BITS Event ID 60: Transfer stopped
- Event ID
- 60
- Channel
- Microsoft-Windows-Bits-Client/Operational
- Provider
- Microsoft-Windows-Bits-Client
- Log file
- Microsoft-Windows-Bits-Client%4Operational.evtx
- Category
- Network
- Default logging
- Logged by default
What event 60 means
Event 60 is written when BITS stops transferring a file for a job, whether because the transfer finished, failed or was suspended. It carries the same identification as event 59 — name, Id, transferId and url — plus the status code hr and transfer details such as bytesTransferred and proxy.
The hr field tells you how it ended: 0x0 is success; other values are HRESULTs from BITS or the network stack, including HTTP errors. Paired with 59, it shows whether a suspicious download actually succeeded and how much data moved.
Like 59, event 60 names the remote URL, so it is equally useful for hunting unusual download sources. Warning-level failures are logged separately as event 61.
When it is logged
None — the Microsoft-Windows-Bits-Client/Operational channel is enabled by default.
Key fields
| Field | What it tells you |
|---|---|
| transferId | GUID of this file transfer. |
| name | Name (title) of the job. |
| Id | GUID of the job; matches jobId in events 3 and 4. |
| url | Remote URL of the file. |
| hr | Status code of the transfer. 0x0 means success; other values are BITS or HTTP-related HRESULTs (see the BITS return values reference). |
| bytesTransferred | Bytes transferred when the transfer stopped. |
| fileLength | Size of the remote file, when known. |
| proxy | Proxy used for the transfer, if any. |
Common benign sources
- Successful Windows and application update downloads (hr
0x0). - Transfers suspended and resumed as the network changes or the machine sleeps.
What attackers do that produces it
- Successful completion of a payload download from attacker infrastructure.
- Repeated failed attempts against a blocked or taken-down host, showing a persistent job or beacon-like retries.
Investigation tips
- Pair with 59 by transferId and Id; check hr to confirm whether the download succeeded.
- Stack url values and review uncommon hosts, raw IPs and non-standard ports.
- For successful suspicious transfers, look for the resulting file (Sysmon 11) and its execution.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.