RawDisk is a legitimate commercial driver from the EldoS Corporation that is used for interacting with files, disks, and partitions. The driver allows for direct modification of data on a local computer's hard drive. In some cases, the tool can enact these raw disk modifications from user-mode processes, circumventing Windows operating system security features.
|Enterprise||T1485||Data Destruction||RawDisk was used in Shamoon to write to protected system locations such as the MBR and disk partitions in an effort to destroy data.|
|Enterprise||T1488||Disk Content Wipe||RawDisk has been used to directly access the hard disk to help overwrite arbitrarily sized portions of disk content.|
|Enterprise||T1487||Disk Structure Wipe||RawDisk was used in Shamoon to help overwrite components of disk structure like the MBR and disk partitions.|
Groups that use this software:Lazarus Group