wpndatabase.db Tables and Columns Explained
Field reference for the Windows notification database: Notification, NotificationHandler, HandlerAssets, WNSPushChannel, FILETIME times and the toast XML payload.
TL;DR. Join Notification.HandlerId to NotificationHandler.RecordId to get the sending app (PrimaryId). Convert ArrivalTime / ExpiryTime from FILETIME (UTC). Read the notification itself from the Payload XML. Handler dates are text, time zone undocumented.
The column list below matches the CREATE TABLE statements published with the Plaso windows_push_notification plugin. Always read the schema of your file too: Windows builds can add columns, and a good parser resolves columns by name.
Notification
| Column | Meaning |
|---|---|
Order | INTEGER PRIMARY KEY, the rowid |
Id | Notification id, unique (ON CONFLICT REPLACE: an update with the same id replaces the row) |
HandlerId | → NotificationHandler.RecordId |
ActivityId | GUID blob |
Type | toast, tile, badge… |
Payload | The notification content, XML when PayloadType is Xml |
Tag, Group | App-chosen labels used to replace or remove notifications; chat apps often put a message or thread id here |
ExpiryTime | When Windows will remove it (FILETIME, UTC) |
ArrivalTime | When it was received (FILETIME, UTC) |
DataVersion, BootId | Internal counters |
ExpiresOnReboot | Boolean stored as text ('FALSE' by default) |
NotificationHandler
| Column | Meaning |
|---|---|
RecordId | Primary key |
PrimaryId | The app's identity: a package family name plus app id (Publisher.App_hash!App), a desktop identifier such as Microsoft.Office.OUTLOOK.EXE.15, a system id such as Windows.SystemToast.…, or a path whose first element can be a known-folder GUID |
HandlerType | For example app:desktop, app:immersive, app:system |
WNSId, WNFEventName | Push service and notification-facility identifiers |
CreatedTime, ModifiedTime | Text dates (YYYY-MM-DD HH:MM:SS); the time zone is not documented, so check against a known event before using them in a UTC timeline |
ParentId, ContainerSid | Relationships and app container SID |
A known-folder GUID prefix such as {6D809377-6AF0-444B-8957-A3773F02200E} stands for Program Files; the parser renders it as %ProgramFiles%.
HandlerAssets, HandlerSettings, NotificationData
Key / value tables keyed by handler (AssetKey / AssetValue, SettingKey / Value) or by notification id. Their keys vary by app and Windows build. Keep them in your export rather than interpreting every key.
WNSPushChannel
ChannelId, HandlerId, Uri, CreatedTime, ExpiryTime. The URI is the endpoint a cloud service uses to push to this app on this device; its creation time tells you when the app registered for push.
FILETIME in practice
A FILETIME is a 64-bit count of 100-nanosecond intervals since 1601-01-01 UTC. Subtract 116444736000000000 and divide by 10,000,000 to get Unix seconds. Values exceed 2^53, so keep them as strings when moving through JSON or spreadsheets — the parser exports the raw values as text next to the converted times.
The payload XML
Toasts use Microsoft's toast content schema:
<toast launch="app-defined-arguments">
<visual>
<binding template="ToastGeneric">
<text>Title line</text>
<text>Body line</text>
<text placement="attribution">via App</text>
<image placement="appLogoOverride" src="ms-appdata:///local/a.png" alt="…"/>
</binding>
</visual>
<actions>
<input id="reply" type="text" placeHolderContent="Type a reply"/>
<action content="Reply" arguments="…" activationType="background"/>
</actions>
</toast>
What matters for an investigation: the <text> lines (what the user saw), launch and action arguments (often an item id or URL), and <image src> references (a remote URL or a local app file). Tiles use <tile> with several <binding> sizes that usually repeat the same text; badges are a single <badge value="…"/>.
FAQ
What time format does wpndatabase.db use?
ArrivalTime and ExpiryTime in the Notification table, and the WNSPushChannel times, are Windows FILETIME values: 100-nanosecond intervals since 1601-01-01 UTC. NotificationHandler CreatedTime and ModifiedTime are text dates without a documented time zone.
How do I link a notification to the app that sent it?
Join Notification.HandlerId to NotificationHandler.RecordId. The handler's PrimaryId identifies the app, for example a package family name with an application id, or a desktop app identifier.