Microsoft-Windows-Bits-Client
114 events across 3 channels
Event ID 0 —
Event ID 1 — BITS job ".
Message
Fields
| Name | Description |
|---|---|
JobGuid | — |
Title | — |
Event ID 2 — BITS job ".
Message
Fields
| Name | Description |
|---|---|
JobGuid | — |
Title | — |
Event ID 3 — The BITS service created a new job.
Message
Fields
| Name | Description |
|---|---|
jobTitle | Transfer job. |
jobId | — |
jobOwner | Owner. |
processPath | — |
processId | — |
ClientProcessStartKey | — |
Example Event
system:
provider: Microsoft-Windows-Bits-Client
guid: EF1CC15B-46C1-414E-BB95-E76B077BD51E
event_source_name: ''
event_id: 3
version: 3
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-06T01:45:20.897391+00:00'
event_record_id: 432
correlation:
ActivityID: E4DB489E-1037-0002-3588-E4E43710DA01
execution:
process_id: 16164
thread_id: 17248
channel: Microsoft-Windows-Bits-Client/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
jobTitle: Chrome Component Updater
jobId: 9A25D168-24E6-4C66-AC78-5ED0E6007F1A
jobOwner: WINDEV2310EVAL\User
processPath: C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.222.982.0_x64__zpdnekdrzrea0\Spotify.exe
processId: 2208
ClientProcessStartKey: 3659174697241209
message: ''
Sigma Rules
- New BITS Job Created Via Bitsadmin
Detects the creation of a new bits job by Bitsadmin - New BITS Job Created Via PowerShell
Detects the creation of a new bits job by PowerShell
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4 — The transfer job is complete.
Message
Fields
| Name | Description |
|---|---|
User | — |
jobTitle | Transfer job. |
jobId | — |
jobOwner | Owner. |
fileCount | — |
bytesTransferred | — |
bytesTransferredFromPeer | — |
Example Event
system:
provider: Microsoft-Windows-Bits-Client
guid: EF1CC15B-46C1-414E-BB95-E76B077BD51E
event_source_name: ''
event_id: 4
version: 1
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-06T02:02:24.353689+00:00'
event_record_id: 436
correlation:
ActivityID: E4DB489E-1037-0002-3588-E4E43710DA01
execution:
process_id: 16164
thread_id: 5192
channel: Microsoft-Windows-Bits-Client/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
User: WINDEV2310EVAL\User
jobTitle: Edge Component Updater
jobId: 3C77FC9E-C30A-4FC3-804B-82E48B3059B6
jobOwner: WINDEV2310EVAL\User
fileCount: 1
bytesTransferred: 201001
bytesTransferredFromPeer: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5 — Job cancelled.
Message
Fields
| Name | Description |
|---|---|
User | Job cancelled. User. |
jobTitle | — |
jobId | — |
jobOwner | — |
fileCount | — |
processId | — |
ClientProcessStartKey | — |
Example Event
system:
provider: Microsoft-Windows-Bits-Client
guid: EF1CC15B-46C1-414E-BB95-E76B077BD51E
event_source_name: ''
event_id: 5
version: 1
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-10-25T21:23:18.455184+00:00'
event_record_id: 20
correlation:
ActivityID: DE03B784-07C3-0003-32C2-03DEC307DA01
execution:
process_id: 4816
thread_id: 4860
channel: Microsoft-Windows-Bits-Client/Operational
computer: WinDevEval
security:
user_id: S-1-5-19
event_data:
User: NT AUTHORITY\LOCAL SERVICE
jobTitle: Font Download
jobId: BF87B9AA-D285-46CB-89FF-C6C111F0E4CB
jobOwner: NT AUTHORITY\LOCAL SERVICE
fileCount: 1
processId: 2948
ClientProcessStartKey: 562949953421373
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 6 — Command-line command set for job %1 with owner %2.
