RawDisk is a legitimate commercial driver from the EldoS Corporation that is used for interacting with files, disks, and partitions. The driver allows for direct modification of data on a local computer's hard drive. In some cases, the tool can enact these raw disk modifications from user-mode processes, circumventing Windows operating system security features.[1][2]
| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1485 | Data Destruction |
RawDisk was used in Shamoon to write to protected system locations such as the MBR and disk partitions in an effort to destroy data.[3][4] |
|
| Enterprise | T1561 | .001 | Disk Wipe: Disk Content Wipe |
RawDisk has been used to directly access the hard disk to help overwrite arbitrarily sized portions of disk content.[2] |
| .002 | Disk Wipe: Disk Structure Wipe |
RawDisk was used in Shamoon to help overwrite components of disk structure like the MBR and disk partitions.[3][4] |
||
| ID | Name | References |
|---|---|---|
| G0032 | Lazarus Group |