BIOCs

Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.

Severity
Category
  • Bitsadmin.exe used to upload data High Exfiltration

    Some attacks are known to abuse BITSAdmin to hide how data upload using legitimate Windows tools.

    Indicator:

    Process action type = execution AND target process cmd = */transfer * AND */upload * AND target process name = bitsadmin.exe

    ATT&CK tactics: Exfiltration (TA0010) Defense Evasion (TA0005)
    ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048) BITS Jobs (T1197)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11