BITS Transfer Job Download To Potential Suspicious Folder

 Original Source: [Sigma source]
Title: BITS Transfer Job Download To Potential Suspicious Folder
Status: test
Description:Detects new BITS transfer job where the LocalName/Saved file is stored in a potentially suspicious location
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1197/T1197.md
Author: Florian Roth (Nextron Systems)
Date: 2022-06-28
modified:2023-03-27
Tags:
  • -'attack.persistence'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1197'
Logsource:
  • product: windows
  • service: bits-client
Detection:
  selection:
    EventID: '16403'
    LocalName|contains:
      -'\Desktop\'
      -'C:\Users\Public\'
      -'C:\PerfLogs\'

  condition:selection
Falsepositives:
  -Unknown
Level: high