How to Analyze wpndatabase.db in Your Browser
Step by step: open the Windows notification database and its -wal in a free browser-based parser, triage findings, recover deleted toasts and export CSV, JSON or Timesketch.
TL;DR. Drop wpndatabase.db with wpndatabase.db-wal on the Windows Notification Parser. Nothing is uploaded: a Rust parser compiled to WebAssembly runs in your browser. Use the findings bar, the time range and the app filter to get to the notifications that matter, then export.
Step 1 — Collect the database with its WAL
Take the whole Notifications folder of every profile, from a shadow copy or a triage collection, as explained in the acquisition guide. The WAL matters: new notifications are written there first.
Step 2 — Load the files
Drop the two files, the Users folder of a collection, or a ZIP (KAPE, Velociraptor, tar or Compress-Archive output). The parser pairs each database with its -wal, ignores -shm, and explains any file it skips. appdb.dat from older Windows 10 builds is read too. No data? Use Try a sample: a synthetic database from a fictional intrusion.
Step 3 — Read warnings and findings
The warnings panel tells you if a WAL was missing, did not match the database, or stopped at a bad frame. The findings bar counts:
- Recovered: deleted notifications carved from free space (how it works).
- Message preview: chat and mail apps, or toasts with a reply box.
- Security alert: security products, or text about threats and quarantine.
- Download: download notices or archive / executable names.
- Unusual app: an app identified by a path outside Program Files and Windows.
Findings are pointers, not verdicts. Click one to filter the table.
Step 4 — Narrow the time range
Type From / To to the second, use a preset (first hour, last hour, last 24 h of data), drag on the density strip, or open a notification and centre the range on it (±5 min, ±1 h, ±24 h). The range applies to arrival by default; switch to expiry when you need it. It is saved in the page address, so a reload or a shared link keeps it.
Step 5 — Open a notification
The detail panel renders the notification as text: app, title, body lines, attribution, image references (never fetched), reply boxes and buttons. Below it: launch arguments, tag and group, notification id, raw FILETIMEs, WAL status and, for recovered rows, the page or WAL frame they came from. The raw XML is shown indented.
The Apps & channels view lists every notification handler with its type, creation time and WNS push channel URIs. Click an app to filter notifications by it.
Step 6 — Export
- CSV: one row per notification, times in UTC, text neutralised against spreadsheet formula injection.
- JSON: every field plus handlers, metadata, warnings and recovery statistics.
- Timesketch CSV:
message,datetime,timestamp_desc, one event per arrival and per expiry.
Exports contain what the table shows: filters and time range apply.