Message
Fields
| Name | Description |
|---|---|
jobId | — |
jobOwner | — |
program | 2. Program. |
parameters | Args. |
Example Event
system:
provider: Microsoft-Windows-Bits-Client
guid: EF1CC15B-46C1-414E-BB95-E76B077BD51E
event_source_name: ''
event_id: 6
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-10-25T21:25:55.426533+00:00'
event_record_id: 32
correlation:
ActivityID: DE03B784-07C3-0003-E610-04DEC307DA01
execution:
process_id: 4940
thread_id: 5896
channel: Microsoft-Windows-Bits-Client/Operational
computer: WinDevEval
security:
user_id: S-1-5-18
event_data:
jobId: F36CA3CE-3AEB-4592-B4ED-D23E59938DF9
jobOwner: NT AUTHORITY\SYSTEM
program: C:\Windows\system32\directxdatabaseupdater.exe
parameters: C:\Windows\system32\directxdatabaseupdater.exe -DatabaseComplete {F36CA3CE-3AEB-4592-B4ED-D23E59938DF9}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 10 — BITS started listening for peer-client requests.
Message
Event ID 11 — BITS was not able to listen for peer-client requests.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 12 — BITS stopped listening for peer-client requests.
Message
Event ID 13 — BITS started listening for peer-server announcements.
Message
Event ID 14 — BITS was not able to listen for peer-server announcements.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 15 — BITS stopped listening for peer-server announcements.
Message
Event ID 16 — BITS has sent an inquiry for peer servers.
Message
Event ID 17 — BITS has read the policy parameters for peer-caching.
Message
Fields
| Name | Description |
|---|---|
peerCacheEnabled | — |
peerClientEnabled | — |
peerServerEnabled | — |
maxPeers | — |
maxClients | — |
maxContentAge | — |
maxCacheSize | — |
minCacheDiskSize | — |
cacheDenyUrls | — |
denyUrlCount | — |
denyUrls | — |
Event ID 18 — The peer list rejected an incoming server announcement.
Message
Fields
| Name | Description |
|---|---|
packet | — |
hr | — |
fqdn | — |
sourceAddress | — |
addressCount | — |
addresses | — |
Event ID 19 — A new peer was added.
Message
Fields
| Name | Description |
|---|---|
fqdn | — |
authenticated | — |
online | — |
addressCount | — |
addressLength | — |
Event ID 20 — A peer was updated.
Message
Fields
| Name | Description |
|---|---|
fqdn | — |
authenticated | — |
online | — |
addressCount | — |
addressLength | — |
Event ID 21 — A peer was removed from the peer list.
Message
Fields
| Name | Description |
|---|---|
fqdn | — |
authenticated | — |
online | — |
addressCount | — |
addressLength | — |
Event ID 22 — A cached peer was restored from disk.
Message
Fields
| Name | Description |
|---|---|
fqdn | — |
authenticated | — |
online | — |
addressCount | — |
addressLength | — |
Event ID 23 — An application cleared the peer list.
Message
Fields
| Name | Description |
|---|---|
user | — |
Event ID 24 — BITS has replied to a client's inquiry for peer servers.
Message
Fields
| Name | Description |
|---|---|
sourceAddress | — |
Event ID 25 — The server received a peer inquiry but rejected it.
Message
Fields
| Name | Description |
|---|---|
sourceAddress | — |
packet | — |
hr | — |
Event ID 27 — A peer search for an URL has begun.
Message
Fields
| Name | Description |
|---|---|
searchId | — |
jobId | — |
url | — |
timestamp | — |
Event ID 28 — A peer search ended.
Message
Fields
| Name | Description |
|---|---|
searchId | — |
jobId | — |
Event ID 29 — A search request is being sent.
Message
Fields
| Name | Description |
|---|---|
requestId | — |
searchId | — |
peer | — |
Event ID 30 — A search request has completed.
Message
Fields
| Name | Description |
|---|---|
requestId | — |
SearchId | — |
hr | — |
Event ID 31 — A search request has completed unsuccessfully.
Message
Fields
| Name | Description |
|---|---|
requestId | — |
SearchId | — |
hr | — |
Event ID 32 — The peer's record %2 matched the request.
Message
Fields
| Name | Description |
|---|---|
requestId | — |
id | — |
url | — |
rangecount | — |
Range | — |
Event ID 33 — BITS updated the set of IP addresses used for peer-caching.
Message
Fields
| Name | Description |
|---|---|
count | — |
addresses | — |
Event ID 34 — Job cannot be transferred because job transfer cost policy preventing it.
Message
Fields
| Name | Description |
|---|---|
jobName | — |
jobId | — |
FileCount | — |
jobTransferPolicy | — |
globalTransferPolicy | — |
Event ID 37 — The cost state has changed.
Message
Fields
| Name | Description |
|---|---|
nlmCost | — |
usage | — |
cap | — |
isThrottled | — |
isOvercap | — |
isRoaming | — |
globalTransferPolicy | — |
Event ID 59 — BITS started the %2 transfer job that is associated with the %4 URL.
Message
Fields
| Name | Description |
|---|---|
transferId | — |
name | — |
Id | — |
url | — |
peer | — |
fileTime | — |
fileLength | — |
bytesTotal | — |
bytesTransferred | — |
bytesTransferredFromPeer | — |
Example Event
system:
provider: Microsoft-Windows-Bits-Client
guid: EF1CC15B-46C1-414E-BB95-E76B077BD51E
event_source_name: ''
event_id: 59
version: 1
level: 4
task: 0
opcode: 1
keywords: 4611686018427387904
time_created: '2023-11-06T01:45:21.457190+00:00'
event_record_id: 434
correlation:
ActivityID: 837C306A-427B-4022-ABDF-56DD359EB862
execution:
process_id: 16164
thread_id: 12700
channel: Microsoft-Windows-Bits-Client/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
transferId: 837C306A-427B-4022-ABDF-56DD359EB862
name: Chrome Component Updater
Id: 9A25D168-24E6-4C66-AC78-5ED0E6007F1A
url: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acwcdm4bj7lx4xbm2ireywxlhvca_4.10.2710.0/oimompecagnajdejgnnjijobebaeigek_4.10.2710.0_win64_adsurwm4gclupf32xdrpgdnapira.crx3
peer: ''
fileTime: '2023-09-22T20:52:50.000000Z'
fileLength: 14317402
bytesTotal: 14317402
bytesTransferred: 0
bytesTransferredFromPeer: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 60 — BITS stopped transferring the %2 transfer job that is associated with the %4 URL.
Message
Fields
| Name | Description |
|---|---|
transferId | — |
name | — |
Id | — |
url | — |
peer | — |
hr | — |
fileTime | — |
fileLength | — |
bytesTotal | — |
bytesTransferred | — |
proxy | — |
peerProtocolFlags | — |
bytesTransferredFromPeer | — |
AdditionalInfoHr | — |
PeerContextInfo | — |
bandwidthLimit | — |
ignoreBandwidthLimitsOnLan | — |
Example Event
system:
provider: Microsoft-Windows-Bits-Client
guid: EF1CC15B-46C1-414E-BB95-E76B077BD51E
event_source_name: ''
event_id: 60
version: 1
level: 4
task: 0
opcode: 2
keywords: 4611686018427387904
time_created: '2023-11-06T01:45:52.846707+00:00'
event_record_id: 435
correlation:
ActivityID: 837C306A-427B-4022-ABDF-56DD359EB862
execution:
process_id: 16164
thread_id: 12832
channel: Microsoft-Windows-Bits-Client/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
transferId: 837C306A-427B-4022-ABDF-56DD359EB862
name: Chrome Component Updater
Id: 9A25D168-24E6-4C66-AC78-5ED0E6007F1A
url: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acwcdm4bj7lx4xbm2ireywxlhvca_4.10.2710.0/oimompecagnajdejgnnjijobebaeigek_4.10.2710.0_win64_adsurwm4gclupf32xdrpgdnapira.crx3
peer: ''
hr: 0
fileTime: '2023-09-22T20:52:50.000000Z'
fileLength: 14317402
bytesTotal: 14317402
bytesTransferred: 14317402
proxy: ''
peerProtocolFlags: 0
bytesTransferredFromPeer: 0
AdditionalInfoHr: 0
PeerContextInfo: 0
bandwidthLimit: 18446744073709551615
ignoreBandwidthLimitsOnLan: false
message: ''
Community Notes
Surfaces Background Intelligent Transfer Service misuse for exfil or downloads.References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 61 — BITS stopped transferring the %2 transfer job that is associated with the %4 URL.
