Skip to content
BITS Client

BITS Event ID 60: Transfer stopped

BITS stopped transferring the transfer jobBITS event 60 records that BITS stopped transferring a job, with the job name, remote URL and status code — success, failure or interruption.
60
Event ID
60
Channel
Microsoft-Windows-Bits-Client/Operational
Provider
Microsoft-Windows-Bits-Client
Log file
Microsoft-Windows-Bits-Client%4Operational.evtx
Category
Network
Default logging
Logged by default

What event 60 means

Event 60 is written when BITS stops transferring a file for a job, whether because the transfer finished, failed or was suspended. It carries the same identification as event 59 — name, Id, transferId and url — plus the status code hr and transfer details such as bytesTransferred and proxy.

The hr field tells you how it ended: 0x0 is success; other values are HRESULTs from BITS or the network stack, including HTTP errors. Paired with 59, it shows whether a suspicious download actually succeeded and how much data moved.

Like 59, event 60 names the remote URL, so it is equally useful for hunting unusual download sources. Warning-level failures are logged separately as event 61.

When it is logged

Audit policy / configuration

None — the Microsoft-Windows-Bits-Client/Operational channel is enabled by default.

Key fields

FieldWhat it tells you
transferIdGUID of this file transfer.
nameName (title) of the job.
IdGUID of the job; matches jobId in events 3 and 4.
urlRemote URL of the file.
hrStatus code of the transfer. 0x0 means success; other values are BITS or HTTP-related HRESULTs (see the BITS return values reference).
bytesTransferredBytes transferred when the transfer stopped.
fileLengthSize of the remote file, when known.
proxyProxy used for the transfer, if any.

Common benign sources

  • Successful Windows and application update downloads (hr 0x0).
  • Transfers suspended and resumed as the network changes or the machine sleeps.

What attackers do that produces it

  • Successful completion of a payload download from attacker infrastructure.
  • Repeated failed attempts against a blocked or taken-down host, showing a persistent job or beacon-like retries.

Investigation tips

  • Pair with 59 by transferId and Id; check hr to confirm whether the download succeeded.
  • Stack url values and review uncommon hosts, raw IPs and non-standard ports.
  • For successful suspicious transfers, look for the resulting file (Sysmon 11) and its execution.

MITRE ATT&CK techniques

TechniqueTactics
T1197 BITS JobsStealth, Persistence, Execution
T1105 Ingress Tool TransferCommand and Control

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading