.DMP

DMP File

Windows Memory / Crash Dump file
Ask a question
QUICK ANSWER

A .dmp file is a snapshot of memory that Windows saves when it crashes (the blue screen of death). You read it with the free WinDbg tool or the simpler NirSoft BlueScreenView to find out which driver caused the crash. MEMORY.DMP is safe to delete; Windows writes a new one on the next crash.

Developer: Microsoft Category: System Files MIME: application/octet-stream
OPENS ON Windows
Related: .NOMEDIA · .DLL · .TMP · .LNK

On this page

19k+ extensions indexed
Last reviewed Aug 8, 2026

Not sure what your file is?

Drop any file into our identifier - we read just the first bytes to name the format.

Identify a file

What is the DMP file format?

.dmp files are used within Windows as space for storing information after a system malfunction. They capture a snapshot of physical memory (RAM) at the moment of a crash, enabling engineers and support staff to diagnose the root cause after the event.

.dmp files are usually generated automatically when an error or malfunction occurs, in order to diagnose and eliminate the problem. On older Windows versions (XP era), a utility called Savedump.exe assisted in writing the dump during the first startup after a crash; on modern Windows the kernel writes the dump directly during the Blue Screen of Death sequence. Every .dmp file carries a binary signature: minidumps begin with the four-byte magic MDMP (4D 44 4D 50) at offset 0, while full kernel dumps start with PAGEDUMP (32-bit) or PAGEDU64 (64-bit).

Files are usually named Memory.dmp, but you may also encounter the minidump form - MiniMMDDYY-NN.dmp (M = month, D = day, Y = year, NN = sequence number) - stored in %SystemRoot%\Minidump so individual crashes are not overwritten.

Types of memory dumps generated in Windows:

  • Full memory dump - after being created, all content of physical RAM is stored within the .dmp file; it may cover a large portion of disk space. Stored in %SystemRoot%\Memory.dmp and overwritten if another malfunction occurs.
  • Kernel memory dump - only kernel-mode memory is recorded; memory assigned to user programs is omitted. Also stored as %SystemRoot%\Memory.dmp and overwritten by the next crash.
  • Small memory dump (minidump) - typically 64 KB, containing the STOP parameters, PRCB processor context, EPROCESS/ETHREAD structures for the halted thread, and a list of loaded drivers. Stored in %SystemRoot%\Minidump and not overwritten.
  • Automatic memory dump - introduced in Windows 8, similar to a kernel dump but lets Windows dynamically size the paging file to ensure the dump fits.

A closely related variant is the .mdmp file (an explicitly-named minidump), and Windows Error Reporting may also produce .hdmp heap dump companions. On Linux/Unix systems a similar concept is the core dump. Crash dumps can be analyzed with WinDbg, Microsoft Visual Studio (which can open .dmp files directly for managed code), or NirSoft BlueScreenView for quick minidump inspection.

Security & safety

RISK: MEDIUM

A .dmp file does not execute - opening it in a debugger cannot infect you. The real concern is privacy: a full memory dump (MEMORY.DMP) or an application dump can contain whatever was in RAM at crash time - passwords, encryption keys, open-document contents, session tokens. Before sending a dump to support or uploading it, be aware it may hold sensitive data; prefer minidumps over full dumps when sharing. Crash dumps are also safe to DELETE to reclaim disk space (Disk Cleanup > 'System error memory dump files'); Windows recreates them on the next crash.

Format details

in a nutshell
FULL NAMEWindows Memory / Crash Dump file
DEVELOPERMicrosoftsince Windows minidump format from the Windows 2000/XP era
CATEGORYSystem Files
MIME TYPEapplication/octet-stream
TYPEBinary memory snapshot (Windows Minidump / kernel / full dump)
This extension is also used by…
  • Oracle Data Pump / exp export (.dmp) - A proprietary binary database export from Oracle's expdp/exp utilities, loaded back into a database with impdp/imp - not a memory dump and unreadable by a debugger.
MAGIC BYTES · FILE SIGNATURE
OFFSET
00010203
HEX
4D444D50
ASCII
MDMP
Windows minidumps start with "MDMP" (4D 44 4D 50) at offset 0. Full kernel dumps start with "PAGEDU64" (x64) or "PAGEDUMP" (x86). A dump file without an MDMP/PAGEDU header from a database server is likely the unrelated Oracle Data Pump export instead.

