Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
4 detections
Filters
Last updated
All Time
Detection languages
3
1
Contributors
4
Categories
1
1
1
1
1
Platforms
4
3
3
Products / Services
4
1
1
1
MITRE Techniques
3
3
1
CVEs
68
68
60
58
49
IDS Classtypes
1
IDS Protocols
1
Flags Zoom Workplace, VDI Client for Windows, and Zoom Rooms processes running a version below the ZOOMSDAY-patched thresholds (7.1.5/7.0.6 Workplace, 7.0.11/6.6.16 VDI, 7.1.0 Rooms/SDK), using semantic major.minor.patch comparison per product line so versions are never compared against the wrong product's threshold.
Suricata signature for a Zoom annotation PDU carrying opcode 0x10001 (AddObj) delivered on the downstream acknowledgement channel (which should only carry 0x10002/AddObjAck), indicating sender-role/opcode confusion that lets any participant forge presenter-privileged annotation objects (ZOOMSDAY, CVE-2026-53413/53414/53415).
Correlates end-to-end encryption (E2EE) enablement events with either an absence of expected server-side annotation-filter log entries or a malformed annotation payload indicator (CAnnoFormatBlock/CAnnoTextFrame/CAnnoTextRange/CAnnoExtBlock/CAnnoPduAddObj fields) within the same 15-minute window, surfacing meetings where Zoom's server-side ZOOMSDAY mitigation could not inspect traffic.
Detects a Zoom client (zoom.exe/zoom.us/CptHost.exe) terminating abnormally (SIGABRT/SIGSEGV/stack corruption) from within the annotation module (libannotate.so) within 30 seconds of receiving a message-type-75 (CAnnoObjAutoMetaShape) annotation object, indicating exploitation of the linked-list unlink write-what-where primitive (CVE-2026-53415). Excludes update-triggered restarts and graceful shutdowns.
