Detection rules › Sigma
BITS Transfer Job Download From File Sharing Domains
Detects BITS transfer job downloading files from a file sharing domain.
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Persistence | T1197 BITS Jobs |
| Defense Evasion | T1197 BITS Jobs |
Event coverage
| Provider | Event ID | Title |
|---|---|---|
| Bits-Client | 16403 |
Stages and Predicates
Stage 1: selection
or:
RemoteName|contains: .githubusercontent.com
RemoteName|contains: anonfiles.com
RemoteName|contains: cdn.discordapp.com
RemoteName|contains: ddns.net
RemoteName|contains: dl.dropboxusercontent.com
RemoteName|contains: ghostbin.co
RemoteName|contains: github.com
RemoteName|contains: glitch.me
RemoteName|contains: gofile.io
RemoteName|contains: hastebin.com
RemoteName|contains: mediafire.com
RemoteName|contains: mega.nz
RemoteName|contains: onrender.com
RemoteName|contains: pages.dev
RemoteName|contains: paste.ee
RemoteName|contains: pastebin.com
RemoteName|contains: pastebin.pl
RemoteName|contains: pastetext.net
RemoteName|contains: pixeldrain.com
RemoteName|contains: privatlab.com
RemoteName|contains: privatlab.net
RemoteName|contains: send.exploit.in
RemoteName|contains: sendspace.com
RemoteName|contains: storage.googleapis.com
RemoteName|contains: storjshare.io
RemoteName|contains: supabase.co
RemoteName|contains: temp.sh
RemoteName|contains: transfer.sh
RemoteName|contains: trycloudflare.com
RemoteName|contains: ufile.io
RemoteName|contains: w3spaces.com
RemoteName|contains: workers.dev
Indicators
Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.
| Field | Kind | Values |
|---|---|---|
RemoteName | match |
|
Neighbors
Broader alternatives (more inclusive than this rule)
These rules match a superset of what this rule catches. They cover the same events plus more. Use them if you want wider coverage and can absorb more false positives.
- BITS Transfer Job With Uncommon Or Suspicious Remote TLD (drops 1 filter this rule applies)