Convert between forensic timestamp formats for timeline analysis. Edit any field, every other format updates instantly.
Currently showing
—
Recent
Unix Epoch (seconds)
Seconds since 1970-01-01 00:00:00 UTC. Used in Linux/macOS system logs, EXIF metadata, most REST APIs.
Unix Epoch (milliseconds)
Milliseconds since the Unix epoch. Used in JavaScript, Chrome DevTools, and most JSON-based application logs.
Windows FILETIME (decimal)
100-nanosecond intervals since 1601-01-01 00:00:00 UTC. Found in NTFS $STANDARD_INFORMATION, registry key LastWrite time, EVTX records, Active Directory/LDAP timestamp attributes.
ISO 8601 (UTC)
Accepts "YYYY-MM-DD HH:mm:ss" or full ISO 8601. Treated as UTC if no offset is given. Best format for timeline reports.
ISO 8601 (Local)
Same instant, shown and parsed using this browser's local timezone. Useful for correlating with a suspect's stated timezone.
Show 11 more formats Windows extras · Apple · Excel · Julian · GPS · RFC 2822
More Unix
Unix Epoch (nanoseconds)
Nanoseconds since the Unix epoch. Seen in high-resolution Linux audit logs, eBPF/Sysdig traces, and some structured JSON logging pipelines.
More Windows
Windows FILETIME (hex)
Same value as above, shown as the 8-byte hex value commonly seen when parsing raw MFT/registry data with a hex editor.
Windows / .NET Ticks
100-nanosecond intervals since 0001-01-01 00:00:00 UTC. This is System.DateTime.Ticks in .NET/PowerShell — a different epoch than FILETIME above, easy to mix up.
DOS Date/Time (32-bit)
16-bit packed date + 16-bit packed time, 2-second resolution, valid 1980–2107. Found in FAT filesystem directory entries and ZIP archive local file headers. Stores no timezone; historically interpreted as local time on the originating system.
Apple
Chrome / WebKit
Microseconds since 1601-01-01 00:00:00 UTC. Used in Chrome/Edge/Brave History and Cookies SQLite databases (visits.visit_time, last_visit_time).
Mac Absolute Time
Seconds since 2001-01-01 00:00:00 UTC. Used in macOS Cocoa/Core Data (CFAbsoluteTime, NSDate) and many plist timestamp values.
HFS+ / Mac OS Classic
Seconds since 1904-01-01 00:00:00 UTC. Legacy Macintosh filesystem timestamp (local time under classic HFS, UTC under HFS+).
Office / Spreadsheet
OLE Automation Date / Excel Serial Date
Days (with fractional day for time-of-day) since 1899-12-30. This is exactly what a date-formatted Excel cell shows as a raw number, and is also used in Microsoft Office/OLE-COM documents, VBA DATE values, and some registry DATE-typed values.
Legacy / Scientific
Julian Date (astronomical)
Days since noon UTC, 4713 BC (proleptic Julian calendar). Used in astronomy, some satellite/imagery metadata, and legacy mainframe systems.
Navigation
GPS Time
Seconds since 1980-01-06 00:00:00 UTC. GPS time does not apply leap seconds, so it currently runs 18 seconds ahead of UTC (the offset as of the last leap second, 2016-12-31; it will change if a new one is ever scheduled). Relevant to vehicle, drone, and GNSS-device forensics.
Web / Email
RFC 2822 (email Date header)
Standard format for the Date header in email (RFC 5322) and HTTP. What you see when you open a message's raw source / full headers.
Direct Format Conversion
Already know exactly which two formats you're going between? Skip the full list of 16 — pick source and target, then convert one value or paste many at once.
Batch Conversion
Paste a list of timestamps (one per line) from a log export and convert them all at once. Pick the source format if you know it; use auto-detect only when you don't — it's a best-effort magnitude guess, not certain, and ambiguous rows are flagged for manual verification.
INPUT
DETECTED AS
UNIX MS
ISO UTC
ISO LOCAL
FILETIME
WEBKIT
Duration Calculator
Enter two timestamps (any format this tool auto-detects: Unix seconds/ms, ISO date, RFC 2822, etc.) to calculate the elapsed time between them — useful for correlating gaps between events on a timeline.