Skip to content

Windows Timestamp Converter

Convert Windows FILETIME timestamps (100-nanosecond intervals since January 1, 1601 UTC) to and from regular dates - the format used by NTFS file timestamps and the Windows Registry.

Category: time
Use Case: Reading NTFS File Timestamps, Digital Forensics & Registry Analysis, Debugging Windows System Data
Privacy: 100% browser-based

Recommended Settings

Pro Tips

  • Edit either the Windows FILETIME value or the date/time field - the other one updates automatically
  • Use the Copy buttons to grab any value in the format you need, including Unix seconds, milliseconds, or ISO 8601
  • Click Use Current Time to instantly see the current moment represented in this format
  • This runs entirely in your browser - nothing you enter is sent to a server

Most Popular

Most users paste in a raw value from a database or log file to see what date and time it actually represents

When to Use This Tool

Reading NTFS File Timestamps

Convert a raw Windows FILETIME value into a readable date and time.

Digital Forensics & Registry Analysis

Work backward from a known date to the equivalent Windows FILETIME value.

Debugging Windows System Data

Quickly verify what a specific timestamp value actually represents.

Debugging Unexpected Date Values

Figure out why a timestamp value looks wrong by converting it to a human-readable date.

How It Works

1

Take the Windows FILETIME value you enter, which represents 100-nanosecond intervals elapsed since January 1, 1601 UTC, the format Windows uses internally for file and system timestamps

2

Convert it to a standard Unix millisecond timestamp using the correct epoch offset and unit scale

3

Display the result in several common formats, and support converting in the opposite direction too

100% Private

Files never leave your device. All processing happens locally in your browser.

Lightning Fast

Powered by Client-side epoch arithmetic for optimal performance on modern browsers.

Open Source

Built with verified, open-source libraries. Fully transparent.

Frequently Asked Questions

What epoch does this format use?

100-nanosecond intervals elapsed since January 1, 1601 UTC, the format Windows uses internally for file and system timestamps.

Why would I need to convert this format?

Windows uses FILETIME internally for NTFS file creation/modification timestamps, Registry key timestamps, and many Win32 API calls - it's the same format used by LDAP/Active Directory attributes.

Is my data sent to a server?

No. All conversion happens entirely in your browser using JavaScript.

Does this account for timezones?

The underlying timestamp is timezone-independent (a single point in time), and the 'Date & Time' field shows it in your browser's local timezone alongside UTC for reference.

What if I enter an invalid value?

The tool will show a warning that the value doesn't look valid rather than silently displaying an incorrect date.