Skip to content
BITS Client

BITS Event ID 3: Job created

The BITS service created a new jobBITS event 3 records the creation of a BITS transfer job: job title, job ID, owner and, on newer builds, the process that created it.
3
Event ID
3
Channel
Microsoft-Windows-Bits-Client/Operational
Provider
Microsoft-Windows-Bits-Client
Log file
Microsoft-Windows-Bits-Client%4Operational.evtx
Category
Network
Default logging
Logged by default

What event 3 means

Event 3 is written when a program asks the Background Intelligent Transfer Service to create a transfer job — through bitsadmin, the Start-BitsTransfer cmdlet or the BITS COM API. It records the job title (jobTitle), its GUID (jobId) and the owner account (jobOwner); newer versions of the event add the creating process (processPath, processId).

BITS downloads files in the background on behalf of Windows and many applications, so job creation is routine. It is also a favorite for attackers: the download is done by the svchost.exe hosting BITS rather than by the attacker's process, it survives reboots, and jobs can be configured to run a command when they finish.

Event 3 does not include the URL. Follow the jobId to 59 and 60 (same job, with the remote URL) and to 4 (job complete).

When it is logged

Audit policy / configuration

None — the Microsoft-Windows-Bits-Client/Operational channel is enabled by default.

Older versions of the event only carry generic string fields with the job name and owner. The processPath and processId fields appear in newer versions of the event (Windows 10 era).

Key fields

FieldWhat it tells you
jobTitleDisplay name given to the job by the creating program. Legitimate software uses descriptive names; bitsadmin jobs carry whatever name the operator typed.
jobIdGUID of the job. Pivot on it to 59, 60 and 4.
jobOwnerAccount that owns the job (DOMAIN\user or NT AUTHORITY\SYSTEM).
processPathImage of the process that created the job, e.g. C:\Windows\System32\bitsadmin.exe or powershell.exe. Newer event versions only.
processIdProcess ID of the creating process. Newer event versions only.

Common benign sources

  • Windows components and Microsoft software downloading updates in the background.
  • Third-party updaters (browsers, vendor agents) that use BITS for their downloads.

What attackers do that produces it

  • Payload download with bitsadmin /transfer or Start-BitsTransfer to evade process-based network controls.
  • Persistent BITS jobs configured to run a command on completion (bitsadmin /SetNotifyCmdLine).
  • Exfiltration through upload jobs to an attacker-controlled server.

Investigation tips

  • Flag jobs whose processPath is bitsadmin.exe, powershell.exe or another script host, or whose title is unusual.
  • Follow jobId to 59/60 for the remote URL and status, and to 4 for completion.
  • Check bitsadmin /list /allusers /verbose (or Get-BitsTransfer -AllUsers) on a live host for jobs still queued and any notify command line.
  • Look for the downloaded file on disk (Sysmon 11) and for its execution afterward (Security 4688, Sysmon 1).

MITRE ATT&CK techniques

TechniqueTactics
T1197 BITS JobsStealth, Persistence, Execution
T1105 Ingress Tool TransferCommand and Control

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

2 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Low · 2

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading