← ZEKASTRA Forensic

ZEKASTRA / FORENSIC / REFERENCE

Artifact Atlas

Find the format. Inspect the raw value. Keep the source with your conclusion.

4 format records

Scoped to Forensic. Search stays in your browser.

WINDOWS / 100 nsWindows FILETIMEReconstruct a 64-bit value from its two DWORD fields, keep all 100 ns digits and distinguish stored time from observed action.Documented format

Windows FILETIME

Link to this record ↗

01 · Representation semantics

Combine unsigned parts as (high << 32) + low. UTC representation has 100 ns units; an API may assign special meaning to sentinel values.

Unix 100 ns ticks = FILETIME − 116444736000000000

02 · Raw synthetic example

{"dwHighDateTime":27111902,"dwLowDateTime":3577643008}
combined = 116444736000000000

Training example generated from the format definition; not a recovered device or application record.

03 · Repeat the checks

  1. Check which API/field produced the value before treating it as a date.
  2. Recombine the two unsigned DWORDs; compare with the decimal raw value.
  3. Convert the example and add one tick: UTC must gain exactly 0.0000001 s.

Expected conversion of the supplied sample: 1970-01-01T00:00:00.0000000Z

04 · Calculate and document

Arithmetic uses exact integers and the declared unit. Calculation verifies the representation, not an acquired event or source clock.

Interpretation limits

File-system update rules and clock accuracy differ. A timestamp alone does not identify an actor or establish exact event time.

Primary references & revision

ZEKASTRA documentation synthesis · Revision 1.0.0 · 2026-10-10
Independent technical review pending

UNIX / sPOSIX / Unix secondsDeclare seconds explicitly instead of guessing from digit count; compare pre-epoch values and keep the source clock context.Documented format

POSIX / Unix seconds

Link to this record ↗

01 · Representation semantics

Seconds since the Unix epoch use a calendar convention that does not count leap seconds as a continuous elapsed-time scale. Milliseconds are a separate producer convention.

Unix milliseconds = declared Unix seconds × 1000

02 · Raw synthetic example

{"synthetic_event_id":"E-001","timestamp_seconds":1704067200}
unit explicitly supplied: seconds

Training example generated from the format definition; not a recovered device or application record.

03 · Repeat the checks

  1. Inspect producer documentation or schema to confirm the unit and field meaning.
  2. Use the zero boundary: 0 → 1970-01-01; −1 → 1969-12-31 23:59:59 UTC.
  3. Retain the raw integer and note source clock synchronization separately.

Expected conversion of the supplied sample: 2024-01-01T00:00:00.000Z

04 · Calculate and document

Arithmetic uses exact integers and the declared unit. Calculation verifies the representation, not an acquired event or source clock.

Interpretation limits

A ten- or thirteen-digit value does not prove its unit. Conversion cannot recover clock drift, leap-second policy or an undocumented application's event meaning.

Primary references & revision

ZEKASTRA documentation synthesis · Revision 1.0.0 · 2026-10-10
Independent technical review pending

CHROMIUM / µsChromium base::TimeRead the C++ source definition with its recorded snapshot and separate absolute Time from duration-oriented TimeTicks.Documented format

Chromium base::Time

Link to this record ↗

01 · Representation semantics

base::Time stores UTC microseconds since the Windows epoch. TimeTicks has no stable calendar origin. Zero is the null state; extreme signed values are sentinels.

Unix microseconds = Chromium Time − 11644473600000000

02 · Raw synthetic example

{"synthetic_time_us":"13348540800000000","type":"base::Time"}
not a recovered visits table row

Training example generated from the format definition; not a recovered device or application record.

03 · Repeat the checks

  1. Confirm that the source is base::Time, not TimeDelta, TimeTicks or another application's format.
  2. Inspect the header's epoch and serialization comments; retain its blob identifier for your review.
  3. Convert the sample; changing its last digit by one must add one microsecond.

Expected conversion of the supplied sample: 2024-01-01T00:00:00.000000Z

04 · Calculate and document

Arithmetic uses exact integers and the declared unit. Calculation verifies the representation, not an acquired event or source clock.

Interpretation limits

The core type definition does not attest to a particular browser database column. Schema, producer version, null handling and acquisition context must be verified separately.

Primary references & revision

ZEKASTRA documentation synthesis · Revision 1.0.0 · 2026-10-10
Independent technical review pending

SQLITE / s (unixepoch)SQLite time-values & explicit modifiersSQLite has several supported time representations; make the chosen storage rule and conversion modifier visible.Documented format

SQLite time-values & explicit modifiers

Link to this record ↗

01 · Representation semantics

Date/time functions accept ISO text and Julian day values. Numeric Unix seconds require an explicit unixepoch modifier. Storage type alone does not establish event semantics.

Declared SQLite Unix INTEGER → seconds × 1000; SQL: datetime(value, 'unixepoch')

02 · Raw synthetic example

-- Synthetic, repeat locally; no real database is read here.
SELECT sqlite_version();
SELECT datetime(1704067200, 'unixepoch');
SELECT datetime(0, 'unixepoch');
SELECT datetime(0, 'auto');

Training example generated from the format definition; not a recovered device or application record.

03 · Repeat the checks

  1. Record sqlite_version(), table/column name, typeof(value) and the application's writing rule.
  2. Run the synthetic SELECT statements locally; our 3.53.1 check returned 2024-01-01 00:00:00 for the first conversion.
  3. At zero, our check returned 1970-01-01 00:00:00 with unixepoch and −4713-11-24 12:00:00 with auto. The modifier changes interpretation.

Expected conversion of the supplied sample: 2024-01-01T00:00:00.000Z

04 · Calculate and document

Arithmetic uses exact integers and the declared unit. Calculation verifies the representation, not an acquired event or source clock.

Interpretation limits

The selected tool handles integer Unix seconds only. It does not infer a schema, parse Julian days, execute SQLite, or prove the meaning of an application record.

Primary references & revision

ZEKASTRA documentation synthesis · Revision 1.0.0 · 2026-10-10
Independent technical review pending

VERIFICATION SCOPE

Know what was checked

Documented

Epoch, unit and representation are supported by the linked primary reference. Each example is synthetic and the conversion method is explicit.

Calculated locally

Integer boundary cases, fractions, input rejection and exported provenance are covered by automated calculation checks. No database engine or device is executed by this tool.

Still requires review

Real application schemas, acquisition paths, clock accuracy and event meaning need controlled tests and an independent reviewer. No such validation is claimed for these records.

Atlas has no file upload, login or analytics events. Search terms, values and notes remain in the current page unless you copy or download them; only the shared adult-page theme preference uses browser storage.