Bitsadmin or BitsTransfer C2/Payload Download via Remote URL

Detects the use of BITSAdmin or PowerShell 'Start-BitsTransfer' to initiate background data transfer jobs pointing to non-Microsoft or non-Windows Update domains. This technique is commonly used by adversaries for C2 communication or to download malicious payloads.