Forensic Timestamp Converter

Convert between forensic timestamp formats for timeline analysis. Edit any field, every other format updates instantly.
Currently showing
—
 
 
Unix Epoch (seconds)
Seconds since 1970-01-01 00:00:00 UTC. Used in Linux/macOS system logs, EXIF metadata, most REST APIs.
Unix Epoch (milliseconds)
Milliseconds since the Unix epoch. Used in JavaScript, Chrome DevTools, and most JSON-based application logs.
Windows FILETIME (decimal)
100-nanosecond intervals since 1601-01-01 00:00:00 UTC. Found in NTFS $STANDARD_INFORMATION, registry key LastWrite time, EVTX records, Active Directory/LDAP timestamp attributes.
ISO 8601 (UTC)
Accepts "YYYY-MM-DD HH:mm:ss" or full ISO 8601. Treated as UTC if no offset is given. Best format for timeline reports.
ISO 8601 (Local)
Same instant, shown and parsed using this browser's local timezone. Useful for correlating with a suspect's stated timezone.
Show 11 more formats Windows extras · Apple · Excel · Julian · GPS · RFC 2822
Unix Epoch (nanoseconds)
Nanoseconds since the Unix epoch. Seen in high-resolution Linux audit logs, eBPF/Sysdig traces, and some structured JSON logging pipelines.
Windows FILETIME (hex)
Same value as above, shown as the 8-byte hex value commonly seen when parsing raw MFT/registry data with a hex editor.
Windows / .NET Ticks
100-nanosecond intervals since 0001-01-01 00:00:00 UTC. This is System.DateTime.Ticks in .NET/PowerShell — a different epoch than FILETIME above, easy to mix up.
DOS Date/Time (32-bit)
16-bit packed date + 16-bit packed time, 2-second resolution, valid 1980–2107. Found in FAT filesystem directory entries and ZIP archive local file headers. Stores no timezone; historically interpreted as local time on the originating system.
Chrome / WebKit
Microseconds since 1601-01-01 00:00:00 UTC. Used in Chrome/Edge/Brave History and Cookies SQLite databases (visits.visit_time, last_visit_time).
Mac Absolute Time
Seconds since 2001-01-01 00:00:00 UTC. Used in macOS Cocoa/Core Data (CFAbsoluteTime, NSDate) and many plist timestamp values.
HFS+ / Mac OS Classic
Seconds since 1904-01-01 00:00:00 UTC. Legacy Macintosh filesystem timestamp (local time under classic HFS, UTC under HFS+).
OLE Automation Date / Excel Serial Date
Days (with fractional day for time-of-day) since 1899-12-30. This is exactly what a date-formatted Excel cell shows as a raw number, and is also used in Microsoft Office/OLE-COM documents, VBA DATE values, and some registry DATE-typed values.
Julian Date (astronomical)
Days since noon UTC, 4713 BC (proleptic Julian calendar). Used in astronomy, some satellite/imagery metadata, and legacy mainframe systems.
GPS Time
Seconds since 1980-01-06 00:00:00 UTC. GPS time does not apply leap seconds, so it currently runs 18 seconds ahead of UTC (the offset as of the last leap second, 2016-12-31; it will change if a new one is ever scheduled). Relevant to vehicle, drone, and GNSS-device forensics.
RFC 2822 (email Date header)
Standard format for the Date header in email (RFC 5322) and HTTP. What you see when you open a message's raw source / full headers.