Programs that open DMP files

Windows3 apps
Microsoft Visual Studio Freemium Open a user-mode application .dmp (File > Open) to inspect the crash with source/symbols; best for developers debugging their own app.
WinDbg (Debugging Tools for Windows) Free File > Open Crash Dump, load the .dmp, then run '!analyze -v' to identify the faulting driver/module. WinDbg is also on the Microsoft Store as 'WinDbg'.
NirSoft BlueScreenView Free Run it; it auto-loads C:\Windows\Minidump and shows each BSOD with the offending driver highlighted - no debugging knowledge needed.

Technical details

deep spec
File formatBinary (not human-readable; structured binary memory snapshot)
Magic bytes - minidump4D 44 4D 50 (ASCII: MDMP) at offset 0
Magic bytes - 32-bit kernel dump50 41 47 45 44 55 4D 50 (ASCII: PAGEDUMP) at offset 0
Magic bytes - 64-bit kernel dump50 41 47 45 44 55 36 34 (ASCII: PAGEDU64) at offset 0
MIME typeapplication/octet-stream
DeveloperMicrosoft
Default path - full / kernel dump%SystemRoot%\Memory.dmp (overwritten by the next crash)
Default path - minidump%SystemRoot%\Minidump\MiniMMDDYY-NN.dmp (individual files, kept across crashes)
Minidump base size64 KB minimum; modern Windows may produce larger minidumps
Dump typesFull, Kernel, Small (Minidump), Automatic (Windows 8+), Active memory dump (Windows 10+)
Creation triggerKernel panic / Blue Screen of Death (BSOD); also creatable manually via Task Manager or ProcDump
Minidump contentsSTOP bugcheck code and parameters, PRCB, EPROCESS, ETHREAD structures, loaded driver list
Primary analysis toolWinDbg / WinDbg Preview (Windows Debugger, part of Debugging Tools for Windows)
Secondary analysis toolsMicrosoft Visual Studio (managed code dumps), NirSoft BlueScreenView (minidump viewer)
Dump type configurationSystem Properties → Advanced → Startup and Recovery → Write debugging information
Related extensions.mdmp (explicit minidump variant), .hdmp (heap dump), .dump, .core (Linux equivalent)
ReleasedWindows minidump format from the Windows 2000/XP era
Specificationlearn.microsoft.com

DMP conversions

Community Q&A

asked by users
Ask a quick question
Get help from people who work with DMP files. Be specific - include your system and software version.
No account needed · answers usually within a day

No questions yet - be the first to ask about DMP files.

Frequently asked questions

How do I open and read a .dmp file?
Use the free WinDbg (File > Open Crash Dump, then '!analyze -v') or, more simply, NirSoft BlueScreenView. Developers can open a user-mode app .dmp in Visual Studio.
Can I delete the MEMORY.DMP file?
Yes. It's a crash diagnostic, not a system requirement. Use Disk Cleanup ('System error memory dump files') to remove it and free space; Windows writes a new one on the next crash.
How do I find out which driver caused my blue screen?
Open the minidump (C:\Windows\Minidump) in BlueScreenView or run '!analyze -v' in WinDbg - both name the driver/module responsible and the stop code.
What is the difference between a minidump and a full memory dump?
A minidump is small (a few hundred KB) with just the crash essentials; a complete memory dump (MEMORY.DMP) captures most of RAM and is much larger but more detailed - and more likely to contain sensitive data.
Is it safe to send a .dmp file to support?
Opening it isn't risky, but a dump can contain sensitive data from memory (passwords, document contents). Prefer a small minidump over a full dump, and only send it to a party you trust.
Is my .dmp a Windows file or an Oracle file?
On a normal PC it's a Windows memory/crash dump (MDMP header). If it came from a database server it may instead be an Oracle Data Pump export, which is a completely different file opened only with Oracle's impdp/imp tools.

References

1Microsoft Learn - Open a Dump File with WinDbglearn.microsoft.com
2Microsoft Learn - Analyze a Kernel-Mode Dump with WinDbglearn.microsoft.com

Keep exploring

across the database

Top extensions this week

1.AQQAQQ Instant Messenger File
2.CRDOWNLOADChrome Partial Download File
3.PARTPartial Download File
4.DATProgram Data File (generic)
5.EXEWindows Executable (Portable Executable)
6.BINCD/DVD Disc Image (BIN/CUE)
7.NOMEDIAAndroid No-Media Marker File
8.RPMSGRestricted Permission Message
9.MDMarkdown Document
10.TMPTemporary File

Related extensions

.NOMEDIAAndroid No-Media Marker File
.DLLDynamic Link Library
.TMPTemporary File
.LNKWindows Shell Link (Shortcut)
.PKGmacOS Installer Package
.ETLEvent Trace Log

Free file tools

An in-browser file identifier and image converter - everything runs on your device.

Open the toolbox

Browse file extensions A-Z