BITS/BITSAdmin Abuse for Persistence and Payload Download

Detects the use of BITSAdmin or the PowerShell Start-BitsTransfer cmdlet for downloading files from the internet or local network, often used by attackers to perform ingress tool transfer or to maintain persistence via BITS jobs.