BIOC High

Bitsadmin.exe used to upload data

Some attacks are known to abuse BITSAdmin to hide how data upload using legitimate Windows tools.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Exfiltration
Status:
Enabled
ATT&CK tactics: Exfiltration (TA0010) Defense Evasion (TA0005)
ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048) BITS Jobs (T1197)
Indicator:

Process action type = execution AND target process cmd = */transfer * AND */upload * AND target process name = bitsadmin.exe

Preventable: yes