Windows BITSAdmin Download from File-Sharing Domains Using Suspicious Transfer/Create/Addfile Parameters

Alerts on BITSAdmin downloads from popular file-sharing domains when transfer/create/addfile command-line flags are present.

FreeUnreviewedSigmahighv1
title: Windows BITSAdmin Download from File-Sharing Domains Using Suspicious Transfer/Create/Addfile Parameters
id: f17c4a3f-c984-49ce-97c9-ef3d26841b9c
related:
  - id: 8b48ad89-10d8-4382-a546-50588c410f0d
    type: similar
  - id: d635249d-86b5-4dad-a8c7-d7272b788586
    type: similar
  - id: 52182dfb-afb7-41db-b4bc-5336cb29b464
    type: similar
  - id: ae02ed70-11aa-4a22-b397-c0d0e8f6ea99
    type: similar
  - id: e0f8ab85-0ac9-423b-a73a-81b3c7b1aa97
    type: similar
  - id: 7b434893-c57d-4f41-908d-6a17bf1ae98f
    type: similar
  - id: 42a5f1e7-9603-4f6d-97ae-3f37d130d794
    type: similar
  - id: 56454143-524f-49fb-b1c6-3fb8b1ad41fb
    type: similar
  - id: b6e04788-29e1-4557-bb14-77f761848ab8
    type: similar
  - id: a0d7e4d2-bede-4141-8896-bc6e237e977c
    type: similar
  - id: 297ae038-edc2-4b2e-bb3e-7c5fc94dd5c7
    type: similar
  - id: 8518ed3d-f7c9-4601-a26c-f361a4256a0c
    type: derived
status: test
description: This rule flags Windows process executions of bitsadmin.exe where the command line includes BITS transfer-related flags (/transfer, /create, /addfile) and references common file-sharing or paste-style domains. Attackers often use BITSAdmin to stage payloads by downloading files from external hosting services while blending in with legitimate Windows tooling. The detection relies on process creation telemetry, specifically the executable path or original file name and the full command line contents indicating both BITS operations and the remote domain.
references:
  - https://blog.netspi.com/15-ways-to-download-a-file/#bitsadmin
  - https://isc.sans.edu/diary/22264
  - https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/
  - https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ransomware-hive-conti-avoslocker
  - https://www.cisa.gov/uscert/ncas/alerts/aa22-321a
  - https://www.microsoft.com/en-us/security/blog/2024/01/17/new-ttps-observed-in-mint-sandstorm-campaign-targeting-high-profile-individuals-at-universities-and-research-orgs/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_bitsadmin_download_file_sharing_domains.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2022-06-28
modified: 2026-03-29
tags:
  - attack.persistence
  - attack.execution
  - attack.stealth
  - attack.t1197
  - attack.s0190
  - attack.t1036.003
  - attack.command-and-control
  - attack.t1105
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - Image|endswith: \bitsadmin.exe
    - OriginalFileName: bitsadmin.exe
  selection_flags:
    CommandLine|contains:
      - " /transfer "
      - " /create "
      - " /addfile "
  selection_domain:
    CommandLine|contains:
      - .githubusercontent.com
      - 0x0.st
      - anonfiles.com
      - bashupload.com
      - cdn.discordapp.com
      - chunk.io
      - ddns.net
      - dl.dropboxusercontent.com
      - ghostbin.co
      - github.com
      - glitch.me
      - gofile.io
      - hastebin.com
      - mediafire.com
      - mega.nz
      - onrender.com
      - pages.dev
      - paste.ee
      - pastebin.com
      - pastebin.pl
      - pastetext.net
      - privatlab.com
      - privatlab.net
      - send.exploit.in
      - sendspace.com
      - storage.googleapis.com
      - storjshare.io
      - supabase.co
      - temp.sh
      - transfer.sh
      - trycloudflare.com
      - ufile.io
      - w3spaces.com
      - workers.dev
      - x0.at
  condition: all of selection_*
falsepositives:
  - Some legitimate apps use this, but limited.
level: high
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_bitsadmin_download_file_sharing_domains/info.yml
simulation:
  - type: atomic-red-team
    name: Windows - BITSAdmin BITS Download
    technique: T1105
    atomic_guid: a1921cd3-9a2d-47d5-a891-f1d0f2a7a31b
license: DRL-1.1

What it detects

This rule flags Windows process executions of bitsadmin.exe where the command line includes BITS transfer-related flags (/transfer, /create, /addfile) and references common file-sharing or paste-style domains. Attackers often use BITSAdmin to stage payloads by downloading files from external hosting services while blending in with legitimate Windows tooling. The detection relies on process creation telemetry, specifically the executable path or original file name and the full command line contents indicating both BITS operations and the remote domain.

Known false positives

  • Some legitimate apps use this, but limited.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.