LoFP LoFP / rare programs that use bitsadmin and update from regional tlds e.g. .uk or .ca

Techniques

Sample rules

Bitsadmin to Uncommon TLD

Description

Detects Bitsadmin connections to domains with uncommon TLDs

Detection logic

condition: selection and not falsepositives
falsepositives:
  cs-host|endswith:
  - .com
  - .net
  - .org
  - .scdn.co
  - .sfx.ms
selection:
  c-useragent|startswith: Microsoft BITS/