BITSAdmin File Transfer or Persistence via T1197
Detects the use of BITSAdmin to create or modify background intelligent transfer jobs. Attackers often abuse BITSAdmin to download malicious payloads (ingress tool transfer) or to execute commands when a transfer job completes or errors, which can be leveraged for persistence or arbitrary code execution.
SentinelOne

