BITS Job Abuse - bitsadmin or PowerShell Remote File Download (T1197)

Detects the use of BITSAdmin or PowerShell 'Start-BitsTransfer' to initiate file transfers, specifically targeting non-Microsoft signed processes. Adversaries often abuse the Background Intelligent Transfer Service (BITS) to download malicious payloads or exfiltrate data, as it is a legitimate Windows service that operates in the background.