Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

5 detections

Flags Zoom Workplace, VDI Client for Windows, and Zoom Rooms processes running a version below the ZOOMSDAY-patched thresholds (7.1.5/7.0.6 Workplace, 7.0.11/6.6.16 VDI, 7.1.0 Rooms/SDK), using semantic major.minor.patch comparison per product line so versions are never compared against the wrong product's threshold.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
107
Suricata signature detecting a Zoom annotation CAnnoFormatBlock/CAnnoTextFrame/CAnnoTextRange PDU where a count field (count1-4) precisely exceeds 64, overflowing the 128-byte destination buffer — the wire-level trigger for the ZOOMSDAY buffer overflow, stack overflow, and heap-disclosure primitives (CVE-2026-53413).
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
105
Detects a Zoom client (zoom.exe/CptHost.exe) crashing or spawning an unexpected non-Zoom child process with an access-violation/stack-corruption/heap-overflow signature within 10 seconds of annotation-channel network activity, indicating attempted or successful exploitation of the ZOOMSDAY zero-click annotation RCE (CVE-2026-53413). Excludes known Zoom updater, crash-reporter, and screen-share helper processes.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
004
Suricata signature for a Zoom annotation PDU carrying opcode 0x10001 (AddObj) delivered on the downstream acknowledgement channel (which should only carry 0x10002/AddObjAck), indicating sender-role/opcode confusion that lets any participant forge presenter-privileged annotation objects (ZOOMSDAY, CVE-2026-53413/53414/53415).
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Correlates end-to-end encryption (E2EE) enablement events with either an absence of expected server-side annotation-filter log entries or a malformed annotation payload indicator (CAnnoFormatBlock/CAnnoTextFrame/CAnnoTextRange/CAnnoExtBlock/CAnnoPduAddObj fields) within the same 15-minute window, surfacing meetings where Zoom's server-side ZOOMSDAY mitigation could not inspect traffic.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003