Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

2 detections

Detects a Zoom client (zoom.exe/CptHost.exe) crashing or spawning an unexpected non-Zoom child process with an access-violation/stack-corruption/heap-overflow signature within 10 seconds of annotation-channel network activity, indicating attempted or successful exploitation of the ZOOMSDAY zero-click annotation RCE (CVE-2026-53413). Excludes known Zoom updater, crash-reporter, and screen-share helper processes.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
004
Detects a Zoom client (zoom.exe/zoom.us/CptHost.exe) terminating abnormally (SIGABRT/SIGSEGV/stack corruption) from within the annotation module (libannotate.so) within 30 seconds of receiving a message-type-75 (CAnnoObjAutoMetaShape) annotation object, indicating exploitation of the linked-list unlink write-what-where primitive (CVE-2026-53415). Excludes update-triggered restarts and graceful shutdowns.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003