AddEventHandler("main", "OnEventLogGetAuditTypes", function () { return ["PHP_INJECTION" => "[SECURITY] PHP Injection"]; }); AddEventHandler("main", "OnEventLog", function (&$arFields) { if (strpos($arFields["DESCRIPTION"], 'wget') !== false || strpos($arFields["DESCRIPTION"], 'curl') !== false) { file_put_contents( $_SERVER["DOCUMENT_ROOT"] . "/local/php_inject.log", $_SERVER['REMOTE_ADDR'] . " : " . $arFields["DESCRIPTION"] . "\n", FILE_APPEND ); } });