Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
2 detections
Filters
Last updated
All Time
Detection languages
2
Contributors
2
Categories
20,020
11,432
5,769
4,979
4,820
Platforms
2
1
1
Products / Services
2
MITRE Techniques
2
2
CVEs
1
1
Detects a Zoom client (zoom.exe/CptHost.exe) crashing or spawning an unexpected non-Zoom child process with an access-violation/stack-corruption/heap-overflow signature within 10 seconds of annotation-channel network activity, indicating attempted or successful exploitation of the ZOOMSDAY zero-click annotation RCE (CVE-2026-53413). Excludes known Zoom updater, crash-reporter, and screen-share helper processes.
Detects a Zoom client (zoom.exe/zoom.us/CptHost.exe) terminating abnormally (SIGABRT/SIGSEGV/stack corruption) from within the annotation module (libannotate.so) within 30 seconds of receiving a message-type-75 (CAnnoObjAutoMetaShape) annotation object, indicating exploitation of the linked-list unlink write-what-where primitive (CVE-2026-53415). Excludes update-triggered restarts and graceful shutdowns.
