PHP file dropped into Forminator uploads directory via web server process
Detects the creation of .php files within the wp-content/uploads directory tree by common web server or PHP-FPM processes. This behavior is indicative of an adversary attempting to drop a web shell via file upload bypass vulnerabilities, such as those exploiting MIME-type manipulation.
Microsoft Sentinel (KQL)

