Skip to content

wpndatabase.db Tables and Columns Explained

Field reference for the Windows notification database: Notification, NotificationHandler, HandlerAssets, WNSPushChannel, FILETIME times and the toast XML payload.

Published on 3 min read

TL;DR. Join Notification.HandlerId to NotificationHandler.RecordId to get the sending app (PrimaryId). Convert ArrivalTime / ExpiryTime from FILETIME (UTC). Read the notification itself from the Payload XML. Handler dates are text, time zone undocumented.

The column list below matches the CREATE TABLE statements published with the Plaso windows_push_notification plugin. Always read the schema of your file too: Windows builds can add columns, and a good parser resolves columns by name.

Notification

ColumnMeaning
OrderINTEGER PRIMARY KEY, the rowid
IdNotification id, unique (ON CONFLICT REPLACE: an update with the same id replaces the row)
HandlerId→ NotificationHandler.RecordId
ActivityIdGUID blob
Typetoast, tile, badge…
PayloadThe notification content, XML when PayloadType is Xml
Tag, GroupApp-chosen labels used to replace or remove notifications; chat apps often put a message or thread id here
ExpiryTimeWhen Windows will remove it (FILETIME, UTC)
ArrivalTimeWhen it was received (FILETIME, UTC)
DataVersion, BootIdInternal counters
ExpiresOnRebootBoolean stored as text ('FALSE' by default)

NotificationHandler

ColumnMeaning
RecordIdPrimary key
PrimaryIdThe app's identity: a package family name plus app id (Publisher.App_hash!App), a desktop identifier such as Microsoft.Office.OUTLOOK.EXE.15, a system id such as Windows.SystemToast.…, or a path whose first element can be a known-folder GUID
HandlerTypeFor example app:desktop, app:immersive, app:system
WNSId, WNFEventNamePush service and notification-facility identifiers
CreatedTime, ModifiedTimeText dates (YYYY-MM-DD HH:MM:SS); the time zone is not documented, so check against a known event before using them in a UTC timeline
ParentId, ContainerSidRelationships and app container SID

A known-folder GUID prefix such as {6D809377-6AF0-444B-8957-A3773F02200E} stands for Program Files; the parser renders it as %ProgramFiles%.

HandlerAssets, HandlerSettings, NotificationData

Key / value tables keyed by handler (AssetKey / AssetValue, SettingKey / Value) or by notification id. Their keys vary by app and Windows build. Keep them in your export rather than interpreting every key.

WNSPushChannel

ChannelId, HandlerId, Uri, CreatedTime, ExpiryTime. The URI is the endpoint a cloud service uses to push to this app on this device; its creation time tells you when the app registered for push.

FILETIME in practice

A FILETIME is a 64-bit count of 100-nanosecond intervals since 1601-01-01 UTC. Subtract 116444736000000000 and divide by 10,000,000 to get Unix seconds. Values exceed 2^53, so keep them as strings when moving through JSON or spreadsheets — the parser exports the raw values as text next to the converted times.

The payload XML

Toasts use Microsoft's toast content schema:

<toast launch="app-defined-arguments">
  <visual>
    <binding template="ToastGeneric">
      <text>Title line</text>
      <text>Body line</text>
      <text placement="attribution">via App</text>
      <image placement="appLogoOverride" src="ms-appdata:///local/a.png" alt="…"/>
    </binding>
  </visual>
  <actions>
    <input id="reply" type="text" placeHolderContent="Type a reply"/>
    <action content="Reply" arguments="…" activationType="background"/>
  </actions>
</toast>

What matters for an investigation: the <text> lines (what the user saw), launch and action arguments (often an item id or URL), and <image src> references (a remote URL or a local app file). Tiles use <tile> with several <binding> sizes that usually repeat the same text; badges are a single <badge value="…"/>.

FAQ

What time format does wpndatabase.db use?

ArrivalTime and ExpiryTime in the Notification table, and the WNSPushChannel times, are Windows FILETIME values: 100-nanosecond intervals since 1601-01-01 UTC. NotificationHandler CreatedTime and ModifiedTime are text dates without a documented time zone.

Join Notification.HandlerId to NotificationHandler.RecordId. The handler's PrimaryId identifies the app, for example a package family name with an application id, or a desktop app identifier.

Related articles

Why dismissed and expired toasts survive in wpndatabase.db, where SQLite leaves them (freeblocks, freelist, WAL frames) and how to recover them without fooling yourself.

What the Windows notification database records, where it lives, what it proves and where it stops: a practical guide to wpndatabase.db for DFIR.

What appdb.dat is, which Windows versions use it, how its fixed chunks hold toasts, tiles and badges, and what you can and cannot get out of it.