Message
Fields
| Name | Description |
|---|---|
transferId | — |
name | — |
Id | — |
url | — |
peer | — |
hr | — |
fileTime | — |
fileLength | — |
bytesTotal | — |
bytesTransferred | — |
proxy | — |
peerProtocolFlags | — |
bytesTransferredFromPeer | — |
AdditionalInfoHr | — |
PeerContextInfo | — |
bandwidthLimit | — |
ignoreBandwidthLimitsOnLan | — |
Example Event
system:
provider: Microsoft-Windows-Bits-Client
guid: EF1CC15B-46C1-414E-BB95-E76B077BD51E
event_source_name: ''
event_id: 61
version: 1
level: 3
task: 0
opcode: 2
keywords: 4611686018427387904
time_created: '2023-10-25T21:23:18.535833+00:00'
event_record_id: 25
correlation:
ActivityID: B93FF5C2-FB5D-428C-88AE-EE3A7EE94E1C
execution:
process_id: 4816
thread_id: 2800
channel: Microsoft-Windows-Bits-Client/Operational
computer: WinDevEval
security:
user_id: S-1-5-18
event_data:
transferId: B93FF5C2-FB5D-428C-88AE-EE3A7EE94E1C
name: Font Download
Id: 0732C691-11CC-4489-AA3A-006D80128165
url: https://fs.microsoft.com/fs/windows/fontset-2017-04.json
peer: ''
hr: 2149580817
fileTime: '1601-01-01T00:00:00.000000Z'
fileLength: 18446744073709551615
bytesTotal: 18446744073709551615
bytesTransferred: 0
proxy: ''
peerProtocolFlags: 0
bytesTransferredFromPeer: 0
AdditionalInfoHr: 0
PeerContextInfo: 0
bandwidthLimit: 18446744073709551615
ignoreBandwidthLimitsOnLan: false
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 62 — The BITS job named ".
Message
Fields
| Name | Description |
|---|---|
Title | — |
Owner | — |
Url | — |
Id | — |
Event ID 63 — The BITS job %1 is configured to launch %3 after transfer of %2.
Message
Fields
| Name | Description |
|---|---|
Job | — |
Url | — |
Pgm | — |
hr | — |
Event ID 64 — The BITS job %1 is configured to launch %3 after transfer of %2.
Message
Fields
| Name | Description |
|---|---|
Job | — |
Url | — |
Pgm | — |
hr | — |
Event ID 70 — BITS received a peer-cache request from a client at address %1.
Message
Fields
| Name | Description |
|---|---|
clientAddress | — |
Event ID 71 — The client's search request is for ".
Message
Fields
| Name | Description |
|---|---|
url | — |
timestamp | — |
Event ID 72 — The cache found a matching cache record with ID %1.
Message
Fields
| Name | Description |
|---|---|
id | — |
url | — |
rangecount | — |
Range | — |
Event ID 73 — While processing the client's request, BITS encountered error %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 74 — BITS rejected the client's request with HTTP status %1.
Message
Fields
| Name | Description |
|---|---|
status | — |
Event ID 75 — BITS has finished processing the client request.
Message
Event ID 76 — The request includes the client's event-log activity ID.
Message
Event ID 77 — BITS search for peer-servers has started.
Message
Event ID 78 — BITS has encountered %1 error while reading the peer-cache information.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 79 — BITS has successfully deleted the peer-cache.
Message
Event ID 80 — BITS has successfully enabled peer-client and/or peer-server related components.
Message
Event ID 81 — BITS has encountered %1 error while starting one or more peer-client or peer-server components.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 82 — BITS accessed group policy value %1 : %2.
Message
Fields
| Name | Description |
|---|---|
Title | — |
PolicyValue | — |
Event ID 83 — BITS defaulted group policy value %1 : %2.
Message
Fields
| Name | Description |
|---|---|
Title | — |
PolicyValue | — |
Event ID 101 — The peer's response to a search was invalid.
Message
Fields
| Name | Description |
|---|---|
requestId | — |
responseXml | — |
Event ID 102 — The file ranges associated with a transfer attempt
Message
Fields
| Name | Description |
|---|---|
xferId | — |
count | — |
ranges | — |
Event ID 200 — While transferring %1, BITS encountered error %2 using %3 as the HTTP proxy server.
Message
Fields
| Name | Description |
|---|---|
URL | }, {URL. |
hr | }, {hr. |
owner | 3 as the HTTP proxy server. This may indicate a problem with the proxy server or with the client's network configuration. If this error occurs frequently, then an administrator should investigate. Details: {Job. |
jobid | }, {owner. |
xferId | }, {jobid. |
proxyServerList | }, {xferId. |
url | — |
proxy | — |
job | — |
jobId | — |
Event ID 201 — The BITS job named ".
