LoFP LoFP / t1197

t1197

TitleTags
administrator powershell scripts
many legitimate applications or scripts could leverage \"bitsadmin\". this event is best correlated with eid 16403 via the jobid field
rare programs that use bitsadmin and update from regional tlds e.g. .uk or .ca
some legitimate apps use this, but limited.
this rule doesn't exclude other known tlds such as \".org\" or \".net\". it's recommended to apply additional filters for software and scripts that leverage the bits service
unknown
while the file extensions in question can be suspicious at times. it's best to add filters according to your environment to avoid large amount false positives