DFIR Reference v0.1

BITS Event Reference

Reference for Background Intelligent Transfer Service (BITS) forensic analysis. Covers the Microsoft-Windows-Bits-Client/Operational log — the primary and often only source of BITS forensic evidence, since BITS jobs are stored in a database rather than the file system. Focused on stealthy downloads, exfiltration, and fileless persistence via SetNotifyCmdLine.

7Event IDs
1Log Channels
6Sigma Rules
Bits-Client/Operational
Showing 7 of 7 events

⚡ Sigma Detection Rules — BITS Event Reference

Curated highest-signal Sigma-style detection rules for BITS Event Reference activity, based on patterns from SigmaHQ/sigma. Click any Event ID chip to jump to that event in the reference tab.

Convert to your SIEM: sigconverter.io

6 detection rules 4 event IDs covered
Copied!