What is wpndatabase.db?
wpndatabase.db is the per-user database of the Windows Push Notification platform (WPN). Every toast, tile update and badge an app sends — through the Windows Push Notification Services (WNS) or locally — is stored there with the app that sent it, when it arrived and when it expires. It is a SQLite 3 database in write-ahead-log mode, so recent changes live in wpndatabase.db-wal until Windows checkpoints them.
The notification itself is kept as XML: the text lines the user saw, image references, the buttons and reply boxes, and the launch arguments that open the app on click. That is why the file preserves chat and mail previews, security alerts and download notices — sometimes after the original message or file is gone.
Where is it stored?
- C:\Users\<user>\AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db, with -wal and -shm next to it (Windows 10 1607 and later, Windows 11).
- appdb.dat in the same folder on Windows 10 before build 1607 and on Windows 8.x: a fixed-size binary file, starting with DNPW.
- Main tables: Notification (payload XML, Type, Tag, Group, ArrivalTime, ExpiryTime as FILETIME), NotificationHandler (PrimaryId of the app, HandlerType, CreatedTime), HandlerAssets, HandlerSettings, WNSPushChannel (channel URIs) and Metadata.
What it tells an investigator
- Message content: previews from chat and mail apps with sender and first lines, often still present after the user deleted the conversation.
- Security events: antivirus and Windows security toasts (threat found, quarantined, protection off) with the file names they mention.
- User activity: download-complete notices, removable drive prompts, calendar reminders — each with a precise arrival time.
- Which apps can notify the user: the handler list and its creation times, including apps registered during an incident, and their WNS push channel URIs.
- Deleted notifications: dismissed or expired rows can survive in SQLite free space and older page images; this tool recovers them and labels them clearly.
Limits
- Only notifications the app chose to send, and only until they expire or are dismissed: absence proves nothing.
- The handler CreatedTime / ModifiedTime are stored as text without a documented time zone; notification times (FILETIME) are UTC.
- Recovery of deleted rows is best effort: space is reused over time, and a record cut by a page boundary is marked partial.
- appdb.dat is undocumented; this tool reads the version 3 layout published by the Dissect project and does not name the app of each chunk.
How to acquire it
- Copy wpndatabase.db and wpndatabase.db-wal together, from a volume shadow copy or with KAPE (WindowsNotificationsDB target) or Velociraptor (Windows.Triage.Targets).
- Copy every profile: each user has their own database.
- Hash the files and keep the originals: never open the live database in a SQLite tool, which may checkpoint and rewrite it.
FAQ
Is anything uploaded?
No. The parser is Rust compiled to WebAssembly and runs in a Web Worker in your browser. The files never leave your machine.
Do I need the -wal file?
Yes, whenever it exists. Windows writes new notifications to wpndatabase.db-wal first; without it the most recent notifications are usually missing. The tool warns when a database is dropped without its WAL.
Can it recover deleted notifications?
Often. SQLite leaves deleted records in place until the space is reused. The parser scans free space, the freelist and older page images in the database and WAL, and shows what it finds as "Recovered", with where it came from.
Which Windows versions are supported?
wpndatabase.db from Windows 10 1607 onwards and Windows 11, and appdb.dat (version 3) from earlier Windows 10 builds. The appdb.dat layout is reverse-engineered, so results are marked best effort.
Are the times UTC?
Arrival and expiry times are Windows FILETIME values, which are UTC. Switch to local time in the toolbar. Handler creation times are stored as text without a documented time zone and are shown as stored.