BITS Event ID 59: Transfer started
- Event ID
- 59
- Channel
- Microsoft-Windows-Bits-Client/Operational
- Provider
- Microsoft-Windows-Bits-Client
- Log file
- Microsoft-Windows-Bits-Client%4Operational.evtx
- Category
- Network
- Default logging
- Logged by default
What event 59 means
Event 59 is written when BITS begins transferring a file for a job. It carries the job name (name), the job GUID (Id), a per-transfer GUID (transferId), the remote URL (url) and file details such as fileLength, bytesTotal and bytesTransferred.
The url field is what makes this event valuable: it is the only place in the BITS log that names the remote resource. Stacking URLs across a fleet quickly separates Microsoft and vendor update servers from raw IP addresses, paste sites, file-sharing services or newly registered domains.
A job can log 59 several times if the transfer is interrupted and resumed; the matching stop event is 60.
When it is logged
None — the Microsoft-Windows-Bits-Client/Operational channel is enabled by default.
Key fields
| Field | What it tells you |
|---|---|
| transferId | GUID of this file transfer. |
| name | Name (title) of the job; same value as jobTitle in event 3. |
| Id | GUID of the job; matches jobId in events 3 and 4. |
| url | Remote URL of the file being transferred. IP-based URLs, unusual ports and non-vendor hosts deserve review. |
| peer | Peer used for the transfer, when peer caching is involved; usually empty. |
| fileLength | Size of the remote file, when known. |
| bytesTotal | Total bytes to transfer. |
| bytesTransferred | Bytes already transferred when the event was written (non-zero on resumed transfers). |
Common benign sources
- Windows components and Microsoft products downloading from Microsoft update and CDN hosts.
- Application updaters fetching from their vendors' servers.
What attackers do that produces it
- Downloads of tools or payloads from attacker infrastructure, cloud storage or paste sites via
bitsadminor PowerShell. - Repeated transfers from the same unusual host, indicating a persistent BITS job.
Investigation tips
- Stack url values across hosts and review hosts that are rare or not tied to known software.
- Pivot on Id to event 3 for the creating process and owner, and to 60 for the result.
- Check DNS (Sysmon 22, DNS client logs) and proxy logs for the same host at the same time.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.