RawDisk is a legitimate commercial driver from the EldoS Corporation that is used for interacting with files, disks, and partitions. The driver allows for direct modification of data on a local computer's hard drive. In some cases, the tool can enact these raw disk modifications from user-mode processes, circumventing Windows operating system security features.[1][2]

ID: S0364
Type: TOOL
Platforms: Windows

Version: 1.0

Techniques Used

EnterpriseT1485Data DestructionRawDisk was used in Shamoon to write to protected system locations such as the MBR and disk partitions in an effort to destroy data.[3][4]
EnterpriseT1488Disk Content WipeRawDisk has been used to directly access the hard disk to help overwrite arbitrarily sized portions of disk content.[2]
EnterpriseT1487Disk Structure WipeRawDisk was used in Shamoon to help overwrite components of disk structure like the MBR and disk partitions.[3][4]


Groups that use this software:

Lazarus Group