BITSAdmin or PowerShell BITS Transfer Abuse for Malware Download (T1197)
Detects the abuse of Windows Background Intelligent Transfer Service (BITS) via 'bitsadmin.exe' or PowerShell's 'Start-BitsTransfer' cmdlet to download files from remote URLs. This rule identifies potentially malicious activity by monitoring for specific transfer-related command-line arguments coupled with external network connections, excluding Microsoft-signed processes. It further refines detection by flagging output to suspicious directories (like Temp, AppData, or Public) or files with common executable extensions.
SentinelOne

