Skip to content

Windows Notification Forensics: The wpndatabase.db Guide

What the Windows notification database records, where it lives, what it proves and where it stops: a practical guide to wpndatabase.db for DFIR.

Published on 4 min read

TL;DR. Every Windows 10 (1607+) and Windows 11 profile has a notification database at %LOCALAPPDATA%\Microsoft\Windows\Notifications\wpndatabase.db. It stores the toasts the user received as XML — sender, text lines, buttons, launch arguments — with a UTC arrival and expiry time. It is a SQLite database in WAL mode, so collect wpndatabase.db-wal with it. Deleted notifications often survive in free space.

Notifications are an underrated artifact. They are written by the operating system on behalf of other apps, they carry a copy of content the user saw on screen, and they outlive the thing they announced: the chat message is deleted in the app, the malware is quarantined, the download is moved — the toast is still in the database.

This guide is the entry point for the series; each section links to a deeper article.

What gets stored

Apps raise notifications through the Windows notification platform, either locally or through the Windows Push Notification Services (WNS). The platform keeps them per user in a SQLite database with these main tables (schema as documented by the Plaso and Dissect parsers):

TableWhat it holds
NotificationOne row per toast, tile update or badge: Type, the Payload XML, Tag, Group, ArrivalTime, ExpiryTime
NotificationHandlerOne row per app that can notify: PrimaryId, HandlerType, CreatedTime, ModifiedTime
HandlerAssets, HandlerSettingsKey / value details per handler
WNSPushChannelPush channel URIs issued to apps by WNS, with creation and expiry times
MetadataDatabase-level keys

The full field reference is in wpndatabase.db tables and columns explained.

Where it lives

C:\Users\<user>\AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db, with wpndatabase.db-wal and wpndatabase.db-shm beside it. Windows 10 builds before 1607 and Windows 8.x used a binary file, appdb.dat, in the same folder — see appdb.dat, the legacy notification store. How to copy both safely is covered in the acquisition guide.

What it tells you

  • Message previews. Chat and mail apps put the sender and the first lines of a message in the toast. Those previews stay in the database until the notification expires or is dismissed, and their bytes often longer.
  • Security alerts. Antivirus and Windows security toasts name the threat and often the file path.
  • User activity with precise times. "Download complete", removable-drive prompts, reminders and sign-in prompts all carry an arrival time in UTC (Windows FILETIME).
  • Which apps can notify. The handler table lists every registered app with a creation time, including one that appeared during an incident.
  • Cloud plumbing. WNSPushChannel shows which apps held a push channel and when it was created.

The incident walkthrough shows how these pieces fit into a timeline.

What it does not tell you

A notification exists only if the app chose to raise one, the user had notifications enabled for it, and it has not yet expired or been dismissed. Absence proves nothing. A toast also proves that the system received a notification, not that the user read it. Handler times are stored as text without a documented time zone, unlike the notification FILETIME values, which are UTC.

Deleted notifications

When a notification is dismissed or expires, Windows deletes the row. SQLite does not wipe deleted records by default: they stay in the page as free space, on the freelist, or in older page images in the file and the WAL. Recovering deleted notifications explains the mechanism and its limits.

Tools

Plaso has a windows_push_notification SQLite plugin, Dissect a notifications plugin (both wpndatabase.db and appdb.dat), and Velociraptor's exchange has a Windows.Forensics.NotificationsDatabase artifact. The Windows Notification Parser on this site runs in the browser, applies the WAL, renders each payload as a readable card and recovers deleted rows — see how to analyze wpndatabase.db in your browser.

FAQ

What is wpndatabase.db?

The per-user SQLite database of the Windows Push Notification platform. It stores the toasts, tile updates and badges apps sent to the user, with the sending app, arrival time, expiry time and the notification's XML content.

Does Windows keep notifications after they are dismissed?

The row is deleted, but SQLite usually leaves the deleted record's bytes in the file until the space is reused, so dismissed notifications can often be recovered from free space.

Related articles

A fictional walkthrough: what one user's notification database adds to an intrusion timeline — a download, an antivirus alert, a new app and a deleted chat message.

Step by step: open the Windows notification database and its -wal in a free browser-based parser, triage findings, recover deleted toasts and export CSV, JSON or Timesketch.

Why dismissed and expired toasts survive in wpndatabase.db, where SQLite leaves them (freeblocks, freelist, WAL frames) and how to recover them without fooling yourself.