1200KM / detection
T1197 BITS Jobs — Detection Rules
Detection workspace for T1197 BITS Jobs: 15 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Bitsadmin to Uncommon IP Server Address · test · high · {"category":"proxy"}
- Bitsadmin to Uncommon TLD · test · high · {"category":"proxy"}
- New BITS Job Created Via Bitsadmin · test · low · {"product":"windows","service":"bits-client"}
- New BITS Job Created Via PowerShell · test · low · {"product":"windows","service":"bits-client"}
- BITS Transfer Job Downloading File Potential Suspicious Extension · test · medium · {"product":"windows","service":"bits-client"}
- BITS Transfer Job Download From File Sharing Domains · test · high · {"product":"windows","service":"bits-client"}
- BITS Transfer Job Download From Direct IP · test · high · {"product":"windows","service":"bits-client"}
- BITS Transfer Job With Uncommon Or Suspicious Remote TLD · test · medium · {"product":"windows","service":"bits-client"}
- BITS Transfer Job Download To Potential Suspicious Folder · test · high · {"product":"windows","service":"bits-client"}
- File Download Via Bitsadmin · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Download From Direct IP Via Bitsadmin · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Download From File-Sharing Website Via Bitsadmin · test · high · {"category":"process_creation","product":"windows"}
- File With Suspicious Extension Downloaded Via Bitsadmin · test · high · {"category":"process_creation","product":"windows"}
- File Download Via Bitsadmin To A Suspicious Target Folder · test · high · {"category":"process_creation","product":"windows"}
- Monitoring For Persistence Via BITS · test · medium · {"product":"windows","category":"process_creation"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0098 Detect abuse of Windows BITS Jobs for download, execution and persistence
AN0274 Analytic 0274
Behavioral chain: (1) An actor creates or modifies a BITS job via bitsadmin.exe, PowerShell BITS cmdlets, or COM; (2) the job performs HTTP(S)/SMB network transfers while the owning user is logged on; (3) upon job completion/error, BITS launches a notify command (SetNotifyCmdLine) from svchost.exe -k netsvcs -s BITS, often establishing persistence by keeping long-lived jobs. The strategy correlates process creation, command/script telemetry, BITS-Client operational events, and network connections initiated by BITS.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.