Windows BITSAdmin Download from File-Sharing Domains Using Suspicious Transfer/Create/Addfile Parameters
Alerts on BITSAdmin downloads from popular file-sharing domains when transfer/create/addfile command-line flags are present.
FreeUnreviewedSigmahighv1
windows-bitsadmin-download-from-file-sharing-domains-using-suspicious-transfer-c-8518ed3d
title: Windows BITSAdmin Download from File-Sharing Domains Using Suspicious Transfer/Create/Addfile Parameters
id: f17c4a3f-c984-49ce-97c9-ef3d26841b9c
related:
- id: 8b48ad89-10d8-4382-a546-50588c410f0d
type: similar
- id: d635249d-86b5-4dad-a8c7-d7272b788586
type: similar
- id: 52182dfb-afb7-41db-b4bc-5336cb29b464
type: similar
- id: ae02ed70-11aa-4a22-b397-c0d0e8f6ea99
type: similar
- id: e0f8ab85-0ac9-423b-a73a-81b3c7b1aa97
type: similar
- id: 7b434893-c57d-4f41-908d-6a17bf1ae98f
type: similar
- id: 42a5f1e7-9603-4f6d-97ae-3f37d130d794
type: similar
- id: 56454143-524f-49fb-b1c6-3fb8b1ad41fb
type: similar
- id: b6e04788-29e1-4557-bb14-77f761848ab8
type: similar
- id: a0d7e4d2-bede-4141-8896-bc6e237e977c
type: similar
- id: 297ae038-edc2-4b2e-bb3e-7c5fc94dd5c7
type: similar
- id: 8518ed3d-f7c9-4601-a26c-f361a4256a0c
type: derived
status: test
description: This rule flags Windows process executions of bitsadmin.exe where the command line includes BITS transfer-related flags (/transfer, /create, /addfile) and references common file-sharing or paste-style domains. Attackers often use BITSAdmin to stage payloads by downloading files from external hosting services while blending in with legitimate Windows tooling. The detection relies on process creation telemetry, specifically the executable path or original file name and the full command line contents indicating both BITS operations and the remote domain.
references:
- https://blog.netspi.com/15-ways-to-download-a-file/#bitsadmin
- https://isc.sans.edu/diary/22264
- https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/
- https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ransomware-hive-conti-avoslocker
- https://www.cisa.gov/uscert/ncas/alerts/aa22-321a
- https://www.microsoft.com/en-us/security/blog/2024/01/17/new-ttps-observed-in-mint-sandstorm-campaign-targeting-high-profile-individuals-at-universities-and-research-orgs/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_bitsadmin_download_file_sharing_domains.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2022-06-28
modified: 2026-03-29
tags:
- attack.persistence
- attack.execution
- attack.stealth
- attack.t1197
- attack.s0190
- attack.t1036.003
- attack.command-and-control
- attack.t1105
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: \bitsadmin.exe
- OriginalFileName: bitsadmin.exe
selection_flags:
CommandLine|contains:
- " /transfer "
- " /create "
- " /addfile "
selection_domain:
CommandLine|contains:
- .githubusercontent.com
- 0x0.st
- anonfiles.com
- bashupload.com
- cdn.discordapp.com
- chunk.io
- ddns.net
- dl.dropboxusercontent.com
- ghostbin.co
- github.com
- glitch.me
- gofile.io
- hastebin.com
- mediafire.com
- mega.nz
- onrender.com
- pages.dev
- paste.ee
- pastebin.com
- pastebin.pl
- pastetext.net
- privatlab.com
- privatlab.net
- send.exploit.in
- sendspace.com
- storage.googleapis.com
- storjshare.io
- supabase.co
- temp.sh
- transfer.sh
- trycloudflare.com
- ufile.io
- w3spaces.com
- workers.dev
- x0.at
condition: all of selection_*
falsepositives:
- Some legitimate apps use this, but limited.
level: high
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_bitsadmin_download_file_sharing_domains/info.yml
simulation:
- type: atomic-red-team
name: Windows - BITSAdmin BITS Download
technique: T1105
atomic_guid: a1921cd3-9a2d-47d5-a891-f1d0f2a7a31b
license: DRL-1.1
What it detects
This rule flags Windows process executions of bitsadmin.exe where the command line includes BITS transfer-related flags (/transfer, /create, /addfile) and references common file-sharing or paste-style domains. Attackers often use BITSAdmin to stage payloads by downloading files from external hosting services while blending in with legitimate Windows tooling. The detection relies on process creation telemetry, specifically the executable path or original file name and the full command line contents indicating both BITS operations and the remote domain.
Known false positives
- Some legitimate apps use this, but limited.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.