Windows Notifications in an Incident Investigation
A fictional walkthrough: what one user's notification database adds to an intrusion timeline — a download, an antivirus alert, a new app and a deleted chat message.
TL;DR. In this fictional case, wpndatabase.db confirms a download minute by minute, shows an antivirus alert the user dismissed, reveals an app that registered for notifications during the intrusion, and — from free space — recovers a chat message the attacker's contact sent. Everything below is from the synthetic sample you can load on the home page with Try a sample.
All names, apps and messages are invented. The story continues the FIN-WKS-07 case used across these parser sites: a rogue account, svc_backup, active on 2026-09-14 between about 10:00 and 10:55 UTC.
The question
The team knows svc_backup logged on interactively. They want to know what the account saw and received during the session, and whether anything points to a second person.
09:58 — a mail preview
A mail client toast at 09:58:21 from someone@contoso.example, subject "Re: Q3 payroll export", preview "can you send the payroll export before noon?". It is a normal-looking request — and a reason someone would open the finance share an hour later. The preview is in the database whether or not the mail still exists in the mailbox.
10:02 — "Download complete: tools.zip"
A browser toast at 10:02:04 announces tools.zip in C:\Users\svc_backup\Downloads. Its launch arguments hold the browser's internal download id. This gives a UTC time for the download that can be matched with the file's $MFT times, the browser history and the Zone.Identifier stream.
10:10 — the antivirus spoke
At 10:10:31 a security toast: "Threat quarantined", naming a file under Downloads\tools\. The notification does not tell you whether the user restored the file — the antivirus logs will — but it pins the detection time and the path.
10:11 — a new app
The Apps & channels view shows a handler whose PrimaryId is C:\ProgramData\Intel\m64.exe, created at 2026-09-14 10:11:58 (text, time zone undocumented), with one toast at 10:12. An executable in ProgramData registering as a notification source in the middle of the session is worth a look. The parser flags it as an unusual app; a legitimate updater could produce the same flag, so corroborate with execution artifacts.
10:31 to 10:48 — a chat thread
A chat app shows messages from "Mara K.": "Did the share mount?" at 10:31, then "Transfer done?" at 10:48 — the latter only in the -wal file, not yet checkpointed. A removable-drive prompt at 10:38 ("USB Drive (E:)") sits in between.
The parser also lists a recovered notification at 10:44:15 from the same thread: "Use the E: drive, not the share." The row was deleted (dismissed) but its bytes were still in free space. That message ties the USB prompt to the exfiltration path, and suggests a second person directing the session.
What to write in the report
- Times are from
FILETIMEvalues (UTC) for notifications; handler times are text and are reported "as stored". - The recovered message is labelled as recovered, with its source (page and offset), and corroborated before it is relied on.
- The notifications prove what the system received, not what the user read.
Try it
Load the sample, click Recovered in the findings bar, then set the range around 10:44 (±5 min) from the notification's detail panel. The how-to walks through each control.