BITS Job Persistence via Bitsadmin Notify Command (via process_creation)

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-05
Updated
2026-09-05

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects bitsadmin.exe configuring a background transfer job to launch a command when it completes, using SetNotifyCmdLine or a long-lived custom job, an abuse of the Background Intelligent Transfer Service for stealthy persistence and execution. BITS abuse appears in the Red Canary Threat Detection Report as a way to survive reboots and run payloads under a trusted service. Detecting notify-command job setup surfaces the persistence mechanism.

Related detections9 linkedT1197 — drag to rearrange
BITS Payload Downloaded via Commandline (via process_creation)
BITS Payload Downloaded via PowerShell (via powershell)
Malicious mshta.exe Spawning bitsadmin via ClickFix Phantom Meet
Suspicious BITSAdmin File Transfer Download (via process_creation)
Suspicious sLoad Payload Download via BITSAdmin LOLBin Transfer (via process_creation)
Suspicious File Download via Certutil URLCache
Suspicious bitsadmin Download to AppData Temp via ClickFix Revenge Chain
Suspicious Bitsadmin Transfer of CoinMiner Archive (via process_creation)
Malicious BITS Job Notify Command Pointing To ProgramData Payload via BITSLOTH
BITS Job Persistence via Bitsadmin Notify Command (via process_creation)
Pivot detection · T1197 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.