Windows Process Creation: bitsadmin Download Using Direct IP URL
Alerts when bitsadmin.exe is used to download via a direct IP address in the command line on Windows.
- Product
- windows
- Category
- process_creation
- Author
- Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2022-06-28
- Updated
- 2026-07-31
ATT&CK techniques
Execution → Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies suspicious use of bitsadmin.exe to download files when the command line includes transfer and job creation flags along with a URL containing a direct IP address. Attackers commonly use bitsadmin to retrieve remote payloads while blending into normal Windows activity. It relies on Windows process creation telemetry with access to the Image/OriginalFileName and the full command line.
Reporting behind it
- blog.netspi.comhttps://blog.netspi.com/15-ways-to-download-a-file/#bitsadmin
- isc.sans.eduhttps://isc.sans.edu/diary/22264
- lolbas-project.github.iohttps://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/
- blog.talosintelligence.comhttps://blog.talosintelligence.com/breaking-the-silence-recent-truebot-activity/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_bitsadmin_download_direct_ip.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows Process Creation: bitsadmin Download Using Direct IP URL"
id: 6a6d5848-923f-49d6-9ce8-1a0934369361
related:
- id: 90f138c1-f578-4ac3-8c49-eecfd847c8b7
type: similar
- id: 99c840f2-2012-46fd-9141-c761987550ef
type: derived
status: test
description: This rule identifies suspicious use of bitsadmin.exe to download files when the command line includes transfer and job creation flags along with a URL containing a direct IP address. Attackers commonly use bitsadmin to retrieve remote payloads while blending into normal Windows activity. It relies on Windows process creation telemetry with access to the Image/OriginalFileName and the full command line.
references:
- https://blog.netspi.com/15-ways-to-download-a-file/#bitsadmin
- https://isc.sans.edu/diary/22264
- https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/
- https://blog.talosintelligence.com/breaking-the-silence-recent-truebot-activity/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_bitsadmin_download_direct_ip.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2022-06-28
modified: 2023-02-15
tags:
- attack.persistence
- attack.execution
- attack.stealth
- attack.t1197
- attack.s0190
- attack.t1036.003
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: \bitsadmin.exe
- OriginalFileName: bitsadmin.exe
selection_flags:
CommandLine|contains:
- " /transfer "
- " /create "
- " /addfile "
selection_extension:
CommandLine|contains:
- ://1
- ://2
- ://3
- ://4
- ://5
- ://6
- ://7
- ://8
- ://9
filter_seven_zip:
CommandLine|contains: ://7-
condition: all of selection_* and not 1 of filter_*
falsepositives:
- Unknown
level: high
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_bitsadmin_download_direct_ip/info.yml
license: DRL-1.1