> For the complete documentation index, see [llms.txt](https://www.ired.team/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://www.ired.team/miscellaneous-reversing-forensics/dump-virtual-box-memory.md).

# Dump Virtual Box Memory

## List Available VMs

```erlang
cd "C:\Program Files\Oracle\VirtualBox\"
.\VBoxManage.exe list vms

...
"win1002 debugee" {5f176ebb-a0cc-4dc7-9c6f-988fcbcca867}
...
```

## Enable Debug Mode

{% code title="linux host" %}

```bash
mantvydas@~: virtualbox --startvm 'yourVMName or VM UUID' --dbg
```

{% endcode %}

## Dump VM Memory

Launch the VirtualBox debug console by navigating to "Debug" menu an select "Command Line":

![](/files/-LIaaB-m1ieDNZur2HfN)

Once you select "Command Line", you will be presented with a console that looks like this:

![memory dump will be a raw file dumped to /home/youruser directory](/files/-LIaZmJjRIjVb7NaLhVr)

To create a memory dump, issue the below command (also highlighted in the above graphic):

{% code title="VM\@virtualbox" %}

```
VBoxDbg> .pgmphystofile 'w7-nc-shell.bin'
```

{% endcode %}

## Persistence

If you want the debug options to be always available, you can:

* export `VBOX_GUI_DBG_ENABLED=true` before launching the VM or
* put export `VBOX_GUI_DBG_ENABLED=true` in your `.bashrc` or `/etc/environment`&#x20;
