Track Common Adversary Tasks Performed Using BITSAdmin
Overview
BITSAdmin (Background Intelligent Transfer Service Admin) is a command-line tool that can create as well as manage BITS jobs. It is generally used to download files from or upload files to HTTP web servers and SMB file shares. It can also manage network interruptions, pausing and automatically resuming transfers, even after a reboot.
How Does It Works?
BITSAdmin consists of two switches, viz., '/transfer', and '/addfile' whom working profile is similar to each other while their style of working is quite different. As BITSAdmin downloads files in the form of jobs, these jobs must be defined before moving on; which can be done via various switches.
Detection
Regular monitoring of the logs for the usage of the BITSAdmin tools and gaining information regarding the transfers through QMGR Database are some of the ways to detect them. However, it was very difficult to detect BITS transfers in the past before BITSAdmin was introduced in the Windows Defender Real-Time Scan as scanning through logs was the only other method to do that.
Mitigation
The following measures can help in mitigating cyberthreat:
- Modify network and/or host firewall rules.
- Allow only the legitimate BITS traffic by properly controlling the network.
- Limit the external access of the BITSAdmin interface to specific users or groups.
To know more about it, you can go through my detailed document by clicking here
Comments
Post a Comment