Skip to content

wpndatabase.db Location and Acquisition

Where the Windows notification database lives on Windows 10 and 11, and how to collect it with its -wal file from live systems, images, KAPE or Velociraptor.

Published on 3 min read

TL;DR. Collect wpndatabase.db and wpndatabase.db-wal from C:\Users\<user>\AppData\Local\Microsoft\Windows\Notifications\ for every profile, at the same instant. On a live system the file is held open: use a shadow copy, KAPE's WindowsNotificationsDB target or Velociraptor. Never open the live database in a SQLite tool first.

The path

ItemValue
Folder%LOCALAPPDATA%\Microsoft\Windows\Notifications\
Windows 10 1607+ / Windows 11wpndatabase.db, wpndatabase.db-wal, wpndatabase.db-shm
Windows 10 before 1607, Windows 8.xappdb.dat

There is one database per profile. Keep Users\<name>\ in the collected path: the folder itself does not say whose database it is.

Which files to take

FileTake it?Why
wpndatabase.dbYesThe checkpointed database
wpndatabase.db-walYesCommitted changes not yet written back: often the newest notifications, and older page images useful for recovery
wpndatabase.db-shmOptionalA shared-memory index SQLite rebuilds; it holds no evidence the other two lack
appdb.datIf presentThe pre-1607 store

Live system: one shadow copy

The database is open while the user is logged on, so a plain copy fails or returns a file of zeros. A single volume shadow copy gives you the database and its WAL from the same instant. From an elevated Windows PowerShell:

New-Item -ItemType Directory -Force -Path C:\triage | Out-Null
$sc = Invoke-CimMethod -ClassName Win32_ShadowCopy -MethodName Create -Arguments @{ Volume = 'C:\' }
$vss = Get-CimInstance -ClassName Win32_ShadowCopy -Filter "ID='$($sc.ShadowID)'"
cmd /c mklink /d C:\triage\vss "$($vss.DeviceObject)\"
robocopy C:\triage\vss\Users C:\triage\Users wpndatabase.db wpndatabase.db-wal appdb.dat /S /XJ /B /R:0 /W:0 /NP /NDL
cmd /c rmdir C:\triage\vss
$vss | Remove-CimInstance

The result is C:\triage\Users\<user>\AppData\Local\Microsoft\Windows\Notifications\ for each profile.

KAPE

kape.exe --tsource C: --tdest C:\triage\kape --target WindowsNotificationsDB

The WindowsNotificationsDB target uses the mask wpndatabase.db* (so the WAL comes along) plus appdb.dat, for every user.

Velociraptor

Collect the Windows.Triage.Targets artifact from the Velociraptor Triage project with the WindowsNotificationsDB target, from the GUI or an offline collector. The built-in Windows.Search.FileFinder artifact with a glob on the Notifications folder and file upload enabled works too.

Disk images

Mount the image read-only and export Users\*\AppData\Local\Microsoft\Windows\Notifications\ with its structure. Check the image's volume shadow copies as well: an older snapshot can hold notifications that have since expired.

Mistakes that cost evidence

  • Opening the live database in a SQLite browser. Opening a WAL database can run a checkpoint that folds the WAL into the main file and resets it — the older page images you wanted for recovery are gone.
  • Copying the database without its WAL, or the two at different moments. The first loses the newest notifications; the second mixes states. A WAL from a different database is detected and ignored by the parser.
  • Waiting. Notifications expire and dismissed ones are deleted; free space is reused as new notifications arrive.

Hash the files as collected, then analyse copies — for example with the browser-based parser.

FAQ

Where is the Windows notification database stored?

In C:\Users\<user>\AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db, with wpndatabase.db-wal and wpndatabase.db-shm next to it. Older Windows 10 builds use appdb.dat in the same folder.

Which KAPE target collects it?

WindowsNotificationsDB. It collects wpndatabase.db* (database, -wal and -shm) and appdb.dat from every user profile. The same target is available in Velociraptor's Windows.Triage.Targets artifact.

Related articles

A fictional walkthrough: what one user's notification database adds to an intrusion timeline — a download, an antivirus alert, a new app and a deleted chat message.

Step by step: open the Windows notification database and its -wal in a free browser-based parser, triage findings, recover deleted toasts and export CSV, JSON or Timesketch.

What the Windows notification database records, where it lives, what it proves and where it stops: a practical guide to wpndatabase.db for DFIR.