Skip to content
Threat Feed

Tag

Bits

6 briefs RSS
medium advisory

Abuse of BITS Jobs via Suspicious or Uncommon Remote Endpoints

Adversaries utilize the Background Intelligent Transfer Service (BITS) to execute or stage malicious payloads from uncommon or suspicious remote domains to evade detection.

persistence execution bits windows
1r 1t
medium advisory

Suspicious File Extensions in BITS Transfer Jobs

Detection of BITS transfer jobs saving files with potentially malicious extensions, a technique used by adversaries to download and execute payloads while evading traditional security monitoring.

persistence execution bits windows
1r 1t
medium advisory

Persistence via BITS Job Notify Cmdline

Adversaries can achieve persistence by abusing the Background Intelligent Transfer Service (BITS) SetNotifyCmdLine method to execute a program after a job finishes, leading to arbitrary code execution and system compromise.

Defender XDR +2 persistence bits windows
2r 1t
medium advisory

Ingress Transfer via Windows BITS

Adversaries leverage the Windows Background Intelligent Transfer Service (BITS) to download executable and archive files, potentially delivering malicious payloads while evading traditional security measures.

Windows bits file-transfer command-and-control defense-evasion
2r 2t
low advisory

Ingress Transfer via Windows BITS

Adversaries may leverage Windows Background Intelligent Transfer Service (BITS) to download executable and archive files to evade defenses and establish command and control.

Background Intelligent Transfer Service +2 bits ingress-transfer command-and-control defense-evasion windows
2r 2t
medium advisory

BITS Job Notify Command Persistence

Adversaries can abuse the Background Intelligent Transfer Service (BITS) SetNotifyCmdLine method to execute arbitrary commands for persistence by configuring a BITS job to execute a program after a transfer completes or enters a specific state.

Windows persistence bits
2r 1t