And actually, he is the hardest part of the code...the rest is simply extracting timestamps and translating them, as necessary.Also, I didn't want to miss mentioning that there is a tool for performing temporal analysis of the MFTRipper output from Mark McKinnon over at RedWolf Computer Forensics.