BITS/BITSAdmin Abuse for Persistence and Payload Download
Detects the use of BITSAdmin or the PowerShell Start-BitsTransfer cmdlet for downloading files from the internet or local network, often used by attackers to perform ingress tool transfer or to maintain persistence via BITS jobs.
Microsoft Sentinel (KQL)

