The sub-techniques beta is now live! Read the release blog post for more info.


RawDisk is a legitimate commercial driver from the EldoS Corporation that is used for interacting with files, disks, and partitions. The driver allows for direct modification of data on a local computer's hard drive. In some cases, the tool can enact these raw disk modifications from user-mode processes, circumventing Windows operating system security features.[1][2]

ID: S0364
Type: TOOL
Platforms: Windows
Version: 1.0
Created: 25 March 2019
Last Modified: 19 April 2019

Techniques Used

Domain ID Name Use
Enterprise T1485 Data Destruction

RawDisk was used in Shamoon to write to protected system locations such as the MBR and disk partitions in an effort to destroy data.[3][4]

Enterprise T1488 Disk Content Wipe

RawDisk has been used to directly access the hard disk to help overwrite arbitrarily sized portions of disk content.[2]

Enterprise T1487 Disk Structure Wipe

RawDisk was used in Shamoon to help overwrite components of disk structure like the MBR and disk partitions.[3][4]

Groups That Use This Software

ID Name References
G0032 Lazarus Group [5] [2]