Message
Fields
| Name | Description |
|---|---|
job | — |
jobId | — |
jobOwner | — |
url | — |
transferId | — |
proxyServerList | — |
proxyBypassList | — |
error | — |
Event ID 202 — While transferring %1, BITS encountered error %7 using %6 as the HTTP proxy server.
Message
Fields
| Name | Description |
|---|---|
owner | }, {owner. |
jobId | }, {jobId. |
url | }, {url. |
xferId | }, {xferId. |
proxyServer | }, {proxyServer. |
hr | }, {hr. |
urlContentLength | }, {urlContentLength. |
urlHttpVersion | }, {urlHttpVersion. |
urlRange | }, {urlRange. |
jobName | — |
jobOwner | — |
proxy | — |
fileLength | — |
HTTPVersion | — |
URLRange | — |
Event ID 203 — The BITS service provided job credentials in response to an authentication challenge from the %1 server for the %2 transfer job that is associated ...
Message
Fields
| Name | Description |
|---|---|
server | — |
job | — |
url | — |
scheme | — |
user | — |
Event ID 204 — The BITS service provided job credentials in response to an authentication challenge from %1 for job %2, url %3.
Message
Fields
| Name | Description |
|---|---|
server | — |
job | — |
url | 2 transfer job that is associated with the following URL. |
scheme | — |
user | — |
Event ID 205 — A bandwidth slot transition occurred.
Message
Fields
| Name | Description |
|---|---|
profileType | — |
currSlotStartTime | — |
currSlotBandwidthLimit | — |
nextSlotStartTime | — |
nextSlotBandwidthLimit | — |
Event ID 206 — The URL ".
Message
Fields
| Name | Description |
|---|---|
jobName | — |
url | — |
Event ID 207 — The URL ".
Message
Fields
| Name | Description |
|---|---|
jobName | — |
url | — |
Event ID 208 — A flash-Crowd situation is detected for the URL ".
Message
Fields
| Name | Description |
|---|---|
jobName | — |
url | — |
Event ID 209 — High performance property for BITS job ".
Message
Fields
| Name | Description |
|---|---|
jobName | — |
jobId | — |
isRoaming | — |
Example Event
system:
provider: Microsoft-Windows-Bits-Client
guid: EF1CC15B-46C1-414E-BB95-E76B077BD51E
event_source_name: ''
event_id: 209
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:27:06.012810+00:00'
event_record_id: 121
correlation:
ActivityID: F590C418-1079-0000-98E3-90F57910DA01
execution:
process_id: 5620
thread_id: 4004
channel: Microsoft-Windows-Bits-Client/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
jobName: Font Download
jobId: 45827C8A-7310-400E-A51E-179189C5AC76
isRoaming: 1
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 210 — The URL ".
Message
Fields
| Name | Description |
|---|---|
jobName | — |
url | — |
Event ID 211 — BITS job ".
Message
Fields
| Name | Description |
|---|---|
JobGuid | — |
Title | — |
ErrorCode | — |
Message | — |
Event ID 212 — BITS service has detected a '.
Message
Fields
| Name | Description |
|---|---|
SystemEvent | — |
Event ID 213 — Job is not currently transferring because one of its transfer policies conflicts with current system state.
Message
Fields
| Name | Description |
|---|---|
jobName | — |
jobId | — |
FileCount | — |
BlockReasonErrorCode | — |
Event ID 281 — The service is generating its common global data.
Message
Event ID 282 — The service is reading its group policy settings.
Message
Event ID 283 — The service is creating its performance counters.
Message
Event ID 284 — The service is searching for gateway devices.
Message
Event ID 285 — The service is starting the peer-caching client.
Message
Event ID 286 — The service is starting the peer-caching server.
Message
Event ID 287 — The service is reading the job list from the disk.
Message
Event ID 288 — The service is updating its list of active network connections.
Message
Event ID 289 — The service is updating its list of logged-in users.
Message
Event ID 290 — The service is creating the Volume Shadow Copy writer.
Message
Event ID 291 — The service is registering its COM objects.
