Glossary
FILETIME
The 64-bit Windows timestamp counting 100-nanosecond intervals since 1 January 1601 UTC, used for BAM last-execution times and registry key times.
A FILETIME is a 64-bit value representing the number of 100-nanosecond intervals since 1 January 1601 (UTC), as defined by Microsoft. It is stored little-endian.
The first 8 bytes of every BAM value are a FILETIME; registry keys also carry a FILETIME last-write time. To convert: divide by 10,000,000 for seconds, subtract 11,644,473,600 to get Unix time. FILETIMEs are UTC — the local time zone is a separate setting. Tools that go through JavaScript Date lose the sub-millisecond part; the BAM/DAM Parser keeps all seven decimals. Worked example: BAM value data format.