Skip to content

A–Z

Glossary

Plain-language definitions of the Windows notification and SQLite forensics terms used across the blog.

appdb.dat
The undocumented binary notification store of Windows 8.x and Windows 10 before build 1607, replaced by wpndatabase.db.
FILETIME
Windows' 64-bit timestamp: the number of 100-nanosecond intervals since 1601-01-01 00:00:00 UTC.
Notification handler
An app registered with the Windows notification platform, stored as a NotificationHandler row with its PrimaryId, type and creation time.
Notification payload XML
The XML document that defines a toast, tile or badge: its text lines, images, actions and launch arguments, stored in the Notification.Payload column.
PrimaryId (AppUserModelID)
The identifier of the app behind a notification handler: usually an AppUserModelID such as a package family name plus app id, or a desktop app identifier.
SQLite freeblock
Free space inside a SQLite b-tree page, typically left by a deleted record, whose first four bytes are overwritten and the rest left intact.
SQLite freelist
The list of whole database pages that SQLite no longer uses and keeps for reuse, often with their old content still in place.
Toast notification
A pop-up notification shown by Windows on behalf of an app, kept in the notification center and in wpndatabase.db until it expires or is dismissed.
WAL checkpoint
The SQLite operation that copies committed pages from the -wal file back into the main database file, after which the WAL can be reset.
WNS push channel
A URI issued by the Windows Push Notification Services so a cloud service can send notifications to one app on one device.
wpndatabase.db
The per-user SQLite database where Windows 10 (1607+) and Windows 11 store the notifications apps send, with their content, sending app and times.
Write-ahead log (WAL)
SQLite's journaling mode in which committed changes are appended to a separate -wal file before being copied into the main database at a checkpoint.