Skip to content

Add BITS job and file records for Windows - #326

Merged
abrignoni merged 1 commit into
mainfrom
feat/bits-jobs
Sep 27, 2026
Merged

abrignoni merged 1 commit into
mainfrom
feat/bits-jobs

Conversation

@abrignoni

Copy link
Copy Markdown
Owner

Adds BITS support for Windows. Two artifacts from the BITS queue in ProgramData\Microsoft\Network\Downloader:

  • BITS Jobs: name, GUID, state, owner SID, notify command line and flags, error codes, created and modified times
  • BITS Job Files: remote URL, local and temporary names, bytes transferred and total, linked job

Live rows come from the Jobs and Files tables of qmgr.db. Older versions and jobs no longer in the tables are recovered from the database and its ESE log files, one row per distinct version. The record layout follows ANSSI's bits_parser, cited in the notes.

🤖 Generated with Claude Code

Reads the Background Intelligent Transfer Service queue (qmgr.db and its ESE log files)
into two artifacts, BITS Jobs and BITS Job Files. Live rows come from the Jobs and Files
tables; records flagged deleted there are counted in the run log, not reported. Other
versions and jobs no longer in the tables are found by searching the database and its logs
for the job and file marker GUIDs, one row per distinct version.

The record layout follows ANSSI's bits_parser structures, and both error entry sizes seen on
the tested builds (21 and 25 bytes) are handled. A size of all bits set (BG_SIZE_UNKNOWN) is
left blank, which also keeps the LAVA insert from overflowing.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@abrignoni
abrignoni merged commit 6ff589f into main Sep 27, 2026
11 checks passed
@abrignoni
abrignoni deleted the feat/bits-jobs branch September 27, 2026 08:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant