Skip to content
BITS Client

BITS Event ID 59: Transfer started

BITS started the transfer jobBITS event 59 records that BITS started transferring a job, with the job name and the remote URL — the event that tells you where BITS was downloading from.
59
Event ID
59
Channel
Microsoft-Windows-Bits-Client/Operational
Provider
Microsoft-Windows-Bits-Client
Log file
Microsoft-Windows-Bits-Client%4Operational.evtx
Category
Network
Default logging
Logged by default

What event 59 means

Event 59 is written when BITS begins transferring a file for a job. It carries the job name (name), the job GUID (Id), a per-transfer GUID (transferId), the remote URL (url) and file details such as fileLength, bytesTotal and bytesTransferred.

The url field is what makes this event valuable: it is the only place in the BITS log that names the remote resource. Stacking URLs across a fleet quickly separates Microsoft and vendor update servers from raw IP addresses, paste sites, file-sharing services or newly registered domains.

A job can log 59 several times if the transfer is interrupted and resumed; the matching stop event is 60.

When it is logged

Audit policy / configuration

None — the Microsoft-Windows-Bits-Client/Operational channel is enabled by default.

Key fields

FieldWhat it tells you
transferIdGUID of this file transfer.
nameName (title) of the job; same value as jobTitle in event 3.
IdGUID of the job; matches jobId in events 3 and 4.
urlRemote URL of the file being transferred. IP-based URLs, unusual ports and non-vendor hosts deserve review.
peerPeer used for the transfer, when peer caching is involved; usually empty.
fileLengthSize of the remote file, when known.
bytesTotalTotal bytes to transfer.
bytesTransferredBytes already transferred when the event was written (non-zero on resumed transfers).

Common benign sources

  • Windows components and Microsoft products downloading from Microsoft update and CDN hosts.
  • Application updaters fetching from their vendors' servers.

What attackers do that produces it

  • Downloads of tools or payloads from attacker infrastructure, cloud storage or paste sites via bitsadmin or PowerShell.
  • Repeated transfers from the same unusual host, indicating a persistent BITS job.

Investigation tips

  • Stack url values across hosts and review hosts that are rare or not tied to known software.
  • Pivot on Id to event 3 for the creating process and owner, and to 60 for the result.
  • Check DNS (Sysmon 22, DNS client logs) and proxy logs for the same host at the same time.

MITRE ATT&CK techniques

TechniqueTactics
T1197 BITS JobsStealth, Persistence, Execution
T1105 Ingress Tool TransferCommand and Control

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading