A–Z
Glossary
Plain-language definitions of the Windows notification and SQLite forensics terms used across the blog.
- appdb.dat
- The undocumented binary notification store of Windows 8.x and Windows 10 before build 1607, replaced by wpndatabase.db.
- FILETIME
- Windows' 64-bit timestamp: the number of 100-nanosecond intervals since 1601-01-01 00:00:00 UTC.
- Notification handler
- An app registered with the Windows notification platform, stored as a NotificationHandler row with its PrimaryId, type and creation time.
- Notification payload XML
- The XML document that defines a toast, tile or badge: its text lines, images, actions and launch arguments, stored in the Notification.Payload column.
- PrimaryId (AppUserModelID)
- The identifier of the app behind a notification handler: usually an AppUserModelID such as a package family name plus app id, or a desktop app identifier.
- SQLite freeblock
- Free space inside a SQLite b-tree page, typically left by a deleted record, whose first four bytes are overwritten and the rest left intact.
- SQLite freelist
- The list of whole database pages that SQLite no longer uses and keeps for reuse, often with their old content still in place.
- Toast notification
- A pop-up notification shown by Windows on behalf of an app, kept in the notification center and in wpndatabase.db until it expires or is dismissed.
- WAL checkpoint
- The SQLite operation that copies committed pages from the -wal file back into the main database file, after which the WAL can be reset.
- WNS push channel
- A URI issued by the Windows Push Notification Services so a cloud service can send notifications to one app on one device.
- wpndatabase.db
- The per-user SQLite database where Windows 10 (1607+) and Windows 11 store the notifications apps send, with their content, sending app and times.
- Write-ahead log (WAL)
- SQLite's journaling mode in which committed changes are appended to a separate -wal file before being copied into the main database at a checkpoint.