Detection: selection: EventID:
'3' processPath|endswith:
'\bitsadmin.exe' condition:selection Falsepositives:
-Many legitimate applications or scripts could leverage "bitsadmin". This event is best correlated with EID 16403 via the JobID field Level:low