Skip to content
BITS Client

BITS Event ID 4: Job completed

The transfer job is completeBITS event 4 records that a BITS transfer job completed: job title, ID, owner, file count and bytes transferred. Confirms a download or upload finished.
4
Event ID
4
Channel
Microsoft-Windows-Bits-Client/Operational
Provider
Microsoft-Windows-Bits-Client
Log file
Microsoft-Windows-Bits-Client%4Operational.evtx
Category
Network
Default logging
Logged by default

What event 4 means

Event 4 is written when a BITS job finishes transferring all its files. It records the user (User), the job title and GUID (jobTitle, jobId), the owner (jobOwner), the number of files (fileCount) and, in newer versions, the byte counts (bytesTransferred, bytesTransferredFromPeer).

Where event 3 shows intent, event 4 shows success: the data really arrived (or left, for upload jobs). The byte count helps judge what was moved — a few hundred kilobytes for a tool, much more for staged data or large payloads.

The event does not name the URL or the local file. Use jobId to find the matching 59/60 events for the URL, and file creation telemetry for where the file landed.

When it is logged

Audit policy / configuration

None — the Microsoft-Windows-Bits-Client/Operational channel is enabled by default.

Key fields

FieldWhat it tells you
UserUser context of the job.
jobTitleDisplay name of the job.
jobIdGUID of the job; matches event 3 and the job ID in 59/60.
jobOwnerAccount that owns the job.
fileCountNumber of files in the job.
bytesTransferredTotal bytes transferred by the job (newer event versions).
bytesTransferredFromPeerBytes obtained from peers rather than the origin server (newer event versions).

Common benign sources

  • Completion of Windows and application update downloads.
  • Enterprise software distribution that uses BITS.

What attackers do that produces it

  • Completion of a tool or payload download started with bitsadmin or Start-BitsTransfer.
  • Completion of an upload job used to exfiltrate data.

Investigation tips

  • Match jobId with event 3 (creator) and 59/60 (URL) to build the full job story.
  • Use bytesTransferred to size the transfer and prioritize.
  • Find the local file (Sysmon 11, file system timeline) and check whether it was executed afterward.

MITRE ATT&CK techniques

TechniqueTactics
T1197 BITS JobsStealth, Persistence, Execution
T1105 Ingress Tool TransferCommand and Control

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading