1200KM / tool
RawDisk — Attack Tool
RawDisk is a legitimate commercial driver from the EldoS Corporation that is used for interacting with files, disks, and partitions. The driver allows for direct modification of data on a local computer's hard drive. In some cases, the tool can enact these raw disk modifications from user-mode processes, circumventing Windows operating system security features.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: RawDisk
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- Lazarus Group · G0032 · Pinned relationship source (relationship--00e9a38d-6dc5-4d67-b2fe-977b1c7d17dd)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Cloud Storage Deletion · DC0022
- Command Execution · DC0064
- Drive Access · DC0054
- Drive Modification · DC0046
- Driver Load · DC0079
- File Creation · DC0039
- File Deletion · DC0040
- Process Creation · DC0032
- Process Termination · DC0033
- User Account Authentication · DC0002
- User Account Metadata · DC0013
- Volume Deletion · DC0098
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.