Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0098 — Detect abuse of Windows BITS Jobs for download, execution and persistence
DET0098

Detect abuse of Windows BITS Jobs for download, execution and persistence

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0274 Analytic 0274
Windows

Behavioral chain: (1) An actor creates or modifies a BITS job via bitsadmin.exe, PowerShell BITS cmdlets, or COM; (2) the job performs HTTP(S)/SMB network transfers while the owning user is logged on; (3) upon job completion/error, BITS launches a notify command (SetNotifyCmdLine) from svchost.exe -k netsvcs -s BITS, often establishing persistence by keeping long-lived jobs. The strategy correlates process creation, command/script telemetry, BITS-Client operational events, and network connections initiated by BITS.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=3, 22 WinEventLog:PowerShell EventCode=4103, 4104, 4105, 4106 WinEventLog:System EventCode=7036
[TimeWindow] Correlation window linking job creation, transfer, and notify execution (e.g., 30m–24h depending on environment and BITS retry behavior).
[ExpectedUpdateHosts] Allow-list of corporate update/CDN endpoints that legitimately use BITS (WSUS, MEMCM, vendor updaters).
[SuspiciousCliSwitches] BITSAdmin flags of interest (/transfer, /addfile, /SetNotifyCmdLine, /resume, /setcustomheaders, /setminretrydelay).
[NotifyCmdBlockList] Known risky binaries or folders (e.g., %TEMP%\*.exe, powershell.exe, cmd.exe) used as BITS notify commands.
[UserContext] Scope by interactive users, service accounts, or high-value targets (admins/servers) to reduce benign noise.
[ExternalNetCIDRs] Definition of external/non-corp destinations for network correlation.
[JobLifetimeThreshold] Maximum age or retry count for benign jobs before flagging persistence (e.g., >3 days or retry>20).

Detected Techniques

1

Stealth (1)

Details

MITRE ID
DET0098
STIX ID
x-mitre-detection-strategy--de9fde27-426b-4cb1-afcd-dbe1f7d4273f
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.