Message
Event ID 301 — The BITS service has started successfully.
Message
Event ID 302 — The BITS service has started successfully, but it was delayed long enough that there may be a problem.
Message
Event ID 303 — The peer-cache client startup phase of startup has completed.
Message
Event ID 304 — The service is shutting down.
Message
Event ID 305 — The service shutdown is complete.
Message
Event ID 306 — The BITS service loaded the job list from disk.
Message
Example Event
system:
provider: Microsoft-Windows-Bits-Client
guid: EF1CC15B-46C1-414E-BB95-E76B077BD51E
event_source_name: ''
event_id: 306
version: 0
level: 5
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-06T00:47:39.589942+00:00'
event_record_id: 416
correlation: {}
execution:
process_id: 16164
thread_id: 16220
channel: Microsoft-Windows-Bits-Client/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 307 — It took %1 seconds to write a change file to the BITS job list.
Message
Fields
| Name | Description |
|---|---|
number | — |
Event ID 308 — The BITS service shut down successfully, but it was delayed for %1 seconds.
Message
Fields
| Name | Description |
|---|---|
number | — |
Example Event
system:
provider: Microsoft-Windows-Bits-Client
guid: EF1CC15B-46C1-414E-BB95-E76B077BD51E
event_source_name: ''
event_id: 308
version: 0
level: 3
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2021-06-13T06:19:28.351119Z'
event_record_id: 17
correlation:
'#attributes':
ActivityID: 9E13646C-6014-0001-5C6E-139E1460D701
execution:
process_id: 1140
thread_id: 356
channel: Microsoft-Windows-Bits-Client/Operational
computer: sv-dc.hinokabegakure-no-sato.local
security:
user_id: S-1-5-18
event_data:
number: '3199.234'
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 309 — The BITS peer cache was unable to find any peers in the network.
Message
Event ID 310 — The initialization of the peer helper modules failed with the following error.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | The initialization of the peer helper modules failed with the following error. |
Example Event
system:
provider: Microsoft-Windows-Bits-Client
guid: EF1CC15B-46C1-414E-BB95-E76B077BD51E
event_source_name: ''
event_id: 310
version: 0
level: 3
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-06T00:48:24.805665+00:00'
event_record_id: 419
correlation: {}
execution:
process_id: 16164
thread_id: 15644
channel: Microsoft-Windows-Bits-Client/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
ErrorCode: 2147942450
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 311 — The BITS peer transfer with the %1 ID for the %2 transfer job resulted in the following error: %4.
Message
Fields
| Name | Description |
|---|---|
JobId | — |
JobName | — |
url | — |
ErrorCode | — |
ErrorContext | — |
bytesTransferredFromPeer | — |
PeerProtocolFlags | — |
Event ID 312 — The Network List Manager Cost Interface is not available on this system.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 313 — The Network List Manager Cost Interface is reporting no network connectivity.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 16384 — The administrator %4 canceled job "%2" on behalf of %3.
Message
Fields
| Name | Description |
|---|---|
Id | — |
Title | — |
Owner | — |
User | — |
processId | — |
ClientProcessStartKey | — |
Event ID 16385 — While canceling job ".
Message
Fields
| Name | Description |
|---|---|
Id | — |
Title | — |
FileList | — |
Event ID 16386 — While canceling job ".
Message
Fields
| Name | Description |
|---|---|
Id | — |
Title | — |
FileList | — |
Event ID 16387 — The administrator %3 modified the %4 property of job "%2".
Message
Fields
| Name | Description |
|---|---|
Id | — |
Title | — |
Owner | — |
PropertyName | — |
Event ID 16388 — The administrator %4 took ownership of job "%2" from %3.
Message
Fields
| Name | Description |
|---|---|
Id | — |
Title | — |
Owner | — |
User | — |
processId | — |
ClientProcessStartKey | — |
Event ID 16389 — Job ".
Message
Fields
| Name | Description |
|---|---|
Id | — |
Title | — |
Owner | — |
DayCount | — |
Event ID 16390 — Job ".
Message
Fields
| Name | Description |
|---|---|
Id | — |
Title | — |
Owner | — |
RetryWaitTime | — |
Event ID 16391 — The BITS job list is not in a recognized format.
