What is the MDMP file format?
A file with the .mdmp extension is a system file created by Windows to capture a snapshot of memory and process state at the moment of failure. Its name is short for Windows Minidump. .mdmp files are binary in format and typically small compared to full memory dumps.
The file is created each time an unexpected crash occurs - for instance, during a Blue Screen of Death (BSOD), indicating a serious system or software error. Kernel minidumps are stored in the %SystemRoot%\Minidump\ folder. A file name encodes the crash date in month-day-year order followed by a sequential dump number - for example, Mini081518-01.mdmp for a crash on August 15, 2018.
User-mode applications can also generate .mdmp files programmatically via the MiniDumpWriteDump API in DbgHelp.dll. Every .mdmp begins with the four-byte ASCII signature MDMP at byte offset 0, distinguishing it from full kernel dumps (see .DMP), which use a PAGEDUMP or PAGEDU64 signature instead. Windows Error Reporting may save .mdmp files alongside .WER crash reports.
Opening .mdmp files requires a debugger such as WinDbg or Visual Studio.
Security & safety
RISK: LOWA minidump is passive diagnostic data and cannot execute, so opening one is safe. The real concern is privacy: a dump captures live memory, which can include fragments of whatever the program held - file paths, usernames, in some cases passwords, tokens or document contents. Treat a minidump from a sensitive app as sensitive data; only share it with trusted developers/vendors. Beware files named 'something.mdmp.exe' or fake 'dump readers' bundled with adware - open dumps only in genuine Microsoft tools (WinDbg/Visual Studio) or reputable utilities.
Format details
in a nutshellPrograms that open MDMP files
Technical details
deep spec| File signature | ASCII "MDMP" (hex 4D 44 4D 50) at byte offset 0 |
| Developer | Microsoft |
| Format structure | Binary; root is MINIDUMP_HEADER, data organized as typed streams enumerated in MINIDUMP_DIRECTORY |
| MIME type | application/x-msdownload |
| Generation API | MiniDumpWriteDump() in DbgHelp.dll (Windows SDK); also triggered automatically by Windows Error Reporting |
| Kernel minidump storage path | %SystemRoot%\Minidump\ (typically C:\Windows\Minidump\) |
| File naming convention | MiniMMDDYY-NN.mdmp - month, day, two-digit year, sequential crash number |
| Dump type field | MINIDUMP_TYPE enum embedded in the file controls captured content: MiniDumpNormal, MiniDumpWithHeap, MiniDumpWithFullMemory, and others |
| Captured data | Thread call stacks, loaded module list, process and system information; optionally heap contents, handle table, unloaded modules |
| Version field | 16-bit implementation version at offset 4 of MINIDUMP_HEADER; current value typically 0xA793 |
| Distinguished from full kernel dumps | Full dumps (MEMORY.DMP) use PAGEDUMP/PAGEDU64 signature and capture all RAM; .mdmp captures only selected process-level data |
| Platform | Windows-only; no native Linux or macOS support (Wine can produce compatible files for POSIX processes) |
| Processor architecture record | Architecture stored in MINIDUMP_SYSTEM_INFO stream; supports x86, x64, ARM, and ARM64 within the same container format |
| Primary analysis tools | WinDbg (Windows SDK / Microsoft Store), Visual Studio debugger, BlueScreenView, WhoCrashed |
| Released | Windows XP / Visual Studio era (MiniDumpWriteDump API, early 2000s) |
| Specification | learn.microsoft.com |
MDMP conversions
Community Q&A
asked by usersNo questions yet - be the first to ask about MDMP files.