Skip to content

wpndatabase.db-walappdb.dat

Windows Notification Parser

Every toast a user received — chat and mail previews, security alerts, download notices — from wpndatabase.db and its -wal file, plus deleted notifications recovered from free space. Parsed in your browser with WebAssembly — nothing is uploaded.

Drop wpndatabase.db and its -wal, a folder or a ZIP collection

Works with a single user's Notifications folder, a whole Users tree, a KAPE or Velociraptor collection, or a ZIP. appdb.dat from Windows 10 before 1607 is read too.

The sample is a synthetic database (fictional svc_backup account on FIN-WKS-07) with one deleted notification left in free space.

100% client-side: databases are parsed by WebAssembly in your browser and never uploaded.

How to get your data

Full acquisition guide

Collect wpndatabase.db together with its wpndatabase.db-wal from every user's Notifications folder, then drop the result here. On a live Windows 10 or 11 machine this takes about two minutes.

  1. Collect the database and its -wal
  2. Drop the folder or ZIP here
  3. Parsed in your browser, never uploaded

Paste into Windows PowerShell run as administrator (system drive C:). It creates one shadow copy so the database and its WAL come from the same instant, copies them for every profile, then removes the snapshot.

PowerShell · Admin
New-Item -ItemType Directory -Force -Path C:\triage | Out-Null
$sc = Invoke-CimMethod -ClassName Win32_ShadowCopy -MethodName Create -Arguments @{ Volume = 'C:\' }
$vss = Get-CimInstance -ClassName Win32_ShadowCopy -Filter "ID='$($sc.ShadowID)'"
cmd /c mklink /d C:\triage\vss "$($vss.DeviceObject)\"
robocopy C:\triage\vss\Users C:\triage\Users wpndatabase.db wpndatabase.db-wal appdb.dat /S /XJ /B /R:0 /W:0 /NP /NDL
cmd /c rmdir C:\triage\vss
$vss | Remove-CimInstance

Result: C:\triage\Users\<user>\AppData\Local\Microsoft\Windows\Notifications\ with wpndatabase.db and wpndatabase.db-wal (appdb.dat on old builds). Drop the C:\triage\Users folder here (drag it, or use Choose a folder).

Analysing on another machine? Pack it into one ZIP with the tar.exe built into Windows 10 1803 and later (a ZIP made with PowerShell's Compress-Archive works too):

PowerShell / cmd
tar -a -c -f C:\triage\notifications.zip -C C:\triage Users

Gotchas

  • The database is held open while the user is logged on: a plain copy fails or produces a file full of zeros (listed as "starts with zeros"). Use the shadow-copy command, KAPE or Velociraptor.
  • Take the database and its -wal at the same moment: without the WAL the latest notifications are missing, and a WAL from another database is ignored.
  • Do not open the live database in a SQLite tool before copying it: that can checkpoint the WAL into the database and change what you collect.
  • Notifications expire (ExpiryTime, often a few days) and dismissed ones are deleted: collect early. Deleted rows may survive in free space until SQLite reuses it.

What is wpndatabase.db?

wpndatabase.db is the per-user database of the Windows Push Notification platform (WPN). Every toast, tile update and badge an app sends — through the Windows Push Notification Services (WNS) or locally — is stored there with the app that sent it, when it arrived and when it expires. It is a SQLite 3 database in write-ahead-log mode, so recent changes live in wpndatabase.db-wal until Windows checkpoints them.

The notification itself is kept as XML: the text lines the user saw, image references, the buttons and reply boxes, and the launch arguments that open the app on click. That is why the file preserves chat and mail previews, security alerts and download notices — sometimes after the original message or file is gone.

Where is it stored?

  • C:\Users\<user>\AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db, with -wal and -shm next to it (Windows 10 1607 and later, Windows 11).
  • appdb.dat in the same folder on Windows 10 before build 1607 and on Windows 8.x: a fixed-size binary file, starting with DNPW.
  • Main tables: Notification (payload XML, Type, Tag, Group, ArrivalTime, ExpiryTime as FILETIME), NotificationHandler (PrimaryId of the app, HandlerType, CreatedTime), HandlerAssets, HandlerSettings, WNSPushChannel (channel URIs) and Metadata.

What it tells an investigator

  • Message content: previews from chat and mail apps with sender and first lines, often still present after the user deleted the conversation.
  • Security events: antivirus and Windows security toasts (threat found, quarantined, protection off) with the file names they mention.
  • User activity: download-complete notices, removable drive prompts, calendar reminders — each with a precise arrival time.
  • Which apps can notify the user: the handler list and its creation times, including apps registered during an incident, and their WNS push channel URIs.
  • Deleted notifications: dismissed or expired rows can survive in SQLite free space and older page images; this tool recovers them and labels them clearly.

Limits

  • Only notifications the app chose to send, and only until they expire or are dismissed: absence proves nothing.
  • The handler CreatedTime / ModifiedTime are stored as text without a documented time zone; notification times (FILETIME) are UTC.
  • Recovery of deleted rows is best effort: space is reused over time, and a record cut by a page boundary is marked partial.
  • appdb.dat is undocumented; this tool reads the version 3 layout published by the Dissect project and does not name the app of each chunk.

How to acquire it

  • Copy wpndatabase.db and wpndatabase.db-wal together, from a volume shadow copy or with KAPE (WindowsNotificationsDB target) or Velociraptor (Windows.Triage.Targets).
  • Copy every profile: each user has their own database.
  • Hash the files and keep the originals: never open the live database in a SQLite tool, which may checkpoint and rewrite it.

FAQ

Is anything uploaded?

No. The parser is Rust compiled to WebAssembly and runs in a Web Worker in your browser. The files never leave your machine.

Do I need the -wal file?

Yes, whenever it exists. Windows writes new notifications to wpndatabase.db-wal first; without it the most recent notifications are usually missing. The tool warns when a database is dropped without its WAL.

Can it recover deleted notifications?

Often. SQLite leaves deleted records in place until the space is reused. The parser scans free space, the freelist and older page images in the database and WAL, and shows what it finds as "Recovered", with where it came from.

Which Windows versions are supported?

wpndatabase.db from Windows 10 1607 onwards and Windows 11, and appdb.dat (version 3) from earlier Windows 10 builds. The appdb.dat layout is reverse-engineered, so results are marked best effort.

Are the times UTC?

Arrival and expiry times are Windows FILETIME values, which are UTC. Switch to local time in the toolbar. Handler creation times are stored as text without a documented time zone and are shown as stored.

What appdb.dat is, which Windows versions use it, how its fixed chunks hold toasts, tiles and badges, and what you can and cannot get out of it.

A fictional walkthrough: what one user's notification database adds to an intrusion timeline — a download, an antivirus alert, a new app and a deleted chat message.

Step by step: open the Windows notification database and its -wal in a free browser-based parser, triage findings, recover deleted toasts and export CSV, JSON or Timesketch.