T1197 BITS Jobs — ATT&CK Technique
Adversaries may abuse BITS jobs to persistently execute code and perform various background tasks. Windows Background Intelligent Transfer Service (BITS) is a low-bandwidth, asynchronous file transfer mechanism exposed through Component Object Model (COM). BITS is commonly used by updaters, messengers, and other applications preferred to operate in the background (using available idle bandwidth) without interrupting other networked applications. File transfer tasks are implemented as BITS jobs, which contain a queue of one or more file operations. The interface to create and manage BITS jobs is accessible through PowerShell and the BITSAdmin tool. Adversaries may abuse BITS to download (e.g. Ingress Tool Transfer), execute, and even clean up after running malicious code (e.g. Indicator Removal). BITS tasks are self-contained in the BITS job database, without new files or registry modifications, and often permitted by host firewalls. BITS enabled execution may also enable persistence by creating long-standing jobs (the default maximum lifetime is 90 days and extendable) or invoking an arbitrary program when a job completes or errors (including after system reboots). BITS upload functionalities can also be used to perform Exfiltration Over Alternative Protocol.
Detection coverage (21)
- BITS Client BitsProxy DLL Loaded By Uncommon Process low
- Bitsadmin to Uncommon TLD high
- Bitsadmin to Uncommon IP Server Address high
- New BITS Job Created Via PowerShell low
- BITS Transfer Job Download To Potential Suspicious Folder high
- New BITS Job Created Via Bitsadmin low
- BITS Transfer Job With Uncommon Or Suspicious Remote TLD medium
- BITS Transfer Job Downloading File Potential Suspicious Extension medium
- BITS Transfer Job Download From File Sharing Domains high
- BITS Transfer Job Download From Direct IP high
- Suspicious Download From Direct IP Via Bitsadmin high
- Suspicious Download From File-Sharing Website Via Bitsadmin high
- File Download Via Bitsadmin To A Suspicious Target Folder high
- File Download Via Bitsadmin medium
- Monitoring For Persistence Via BITS medium
- File With Suspicious Extension Downloaded Via Bitsadmin high
- BITS Job Persistence
- BITSAdmin Download File
- Cisco NVM - Curl Execution With Insecure Flags
- Cisco NVM - Suspicious Download From File Sharing Website
- PowerShell Start-BitsTransfer