BITS Event ID 4: Job completed
- Event ID
- 4
- Channel
- Microsoft-Windows-Bits-Client/Operational
- Provider
- Microsoft-Windows-Bits-Client
- Log file
- Microsoft-Windows-Bits-Client%4Operational.evtx
- Category
- Network
- Default logging
- Logged by default
What event 4 means
Event 4 is written when a BITS job finishes transferring all its files. It records the user (User), the job title and GUID (jobTitle, jobId), the owner (jobOwner), the number of files (fileCount) and, in newer versions, the byte counts (bytesTransferred, bytesTransferredFromPeer).
Where event 3 shows intent, event 4 shows success: the data really arrived (or left, for upload jobs). The byte count helps judge what was moved — a few hundred kilobytes for a tool, much more for staged data or large payloads.
The event does not name the URL or the local file. Use jobId to find the matching 59/60 events for the URL, and file creation telemetry for where the file landed.
When it is logged
None — the Microsoft-Windows-Bits-Client/Operational channel is enabled by default.
Key fields
| Field | What it tells you |
|---|---|
| User | User context of the job. |
| jobTitle | Display name of the job. |
| jobId | GUID of the job; matches event 3 and the job ID in 59/60. |
| jobOwner | Account that owns the job. |
| fileCount | Number of files in the job. |
| bytesTransferred | Total bytes transferred by the job (newer event versions). |
| bytesTransferredFromPeer | Bytes obtained from peers rather than the origin server (newer event versions). |
Common benign sources
- Completion of Windows and application update downloads.
- Enterprise software distribution that uses BITS.
What attackers do that produces it
- Completion of a tool or payload download started with
bitsadminorStart-BitsTransfer. - Completion of an upload job used to exfiltrate data.
Investigation tips
- Match jobId with event 3 (creator) and 59/60 (URL) to build the full job story.
- Use bytesTransferred to size the transfer and prioritize.
- Find the local file (Sysmon 11, file system timeline) and check whether it was executed afterward.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.