Windows Process Creation: BITSAdmin Downloading to Suspicious Target Folders
Flags bitsadmin.exe file downloads that target suspicious folders using /transfer, /create, and /addfile command-line parameters.
FreeUnreviewedSigmahighv1
windows-process-creation-bitsadmin-downloading-to-suspicious-target-folders-2ddef153
title: "Windows Process Creation: BITSAdmin Downloading to Suspicious Target Folders"
id: 81ef1620-042c-40b8-9014-05bc07e166e6
related:
- id: 6e30c82f-a9f8-4aab-b79c-7c12bce6f248
type: obsolete
- id: 1cf465a1-2609-4c15-9b66-c32dbe4bfd67
type: similar
- id: 2ddef153-167b-4e89-86b6-757a9e65dcac
type: derived
status: test
description: This rule identifies Windows executions of bitsadmin.exe that include BITS transfer parameters (/transfer, /create, /addfile) and write to commonly abused target locations. Attackers use BITSAdmin to stage files in user-accessible, system, or persistence-related directories while blending into legitimate Windows download activity. The detection relies on process creation telemetry, using the executable name and command-line content to match both the BITSAdmin invocation and the suspicious destination paths.
references:
- https://blog.netspi.com/15-ways-to-download-a-file/#bitsadmin
- https://isc.sans.edu/diary/22264
- https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/
- https://blog.talosintelligence.com/breaking-the-silence-recent-truebot-activity/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_bitsadmin_download_susp_targetfolder.yml
author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-06-28
modified: 2025-12-10
tags:
- attack.persistence
- attack.execution
- attack.stealth
- attack.t1197
- attack.s0190
- attack.t1036.003
- attack.command-and-control
- attack.t1105
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: \bitsadmin.exe
- OriginalFileName: bitsadmin.exe
selection_flags:
CommandLine|contains:
- " /transfer "
- " /create "
- " /addfile "
selection_folder:
CommandLine|contains:
- :\Perflogs
- :\ProgramData\
- :\Temp\
- :\Users\Public\
- :\Windows\
- \$Recycle.Bin\
- \AppData\Local\
- \AppData\Roaming\
- \Contacts\
- \Desktop\
- \Favorites\
- \Favourites\
- \inetpub\wwwroot\
- \Music\
- \Pictures\
- \Start Menu\Programs\Startup\
- \Users\Default\
- \Videos\
- "%ProgramData%"
- "%public%"
- "%temp%"
- "%tmp%"
condition: all of selection_*
falsepositives:
- Unknown
level: high
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_bitsadmin_download_susp_targetfolder/info.yml
simulation:
- type: atomic-red-team
name: Windows - BITSAdmin BITS Download
technique: T1105
atomic_guid: a1921cd3-9a2d-47d5-a891-f1d0f2a7a31b
license: DRL-1.1
What it detects
This rule identifies Windows executions of bitsadmin.exe that include BITS transfer parameters (/transfer, /create, /addfile) and write to commonly abused target locations. Attackers use BITSAdmin to stage files in user-accessible, system, or persistence-related directories while blending into legitimate Windows download activity. The detection relies on process creation telemetry, using the executable name and command-line content to match both the BITSAdmin invocation and the suspicious destination paths.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.