Skip to content

Windows Notifications in an Incident Investigation

A fictional walkthrough: what one user's notification database adds to an intrusion timeline — a download, an antivirus alert, a new app and a deleted chat message.

Published on 3 min read

TL;DR. In this fictional case, wpndatabase.db confirms a download minute by minute, shows an antivirus alert the user dismissed, reveals an app that registered for notifications during the intrusion, and — from free space — recovers a chat message the attacker's contact sent. Everything below is from the synthetic sample you can load on the home page with Try a sample.

All names, apps and messages are invented. The story continues the FIN-WKS-07 case used across these parser sites: a rogue account, svc_backup, active on 2026-09-14 between about 10:00 and 10:55 UTC.

The question

The team knows svc_backup logged on interactively. They want to know what the account saw and received during the session, and whether anything points to a second person.

09:58 — a mail preview

A mail client toast at 09:58:21 from someone@contoso.example, subject "Re: Q3 payroll export", preview "can you send the payroll export before noon?". It is a normal-looking request — and a reason someone would open the finance share an hour later. The preview is in the database whether or not the mail still exists in the mailbox.

10:02 — "Download complete: tools.zip"

A browser toast at 10:02:04 announces tools.zip in C:\Users\svc_backup\Downloads. Its launch arguments hold the browser's internal download id. This gives a UTC time for the download that can be matched with the file's $MFT times, the browser history and the Zone.Identifier stream.

10:10 — the antivirus spoke

At 10:10:31 a security toast: "Threat quarantined", naming a file under Downloads\tools\. The notification does not tell you whether the user restored the file — the antivirus logs will — but it pins the detection time and the path.

10:11 — a new app

The Apps & channels view shows a handler whose PrimaryId is C:\ProgramData\Intel\m64.exe, created at 2026-09-14 10:11:58 (text, time zone undocumented), with one toast at 10:12. An executable in ProgramData registering as a notification source in the middle of the session is worth a look. The parser flags it as an unusual app; a legitimate updater could produce the same flag, so corroborate with execution artifacts.

10:31 to 10:48 — a chat thread

A chat app shows messages from "Mara K.": "Did the share mount?" at 10:31, then "Transfer done?" at 10:48 — the latter only in the -wal file, not yet checkpointed. A removable-drive prompt at 10:38 ("USB Drive (E:)") sits in between.

The parser also lists a recovered notification at 10:44:15 from the same thread: "Use the E: drive, not the share." The row was deleted (dismissed) but its bytes were still in free space. That message ties the USB prompt to the exfiltration path, and suggests a second person directing the session.

What to write in the report

  • Times are from FILETIME values (UTC) for notifications; handler times are text and are reported "as stored".
  • The recovered message is labelled as recovered, with its source (page and offset), and corroborated before it is relied on.
  • The notifications prove what the system received, not what the user read.

Try it

Load the sample, click Recovered in the findings bar, then set the range around 10:44 (±5 min) from the notification's detail panel. The how-to walks through each control.

Related articles

Step by step: open the Windows notification database and its -wal in a free browser-based parser, triage findings, recover deleted toasts and export CSV, JSON or Timesketch.

Where the Windows notification database lives on Windows 10 and 11, and how to collect it with its -wal file from live systems, images, KAPE or Velociraptor.

What the Windows notification database records, where it lives, what it proves and where it stops: a practical guide to wpndatabase.db for DFIR.