7eed15ab7
MD5 1f9245a0d8be68fe11cd53a3f86b6b9e
BLAKE2b-256 149c23113d834dfd00b0e8614ee1a0168912484592c2a957648867693d6d72b8

See more details on using hashes here.

File details

Details for the file timeglyph-0.9.5-cp39-abi3-manylinux_2_34_x86_64.whl.

File metadata

File hashes

Hashes for timeglyph-0.9.5-cp39-abi3-manylinux_2_34_x86_64.whl
Algorithm Hash digest
SHA256 86da9f1940cba2489c9c4f330da6bf4d33d26ab9d69876b29f25aca25e122fb7
MD5 14a77eb78f17847f3d045dd96dc0fc52
BLAKE2b-256 6dff0042ecc302837939c1da15534ccd3b0204c9962d9cd6c5ac04fc0e43bc20

See more details on using hashes here.

File details

Details for the file timeglyph-0.9.5-cp39-abi3-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for timeglyph-0.9.5-cp39-abi3-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 f78ada0fd130f9ec7eb400ad769ff97aaf139cca7f542b4cf054bc907a83853b
MD5 cc738156396ea73655eaeba12ce10365
BLAKE2b-256 1c7c4121c1acca16f9afa7301c9829f9f68cb4cc6b42622cc0b4ef331e8eb7b5

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

0.9.5 This release

3 files

0.9.3

3 files

0.9.2

3 files

0.9.1

3 files

0.7.1

3 files

0.7.0

3 files

0.6.0

3 files

0.5.0

3 files

0.4.1

3 files

0.4.0

3 files

0.3.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page