Windows Process Creation: BITSAdmin Downloading File with Suspicious Extension

Flags bitsadmin.exe commands that transfer or add files with suspicious extensions based on process creation command-line content.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-06-28
Updated
2026-07-31

ATT&CK techniques

Execution → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. Exfiltration

  11. Impact

What it detects

This rule flags Windows process executions of bitsadmin.exe where the command line includes transfer-related switches (/transfer, /create, /addfile) and the command line contains one of several potentially suspicious file extensions. Attackers may use BITSAdmin to stealthily download payloads or staging files, so correlating BITSAdmin activity with extension indicators can highlight likely malicious file retrieval. It relies on process creation telemetry capturing the Image/OriginalFileName of bitsadmin.exe and the full CommandLine.

Related detections9 linkedT1105 — drag to rearrange
Windows Process Creation: bitsadmin Downloads Files to Suspicious Directories
Windows BITSAdmin Downloads from File-Sharing Domains
Windows BITSAdmin File Download via bitsadmin.exe with Transfer/Addfile Arguments
Suspicious Remote Script Transfer via Bitsadmin (via process_creation)
Suspicious File Download Via Bitsadmin Transfer
BITS Payload Downloaded via Commandline (via process_creation)
BITS Payload Downloaded via PowerShell (via powershell)
Suspicious sLoad Payload Download via BITSAdmin LOLBin Transfer (via process_creation)
Suspicious File Download via Certutil URLCache
Windows Process Creation: BITSAdmin Downloading File with Suspicious Extension
Pivot detection · T1105 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.