BitsAdmin LOLBin Abuse - Transfer, Download, or Child Process Exec
This rule detects suspicious activity involving the BITSAdmin (bitsadmin.exe) utility, which is a known LOLBin (Living Off the Land Binary). It monitors for the creation of BITS jobs using suspicious flags (e.g., /transfer, /setnotifycmdline) potentially indicating external file downloads, as well as the execution of known command interpreters or utilities spawned as child processes by BITSAdmin, which is a common post-exploitation technique for persistence or secondary payload execution.
SentinelOne

