Skip to content

appdb.dat: the Legacy Windows Notification Store

What appdb.dat is, which Windows versions use it, how its fixed chunks hold toasts, tiles and badges, and what you can and cannot get out of it.

Published on 2 min read

TL;DR. Before Windows 10 build 1607 (and on Windows 8.x), notifications lived in appdb.dat, a fixed-size binary file starting with DNPW, in the same Notifications folder. It is undocumented. The known version 3 layout holds 256 chunks, each with a push URI, a badge, five tiles and twenty toasts with FILETIME arrival and expiry times and their XML. It does not say which app owns a chunk.

Who still has one

Systems upgraded from early Windows 10 builds may keep an appdb.dat beside wpndatabase.db, and images of older machines have only appdb.dat. Collect it anyway: KAPE's WindowsNotificationsDB target already includes it.

Structure

Yogesh Khatri described the file in 2016 (swiftforensics): a DNPW signature, a header with a timestamp and the next notification id, then fixed chunks holding a push URI, badge XML and tile data. The Dissect project publishes a complete structure definition for version 3, which this site's parser follows:

PartContent
Chunk header (first chunk only)DNPW, version, timestamp, next notification id
Chunk infoIn-use flag and write indexes
Push descriptorTwo FILETIMEs and the WNS push URI
BadgeId, timestamp, badge XML
5 tile descriptors + XML slotsId, expiry and arrival FILETIMEs, name, XML length
20 toast descriptors + XML slotsId, expiry and arrival FILETIMEs, two names, XML length

Each chunk is 0x23810 bytes and the file holds 256 of them, so a complete appdb.dat is a little over 37 MB whatever it contains.

What you get

For each in-use chunk: the push URI, the badge value, and each tile and toast with arrival and expiry time (UTC FILETIME), an id, the names stored in the descriptor, and the XML — the same toast schema as in wpndatabase.db, so text lines, launch arguments and actions read the same way.

What you do not get

  • The app. The chunk does not name its app. Correlate the push URI, the names and the content with other artifacts.
  • Certainty. The layout comes from reverse engineering. Version 1 (Windows 8) differs and is reported, not parsed.
  • Deleted entries, beyond what remains in unused slots: there is no SQLite free space to carve.

The Windows Notification Parser reads version 3 and labels every result from it as best effort. For modern systems, see the wpndatabase.db guide.

Related articles

Field reference for the Windows notification database: Notification, NotificationHandler, HandlerAssets, WNSPushChannel, FILETIME times and the toast XML payload.

A fictional walkthrough: what one user's notification database adds to an intrusion timeline — a download, an antivirus alert, a new app and a deleted chat message.

Step by step: open the Windows notification database and its -wal in a free browser-based parser, triage findings, recover deleted toasts and export CSV, JSON or Timesketch.