Register to stream ATT&CKcon 2.0 October 29-30

RawDisk

RawDisk is a legitimate commercial driver from the EldoS Corporation that is used for interacting with files, disks, and partitions. The driver allows for direct modification of data on a local computer's hard drive. In some cases, the tool can enact these raw disk modifications from user-mode processes, circumventing Windows operating system security features.[1][2]

ID: S0364
Type: TOOL
Platforms: Windows
Version: 1.0

Techniques Used

Domain ID Name Use
Enterprise T1485 Data Destruction RawDisk was used in Shamoon to write to protected system locations such as the MBR and disk partitions in an effort to destroy data. [3] [4]
Enterprise T1488 Disk Content Wipe RawDisk has been used to directly access the hard disk to help overwrite arbitrarily sized portions of disk content. [2]
Enterprise T1487 Disk Structure Wipe RawDisk was used in Shamoon to help overwrite components of disk structure like the MBR and disk partitions. [3] [4]

Groups That Use This Software

ID Name References
G0032 Lazarus Group [5] [2]

References