BITS Transfer Job Downloading File Potential Suspicious Extension

 Original Source: [Sigma source]
Title: BITS Transfer Job Downloading File Potential Suspicious Extension
Status: test
Description:Detects new BITS transfer job saving local files with potential suspicious extensions
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1197/T1197.md
Author: frack113
Date: 2022-03-01
modified:2023-03-27
Tags:
  • -'attack.persistence'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1197'
Logsource:
  • product: windows
  • service: bits-client
Detection:
  selection:
    EventID: '16403'
    LocalName|endswith:
      -'.bat'
      -'.dll'
      -'.exe'
      -'.hta'
      -'.ps1'
      -'.psd1'
      -'.sh'
      -'.vbe'
      -'.vbs'

  filter_optional_generic:
    LocalName|contains: '\AppData\'
    RemoteName|contains: '.com'
  condition:selection and not 1 of filter_optional_*
Falsepositives:
  -While the file extensions in question can be suspicious at times. It's best to add filters according to your environment to avoid large amount false positives
Level: medium