wpndatabase.db Location and Acquisition
Where the Windows notification database lives on Windows 10 and 11, and how to collect it with its -wal file from live systems, images, KAPE or Velociraptor.
TL;DR. Collect wpndatabase.db and wpndatabase.db-wal from C:\Users\<user>\AppData\Local\Microsoft\Windows\Notifications\ for every profile, at the same instant. On a live system the file is held open: use a shadow copy, KAPE's WindowsNotificationsDB target or Velociraptor. Never open the live database in a SQLite tool first.
The path
| Item | Value |
|---|---|
| Folder | %LOCALAPPDATA%\Microsoft\Windows\Notifications\ |
| Windows 10 1607+ / Windows 11 | wpndatabase.db, wpndatabase.db-wal, wpndatabase.db-shm |
| Windows 10 before 1607, Windows 8.x | appdb.dat |
There is one database per profile. Keep Users\<name>\ in the collected path: the folder itself does not say whose database it is.
Which files to take
| File | Take it? | Why |
|---|---|---|
wpndatabase.db | Yes | The checkpointed database |
wpndatabase.db-wal | Yes | Committed changes not yet written back: often the newest notifications, and older page images useful for recovery |
wpndatabase.db-shm | Optional | A shared-memory index SQLite rebuilds; it holds no evidence the other two lack |
appdb.dat | If present | The pre-1607 store |
Live system: one shadow copy
The database is open while the user is logged on, so a plain copy fails or returns a file of zeros. A single volume shadow copy gives you the database and its WAL from the same instant. From an elevated Windows PowerShell:
New-Item -ItemType Directory -Force -Path C:\triage | Out-Null
$sc = Invoke-CimMethod -ClassName Win32_ShadowCopy -MethodName Create -Arguments @{ Volume = 'C:\' }
$vss = Get-CimInstance -ClassName Win32_ShadowCopy -Filter "ID='$($sc.ShadowID)'"
cmd /c mklink /d C:\triage\vss "$($vss.DeviceObject)\"
robocopy C:\triage\vss\Users C:\triage\Users wpndatabase.db wpndatabase.db-wal appdb.dat /S /XJ /B /R:0 /W:0 /NP /NDL
cmd /c rmdir C:\triage\vss
$vss | Remove-CimInstance
The result is C:\triage\Users\<user>\AppData\Local\Microsoft\Windows\Notifications\ for each profile.
KAPE
kape.exe --tsource C: --tdest C:\triage\kape --target WindowsNotificationsDB
The WindowsNotificationsDB target uses the mask wpndatabase.db* (so the WAL comes along) plus appdb.dat, for every user.
Velociraptor
Collect the Windows.Triage.Targets artifact from the Velociraptor Triage project with the WindowsNotificationsDB target, from the GUI or an offline collector. The built-in Windows.Search.FileFinder artifact with a glob on the Notifications folder and file upload enabled works too.
Disk images
Mount the image read-only and export Users\*\AppData\Local\Microsoft\Windows\Notifications\ with its structure. Check the image's volume shadow copies as well: an older snapshot can hold notifications that have since expired.
Mistakes that cost evidence
- Opening the live database in a SQLite browser. Opening a WAL database can run a checkpoint that folds the WAL into the main file and resets it — the older page images you wanted for recovery are gone.
- Copying the database without its WAL, or the two at different moments. The first loses the newest notifications; the second mixes states. A WAL from a different database is detected and ignored by the parser.
- Waiting. Notifications expire and dismissed ones are deleted; free space is reused as new notifications arrive.
Hash the files as collected, then analyse copies — for example with the browser-based parser.
FAQ
Where is the Windows notification database stored?
In C:\Users\<user>\AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db, with wpndatabase.db-wal and wpndatabase.db-shm next to it. Older Windows 10 builds use appdb.dat in the same folder.
Which KAPE target collects it?
WindowsNotificationsDB. It collects wpndatabase.db* (database, -wal and -shm) and appdb.dat from every user profile. The same target is available in Velociraptor's Windows.Triage.Targets artifact.