What is the DMP file format?
.dmp files are used within Windows as space for storing information after a system malfunction. They capture a snapshot of physical memory (RAM) at the moment of a crash, enabling engineers and support staff to diagnose the root cause after the event.
.dmp files are usually generated automatically when an error or malfunction occurs, in order to diagnose and eliminate the problem. On older Windows versions (XP era), a utility called Savedump.exe assisted in writing the dump during the first startup after a crash; on modern Windows the kernel writes the dump directly during the Blue Screen of Death sequence. Every .dmp file carries a binary signature: minidumps begin with the four-byte magic MDMP (4D 44 4D 50) at offset 0, while full kernel dumps start with PAGEDUMP (32-bit) or PAGEDU64 (64-bit).
Files are usually named Memory.dmp, but you may also encounter the minidump form - MiniMMDDYY-NN.dmp (M = month, D = day, Y = year, NN = sequence number) - stored in %SystemRoot%\Minidump so individual crashes are not overwritten.
Types of memory dumps generated in Windows:
- Full memory dump - after being created, all content of physical RAM is stored within the
.dmpfile; it may cover a large portion of disk space. Stored in%SystemRoot%\Memory.dmpand overwritten if another malfunction occurs. - Kernel memory dump - only kernel-mode memory is recorded; memory assigned to user programs is omitted. Also stored as
%SystemRoot%\Memory.dmpand overwritten by the next crash. - Small memory dump (minidump) - typically 64 KB, containing the STOP parameters, PRCB processor context, EPROCESS/ETHREAD structures for the halted thread, and a list of loaded drivers. Stored in
%SystemRoot%\Minidumpand not overwritten. - Automatic memory dump - introduced in Windows 8, similar to a kernel dump but lets Windows dynamically size the paging file to ensure the dump fits.
A closely related variant is the .mdmp file (an explicitly-named minidump), and Windows Error Reporting may also produce .hdmp heap dump companions. On Linux/Unix systems a similar concept is the core dump. Crash dumps can be analyzed with WinDbg, Microsoft Visual Studio (which can open .dmp files directly for managed code), or NirSoft BlueScreenView for quick minidump inspection.
Security & safety
RISK: MEDIUMA .dmp file does not execute - opening it in a debugger cannot infect you. The real concern is privacy: a full memory dump (MEMORY.DMP) or an application dump can contain whatever was in RAM at crash time - passwords, encryption keys, open-document contents, session tokens. Before sending a dump to support or uploading it, be aware it may hold sensitive data; prefer minidumps over full dumps when sharing. Crash dumps are also safe to DELETE to reclaim disk space (Disk Cleanup > 'System error memory dump files'); Windows recreates them on the next crash.
Format details
in a nutshell- Oracle Data Pump / exp export (.dmp) - A proprietary binary database export from Oracle's expdp/exp utilities, loaded back into a database with impdp/imp - not a memory dump and unreadable by a debugger.
Programs that open DMP files
Technical details
deep spec| File format | Binary (not human-readable; structured binary memory snapshot) |
| Magic bytes - minidump | 4D 44 4D 50 (ASCII: MDMP) at offset 0 |
| Magic bytes - 32-bit kernel dump | 50 41 47 45 44 55 4D 50 (ASCII: PAGEDUMP) at offset 0 |
| Magic bytes - 64-bit kernel dump | 50 41 47 45 44 55 36 34 (ASCII: PAGEDU64) at offset 0 |
| MIME type | application/octet-stream |
| Developer | Microsoft |
| Default path - full / kernel dump | %SystemRoot%\Memory.dmp (overwritten by the next crash) |
| Default path - minidump | %SystemRoot%\Minidump\MiniMMDDYY-NN.dmp (individual files, kept across crashes) |
| Minidump base size | 64 KB minimum; modern Windows may produce larger minidumps |
| Dump types | Full, Kernel, Small (Minidump), Automatic (Windows 8+), Active memory dump (Windows 10+) |
| Creation trigger | Kernel panic / Blue Screen of Death (BSOD); also creatable manually via Task Manager or ProcDump |
| Minidump contents | STOP bugcheck code and parameters, PRCB, EPROCESS, ETHREAD structures, loaded driver list |
| Primary analysis tool | WinDbg / WinDbg Preview (Windows Debugger, part of Debugging Tools for Windows) |
| Secondary analysis tools | Microsoft Visual Studio (managed code dumps), NirSoft BlueScreenView (minidump viewer) |
| Dump type configuration | System Properties → Advanced → Startup and Recovery → Write debugging information |
| Related extensions | .mdmp (explicit minidump variant), .hdmp (heap dump), .dump, .core (Linux equivalent) |
| Released | Windows minidump format from the Windows 2000/XP era |
| Specification | learn.microsoft.com |
DMP conversions
Community Q&A
asked by usersNo questions yet - be the first to ask about DMP files.