LoFP LoFP / many legitimate applications or scripts could leverage \"bitsadmin\". this event is best correlated with eid 16403 via the jobid field

Techniques

Sample rules

New BITS Job Created Via Bitsadmin

Description

Detects the creation of a new bits job by Bitsadmin

Detection logic

condition: selection
selection:
  EventID: 3
  processPath|endswith: \bitsadmin.exe