1200KM / simulation
T1197 BITS Jobs — Attack Simulation
Adversaries may abuse BITS jobs to persistently execute code and perform various background tasks. Windows Background Intelligent Transfer Service (BITS) is a low-bandwidth, asynchronous file transfer mechanism exposed through Component Object Model (COM). BITS is commonly used by updaters, messengers, and other applications preferred to operate in the background (using available idle bandwidth) without interrupting other networked applications.…
Technique description
Adversaries may abuse BITS jobs to persistently execute code and perform various background tasks. Windows Background Intelligent Transfer Service (BITS) is a low-bandwidth, asynchronous file transfer mechanism exposed through Component Object Model (COM). BITS is commonly used by updaters, messengers, and other applications preferred to operate in the background (using available idle bandwidth) without interrupting other networked applications.…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Bitsadmin Download (cmd)
Procedure 3c73d728-75fb-4180-a12f-6712864d7421; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Persist, Download, & Execute
Procedure 62a06ec5-5754-47d2-bcfc-123d8314c6ae; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Bits download using desktopimgdownldr.exe (cmd)
Procedure afb5e09e-e385-4dee-9a94-6ee60979d114; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Bitsadmin Download (PowerShell)
Procedure f63b8bc4-07e5-4112-acba-56f646f3f0bc; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.