BITS Event ID 3: Job created
- Event ID
- 3
- Channel
- Microsoft-Windows-Bits-Client/Operational
- Provider
- Microsoft-Windows-Bits-Client
- Log file
- Microsoft-Windows-Bits-Client%4Operational.evtx
- Category
- Network
- Default logging
- Logged by default
What event 3 means
Event 3 is written when a program asks the Background Intelligent Transfer Service to create a transfer job — through bitsadmin, the Start-BitsTransfer cmdlet or the BITS COM API. It records the job title (jobTitle), its GUID (jobId) and the owner account (jobOwner); newer versions of the event add the creating process (processPath, processId).
BITS downloads files in the background on behalf of Windows and many applications, so job creation is routine. It is also a favorite for attackers: the download is done by the svchost.exe hosting BITS rather than by the attacker's process, it survives reboots, and jobs can be configured to run a command when they finish.
Event 3 does not include the URL. Follow the jobId to 59 and 60 (same job, with the remote URL) and to 4 (job complete).
When it is logged
None — the Microsoft-Windows-Bits-Client/Operational channel is enabled by default.
Older versions of the event only carry generic string fields with the job name and owner. The processPath and processId fields appear in newer versions of the event (Windows 10 era).
Key fields
| Field | What it tells you |
|---|---|
| jobTitle | Display name given to the job by the creating program. Legitimate software uses descriptive names; bitsadmin jobs carry whatever name the operator typed. |
| jobId | GUID of the job. Pivot on it to 59, 60 and 4. |
| jobOwner | Account that owns the job (DOMAIN\user or NT AUTHORITY\SYSTEM). |
| processPath | Image of the process that created the job, e.g. C:\Windows\System32\bitsadmin.exe or powershell.exe. Newer event versions only. |
| processId | Process ID of the creating process. Newer event versions only. |
Common benign sources
- Windows components and Microsoft software downloading updates in the background.
- Third-party updaters (browsers, vendor agents) that use BITS for their downloads.
What attackers do that produces it
- Payload download with
bitsadmin /transferorStart-BitsTransferto evade process-based network controls. - Persistent BITS jobs configured to run a command on completion (
bitsadmin /SetNotifyCmdLine). - Exfiltration through upload jobs to an attacker-controlled server.
Investigation tips
- Flag jobs whose processPath is
bitsadmin.exe,powershell.exeor another script host, or whose title is unusual. - Follow jobId to 59/60 for the remote URL and status, and to 4 for completion.
- Check
bitsadmin /list /allusers /verbose(orGet-BitsTransfer -AllUsers) on a live host for jobs still queued and any notify command line. - Look for the downloaded file on disk (Sysmon 11) and for its execution afterward (Security 4688, Sysmon 1).
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
2 SigmaHQ detection rules (release r2026-07-01) target this event.
- Low · 2
- LowNew BITS Job Created Via BitsadminRule by frack113, SigmaHQ, DRL 1.1
- LowNew BITS Job Created Via PowerShellRule by frack113, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.