BITS Job Abuse via bitsadmin.exe or PowerShell BitsTransfer

This rule detects the use of BITSAdmin or PowerShell 'Start-BitsTransfer' to initiate file transfer jobs. These tools can be abused by adversaries to download malicious payloads or exfiltrate data, often bypassing standard firewall restrictions. The rule specifically filters out legitimate Microsoft-signed processes to reduce noise.