Bitsadmin Activity to Uncommon Top-Level Domains
Detection of Windows Background Intelligent Transfer Service (BITS) administrative utility usage targeting suspicious or non-standard top-level domains.
The Bitsadmin utility is a command-line tool used to create, download, or upload jobs using the Windows Background Intelligent Transfer Service (BITS). While BITS is a legitimate component for software updates and background file transfers, it is frequently abused by adversaries for C2 communication, data exfiltration, and malware delivery. This detection focuses on identifying BITS activity directed toward uncommon or suspicious top-level domains (TLDs) that fall outside of standard enterprise or trusted update traffic. Because BITS typically communicates with established infrastructure like Microsoft update endpoints or trusted CDN domains, connections to unusual TLDs may indicate malicious activity, such as staged malware downloads or beaconing to actor-controlled infrastructure. Defenders should monitor proxy logs for the specific 'Microsoft BITS/' User-Agent string to identify and investigate potential BITS abuse.
Impact
Successful exploitation of BITS for C2 or file transfer allows attackers to blend in with legitimate system traffic, potentially bypassing traditional network perimeter controls and achieving long-term persistence within an environment.
Recommendation
Deploy the provided Sigma rule to your proxy logs to identify BITS traffic directed to non-standard domains. Use the identified logs to investigate the destination domains and the associated file transfer activity.
- Deploy the Sigma rule below to proxy log aggregators to alert on suspicious BITS traffic.
- Baseline common BITS traffic patterns to filter out legitimate, authorized regional TLDs that may trigger false positives in your specific environment.
Immediate actions
Deploy Sigma rule to monitor for BITS activity to uncommon TLDs
Mitigations
Review and restrict BITS communication to known-good domains via proxy/firewall
Detection coverage 1
Detect Bitsadmin Activity to Uncommon TLDs
highDetects Bitsadmin network connections using the Microsoft BITS User-Agent to domains with non-standard or uncommon TLDs.
Detection queries are available on the platform. Get full rules →