The GIAC
BITS Forensics and Malicious Usage Analysis
Pages
29
Time to read
36 mins
Publication
Language
English
Pages
29
Time to read
36 mins
Publication
Language
English
This technical report focuses on the Background Intelligent Transfer Service (BITS), a Microsoft technology designed for efficient file transfers. The paper outlines how BITS can be exploited for malicious purposes, detailing its capabilities to manage downloads and uploads while maintaining resilience against interruptions. It discusses the evolution of BITS usage in cyberattacks, highlighting various malware that have leveraged this service to bypass security measures. The report presents a comparative analysis of the traces left by BITS in network traffic, hard disk, and RAM examinations, emphasizing the limitations of each analysis type. The methodology section describes the virtual machine environment used for testing BITS sessions, including manual and simulated attacks. The findings illustrate the increasing trend of using BITS for malicious activities, reinforcing the need for awareness and monitoring of this service within cybersecurity frameworks.