appdb.dat: the Legacy Windows Notification Store
What appdb.dat is, which Windows versions use it, how its fixed chunks hold toasts, tiles and badges, and what you can and cannot get out of it.
TL;DR. Before Windows 10 build 1607 (and on Windows 8.x), notifications lived in appdb.dat, a fixed-size binary file starting with DNPW, in the same Notifications folder. It is undocumented. The known version 3 layout holds 256 chunks, each with a push URI, a badge, five tiles and twenty toasts with FILETIME arrival and expiry times and their XML. It does not say which app owns a chunk.
Who still has one
Systems upgraded from early Windows 10 builds may keep an appdb.dat beside wpndatabase.db, and images of older machines have only appdb.dat. Collect it anyway: KAPE's WindowsNotificationsDB target already includes it.
Structure
Yogesh Khatri described the file in 2016 (swiftforensics): a DNPW signature, a header with a timestamp and the next notification id, then fixed chunks holding a push URI, badge XML and tile data. The Dissect project publishes a complete structure definition for version 3, which this site's parser follows:
| Part | Content |
|---|---|
| Chunk header (first chunk only) | DNPW, version, timestamp, next notification id |
| Chunk info | In-use flag and write indexes |
| Push descriptor | Two FILETIMEs and the WNS push URI |
| Badge | Id, timestamp, badge XML |
| 5 tile descriptors + XML slots | Id, expiry and arrival FILETIMEs, name, XML length |
| 20 toast descriptors + XML slots | Id, expiry and arrival FILETIMEs, two names, XML length |
Each chunk is 0x23810 bytes and the file holds 256 of them, so a complete appdb.dat is a little over 37 MB whatever it contains.
What you get
For each in-use chunk: the push URI, the badge value, and each tile and toast with arrival and expiry time (UTC FILETIME), an id, the names stored in the descriptor, and the XML — the same toast schema as in wpndatabase.db, so text lines, launch arguments and actions read the same way.
What you do not get
- The app. The chunk does not name its app. Correlate the push URI, the names and the content with other artifacts.
- Certainty. The layout comes from reverse engineering. Version 1 (Windows 8) differs and is reported, not parsed.
- Deleted entries, beyond what remains in unused slots: there is no SQLite free space to carve.
The Windows Notification Parser reads version 3 and labels every result from it as best effort. For modern systems, see the wpndatabase.db guide.