> For the complete documentation index, see [llms.txt](https://www.iblue.team/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://www.iblue.team/memory-forensics-1/acquisition/esxi-vmware-workstation-snapshots.md).

# ESXi / VMware Workstation snapshots

Snapshots generate **.vmem** and **.vmsn** files

Suspended VMs commit memory to **.vmem** and **.vmss** files

These are both required in the operating directory when using Volatility for analysis.