Message
Event ID 16392 — The BITS service failed to start.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 16393 — BITS has encountered an error communicating with an Internet Gateway Device.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 16394 — BITS Peer-caching protocol
Message
Event ID 16395 — Web Services-Discovery protocol
Message
Event ID 16396 — Error %3 occurred when BITS tried to change the state of firewall rule "%1" to %2.
Message
Fields
| Name | Description |
|---|---|
rule | — |
enabled | — |
status | — |
Event ID 16397 — The Per-user job limit specified through Group Policy must be less than or equal to Per-computer job Limit.
Message
Fields
| Name | Description |
|---|---|
entityName | — |
currentSize | — |
currentLimit | — |
Event ID 16398 — A new BITS job could not be created.
Message
Fields
| Name | Description |
|---|---|
entityName | — |
currentSize | — |
currentLimit | — |
Event ID 16400 — A new BITS job could not be created.
Message
Fields
| Name | Description |
|---|---|
entityName | — |
currentSize | — |
currentLimit | — |
Event ID 16401 — BITS could not add file(s) to %1 job.
Message
Fields
| Name | Description |
|---|---|
entityName | — |
currentSize | — |
currentLimit | — |
Event ID 16402 — BITS could not add ranges to %1 file.
Message
Fields
| Name | Description |
|---|---|
entityName | — |
currentSize | — |
currentLimit | — |
Event ID 16403 —
Fields
| Name | Description |
|---|---|
User | — |
jobTitle | — |
jobId | — |
jobOwner | — |
fileCount | — |
RemoteName | — |
LocalName | — |
processId | — |
ClientProcessStartKey | — |
Example Event
system:
provider: Microsoft-Windows-Bits-Client
guid: EF1CC15B-46C1-414E-BB95-E76B077BD51E
event_source_name: ''
event_id: 16403
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-06T01:45:21.024078+00:00'
event_record_id: 433
correlation:
ActivityID: E4DB489E-1037-0002-3588-E4E43710DA01
execution:
process_id: 16164
thread_id: 18264
channel: Microsoft-Windows-Bits-Client/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
User: WINDEV2310EVAL\User
jobTitle: Chrome Component Updater
jobId: 9A25D168-24E6-4C66-AC78-5ED0E6007F1A
jobOwner: WINDEV2310EVAL\User
fileCount: 1
RemoteName: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acwcdm4bj7lx4xbm2ireywxlhvca_4.10.2710.0/oimompecagnajdejgnnjijobebaeigek_4.10.2710.0_win64_adsurwm4gclupf32xdrpgdnapira.crx3
LocalName: C:\Users\User\AppData\Local\Temp\chrome_BITS_2208_583787314\oimompecagnajdejgnnjijobebaeigek_4.10.2710.0_win64_adsurwm4gclupf32xdrpgdnapira.crx3
processId: 2208
ClientProcessStartKey: 3659174697241209
message: ''
Community Notes
May indicate download/staging. See this Google Cloud post Back in a Bit: Attacker Use of the Windows Background Intelligent Transfer ServiceSigma Rules
- BITS Transfer Job Downloading File Potential Suspicious Extension
Detects new BITS transfer job saving local files with potential suspicious extensions - BITS Transfer Job Download From File Sharing Domains
Detects BITS transfer job downloading files from a file sharing domain. - BITS Transfer Job Download From Direct IP
Detects a BITS transfer job downloading file(s) from a direct IP address. - BITS Transfer Job With Uncommon Or Suspicious Remote TLD
Detects a suspicious download using the BITS client from a FQDN that is unusual. Adversaries may abuse BITS jobs to persistently execute or clean up after malicious payloads. - BITS Transfer Job Download To Potential Suspicious Folder
Detects new BITS transfer job where the LocalName/Saved file is stored in a potentially suspicious location
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 16404 — The BITS service has detected an exception, Function: %1, Line: %2 Error code: %3.
Message
Fields
| Name | Description |
|---|---|
function | — |
line | — |
hr | — |
Event ID 16405 — A bandwidth profile is not configured correctly.
Message
Fields
| Name | Description |
|---|---|
Key | — |
SubKeyOrValueName | — |
Event ID 17005 — The BITS service is configured to run as %1.
Message
Fields
| Name | Description |
|---|---|
string | — |
string2 | — |
string3 | — |