Compliance Node Overview
MITRE ATT&CK T1197 (BITS Jobs) is an Enterprise Defense Evasion and Persistence technique. Adversaries may abuse BITS jobs to persistently execute code and perform various background tasks. Windows Background Intelligent Transfer Service (BITS) is a low-bandwidth, asynchronous file transfer mechanism exposed through Component Object Model (COM). BITS is commonly used by updaters, messengers, and other applications preferred to operate in the background (using available idle bandwidth) without interrupting other networked applications. Affected platforms: Windows. MITRE-documented mitigations include M1018 User Account Management, M1037 Filter Network Traffic, M1028 Operating System Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, CA-07, CM-05, CM-06.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1197/
SHA-256 integrity: e021d3e053aa05b2969ac6e31fd85967a8ee355922ee526e95a11c4512093d2d
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1197: BITS Jobs (https://attack.mitre.org/techniques/T1197/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access