Boot. Confirm. Purge. Done.
Author: Abdullah Kareem
License: MIT License
Compliance: NIST SP 800-88 Rev. 1 – Purge-Level Sanitization
Blog Post: Building a NIST-Compliant Boot-and-Nuke USB Tool: Secure Automated Purge
Download Latest ISO (v1.0.0) | All Releases
# SHA256 checksum verification (update with your actual checksum)
echo "b6a2c4af987ce57f8bea213315071145084e2e890e68058614bba936a92bb9c5 SecureAutomatedPurge-v1.0.0.iso" | sha256sum -cThis utility will PERMANENTLY DESTROY ALL DATA on ALL internal drives!
- No recovery possible
- No undo function
- USB drives excluded (safety feature)
- Requires explicit confirmation
The Secure Automated Purge USB Utility is a bootable Linux ISO that performs NIST SP 800-88 Rev. 1 compliant data sanitization on internal drives. It automatically:
- Detects all internal drives (SATA/NVMe/SAS)
- Selects optimal purge method per drive type
- Executes secure erasure with verification
- Provides detailed audit logs
- Shuts down upon completion
Perfect for:
- IT departments decommissioning equipment
- Electronics recycling centers
- Security-conscious organizations
- Personal use before selling/donating computers
- Boot from USB and follow prompts
- No technical knowledge required
- Automatic drive detection and method selection
- NIST 800-88 Compliant: Meets federal standards for data sanitization
- Multi-method support: NVMe crypto erase, ATA Secure Erase, 3-pass overwrite
- Verification: Post-purge sampling confirms data destruction
- Audit trail: Detailed logs for compliance documentation
- NVMe drives: Format with crypto erase (
--ses=2) or block erase (--ses=1) - SATA SSDs: ATA Secure Erase with password protection
- HDDs: NIST-compliant 3-pass overwrite with
shred
- USB drives automatically excluded
- Requires typing
ERASE ALL DATAto proceed - Shows detailed drive information before purge
- No network connectivity in live environment
# Find your USB drive (be VERY careful to select the right device)
lsblk # or: diskutil list (macOS)
# Write ISO to USB (replace /dev/sdX with your USB device)
sudo dd if=live-image-amd64.hybrid.iso of=/dev/sdX bs=4M status=progress conv=fsync- Download Rufus or balenaEtcher
- Select the ISO file
- Select your USB drive
- Click "Write" or "Flash"
- Insert USB into target computer
- Boot from USB (may need to change boot order in BIOS/UEFI and disable secure boot)
- Wait for automatic startup (system loads into RAM)
- Review drive list carefully
- Type confirmation exactly:
ERASE ALL DATA - Wait for completion (time varies by drive size/type)
- System auto-shutdown when finished
===============================================
SecureAutomatedPurge - NIST 800-88 Purge Utility
Developed by Abdullah Kareem - MIT License
Github.com/CyberKareem
===============================================
Detecting drives...
╔══════════════════════════════════════════╗
WARNING
This will PERMANENTLY DESTROY ALL DATA
╚══════════════════════════════════════════╝
Drives to be purged:
• /dev/nvme0n1 - 500GB - Samsung SSD 970 (Serial: S4EVNX0M702146K)
• /dev/sda - 2TB - WDC WD20EZRZ (Serial: WD-WCC4M0KRD8PZ)
To proceed, type: ERASE ALL DATA
Enter confirmation: _
| Drive Type | Detection Method | Purge Method | NIST Reference |
|---|---|---|---|
| NVMe SSD | /dev/nvme* pattern |
nvme format --ses=2 |
SP 800-88 Rev.1 A.11 |
| SATA SSD | rotational=0 | ATA Secure Erase | SP 800-88 Rev.1 A.10 |
| SATA HDD | rotational=1 | 3-pass shred | SP 800-88 Rev.1 A.8 |
nvme format /dev/nvme0n1 --ses=2 -f
# Destroys encryption keys, rendering data unrecoverable
# Fastest method: typically < 5 secondshdparm --user-master u --security-set-pass p /dev/sda
hdparm --user-master u --security-erase p /dev/sda
# Controller-level erase, bypasses OS
# Speed: ~1 minute per 100GBshred -v -n 3 /dev/sdb
# 3 passes: random, random, zeros
# Speed: ~1 hour per TBPost-purge, the utility samples drive sectors:
- Start (sector 0)
- Middle (sector count/2)
- End (last sector)
Expected result: all zeros or random data (no readable filesystem)
Don't trust pre-built ISOs? Build your own:
sudo apt update
sudo apt install live-build debootstrap xorriso syslinux-utils mtools# Clone repository
git clone https://github.com/CyberKareem/SecureAutomatedPurge-USB.git
cd SecureAutomatedPurge-USB
# Run build process
cd build
./build_iso.shThis utility implements Purge-level sanitization as defined in NIST Special Publication 800-88 Revision 1:
- Cryptographic Erase for self-encrypting drives (Section 3.5)
- Block Erase for flash memory (Appendix A.11)
- Overwrite for magnetic media (Appendix A.8)
- Verification procedures (Section 4.8)
| NIST Requirement | Implementation |
|---|---|
| Target Data Categories | All user data on internal storage |
| Sanitization Level | Purge (suitable for moderate security) |
| Verification Method | Direct sector sampling |
| Documentation | Automated logging to /var/log/purge_audit/ |
- BitLocker Cryptographic Erase - Windows-based crypto erase utility
This project is licensed under the MIT License - see the file for details.
Found a security issue? Please report it responsibly:
- Email: abdullahalikareem@gmail.com
- GPG Key: [Available on request]
Contributions welcome! Please:
- Fork the repository
- Create a feature branch
- Submit a pull request
See CONTRIBUTING.md for details.
- Author: Abdullah Kareem
- X: DM me on X
- LinkedIn: Connect on LinkedIn
- Issues: GitHub Issues
- If this tool helps you, please consider starring the repository!
- NIST for SP 800-88 guidelines
- Debian team for live-build framework
- Open source community for drive utilities
- Beta testers and security reviewers
Remember: With great power comes great responsibility. Always verify you're purging the correct system!
