Jump to: 🔥 Challenge News ⚡ Intel 🔬 Research Labs 📡 All News →
🕜 DFIR Tool

Forensic Timestamp Converter

Convert between forensic timestamp formats for timeline analysis. Enter any format to convert all others.

✎ Input Timestamp

💡 Quick Examples

📈 Converted Results

Enter a timestamp and click Convert to see all format equivalents.

⚠ Forensics reminder: Always document the timezone assumption for every timestamp. Mixing UTC and local timestamps is the most common error in forensic timelines. Use UTC throughout and convert to local time only for presentation.

Timestamp Format Reference

Unix Epoch

Seconds (or ms/µs) since 1970-01-01 00:00:00 UTC. Most common in Linux/web logs.

1705323125

Windows FILETIME

100-nanosecond intervals since 1601-01-01 00:00:00 UTC. Used in NTFS, registry, event logs.

133490665250000000

LDAP / Active Directory

Same value as Windows FILETIME. Used in AD attributes (pwdLastSet, lastLogon, accountExpires).

133490665250000000

ISO 8601

Human-readable international standard. Used in SIEM exports, logs, reports.

2024-01-15T14:32:05Z

HFS+ / Mac Absolute

Seconds since 2001-01-01 00:00:00 UTC. Used in Apple HFS+ filesystem and iOS.

726069125

Chrome / WebKit

Microseconds since 1601-01-01 00:00:00 UTC. Used in Chrome History SQLite database.

13305553925000000

.NET / OLE Date

Days (with decimal fraction for time) since 1899-12-30. Used in Excel, COM, .NET DateTime.

45306.605613

FAT Timestamp

Two 16-bit words encoding date+time. Used in FAT16/FAT32 filesystem metadata.

5447 B34A