Track Common Adversary Tasks Performed Using BITSAdmin

 





To know more about it, you can go through my detailed document by clicking here





Overview

BITSAdmin (Background Intelligent Transfer Service Admin) is a command-line tool that can create as well as manage BITS jobs. It is generally used to download files from or upload files to HTTP web servers and SMB file shares. It can also manage network interruptions, pausing and automatically resuming transfers, even after a reboot.

How Does It Works?

BITSAdmin consists of two switches, viz., '/transfer', and '/addfile' whom working profile is similar to each other while their style of working is quite different. As BITSAdmin downloads files in the form of jobs, these jobs must be defined before moving on; which can be done via various switches.

Detection

Regular monitoring of the logs for the usage of the BITSAdmin tools and gaining information regarding the transfers through QMGR Database are some of the ways to detect them. However, it was very difficult to detect BITS transfers in the past before BITSAdmin was introduced in the Windows Defender Real-Time Scan as scanning through logs was the only other method to do that.

Mitigation

The following measures can help in mitigating cyberthreat:
  • Modify network and/or host firewall rules.
  • Allow only the legitimate BITS traffic by properly controlling the network.
  • Limit the external access of the BITSAdmin interface to specific users or groups.

 







To know more about it, you can go through my detailed document by clicking here


























































Comments

Popular posts from this blog

Query, Visualize, & Monitor Data in Azure Sentinel

Planning for Implementing SAP Solutions on Azure (Part 2 of 5)

Work with String Data Using KQL Statements