Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
3 detections
Filters
Last updated
All Time
Detection languages
3
Contributors
3
Categories
20,020
11,432
5,769
4,979
4,820
Platforms
3
3
3
Products / Services
3
MITRE Techniques
3
3
CVEs
2
2
1
IDS Classtypes
3
IDS Protocols
2
1
Suricata signature detecting a Zoom annotation CAnnoFormatBlock/CAnnoTextFrame/CAnnoTextRange PDU where a count field (count1-4) precisely exceeds 64, overflowing the 128-byte destination buffer — the wire-level trigger for the ZOOMSDAY buffer overflow, stack overflow, and heap-disclosure primitives (CVE-2026-53413).
Suricata signature chain detecting a burst of 20+ 592-byte ExtChild AddObj annotation messages from a single source within 5 seconds (heap-spray pattern), followed by a RemoveObj/ModifyObj teardown operation consistent with dispatch through a corrupted vtable pointer — the full CVE-2026-53414 heap overflow and control-flow hijack chain.
Suricata signature for a Zoom annotation PDU carrying opcode 0x10001 (AddObj) delivered on the downstream acknowledgement channel (which should only carry 0x10002/AddObjAck), indicating sender-role/opcode confusion that lets any participant forge presenter-privileged annotation objects (ZOOMSDAY, CVE-2026-53413/53414/53415).
