Anti-nuke
What it watches, how it stops an attack, how it puts everything back - and why only the owner can switch it off.
A nuke is somebody with permissions deleting everything as fast as Discord allows. It takes about forty seconds. Nobody is watching at four in the morning, and by the time somebody is, the channels are gone.
Arklynn reads the audit log for every destructive action, works out who did it, and counts. When a count runs out the account is stopped - and then everything it did in the last ten minutes is reversed, not only the last thing.
Free, like everything in Arklynn. There is no paid version of this module and there never will be.
Turning it on
- 1Run /antinuke toggle on. A backup of the server structure is taken at the same moment. The defaults are sensible and you can stop here - everything below is tuning.
- 2Run /antinuke logs and pick a channel only moderators can see. Without one it still protects, but you find out by asking rather than by reading.
- 3Run /antinuke trust add for a co-owner who should be able to change these settings. See "Who can change the settings" below.
- 4Run /antinuke whitelist add for bots or people that legitimately create and delete a lot of channels or roles.
- 5Run /antinuke status. It lists everything - and warns you if any role with dangerous permissions sits above Arklynn's, because nobody holding that role can be stopped.
Put Arklynn's role at the top of the role list, or as close to it as you can. Discord does not let a bot act on anybody whose highest role is above its own - not to stop them, not to take a role back.
Who can change the settings
Only the server owner, and the people the owner names with /antinuke trust. Not every administrator. This is the most important rule in the module: the most common attack is an admin account that has been taken over, and if any admin could run /antinuke toggle off, the attacker would do exactly that first. The same lock applies to the dashboard.
| Who | Can change settings | Is ever punished |
|---|---|---|
Server owner | Yes | Never |
Trusted (/antinuke trust) | Yes | Never |
Whitelisted (/antinuke whitelist) | No | Never |
Everybody else, admins included | No | When they cross a limit |
Trust and whitelist only accounts with two-factor authentication on. They are exactly the accounts an attacker wants.
Three clocks
A single counter is easy to stay under. Arklynn keeps three, and crossing any one of them stops the account.
| Clock | Catches | Example |
|---|---|---|
Burst | The fast nuke | 4 channels deleted inside 20 seconds. |
Ten minutes | The slow nuke that stays under the burst limit | 3 channels every 21 seconds - caught at the tenth. |
Combined score | The attack spread across several kinds of action | 2 channels and 2 roles deleted in a minute. Each action has a weight; deleting weighs more than creating. |
The combined score only counts when more than one kind of action is involved, so a moderator deleting four channels in a minute is judged by the burst limit alone - the one you set.
What counts as an attack
| What | Default limit | Why that number |
|---|---|---|
channel_delete | 4 in 20 seconds | Clearing up after an event deletes three or four by hand. A nuke deletes ten in the same breath. |
channel_create | 8 in 20 seconds | Spam-creating channels is the noisy half of a nuke. Setting up a category legitimately makes several. |
channel_update | 10 in 30 seconds | Renaming every channel, or opening every channel to @everyone. |
role_delete | 4 in 20 seconds | Same reasoning as channels. |
role_create | 8 in 20 seconds | Usually a precursor: create a role with Administrator, then use it. |
ban | 6 in 30 seconds | A moderator clearing a raid bans five quickly; a nuke bans the whole member list. |
kick | 8 in 30 seconds | Looser than bans - mass-kicking is the normal response to a raid. |
prune | Stopped at once above 10 members | Pruning is one click that removes hundreds. It never shows up as kicks. |
webhook_create | 4 in 30 seconds | A webhook can post as anybody, including @everyone. |
bot_add | 2 in 60 seconds | A malicious bot is the shortest route to owning a server. |
guild_update | 4 in 60 seconds | Renaming the server, the icon, the vanity URL. |
emoji_delete | 12 in 30 seconds | Emoji cleanups happen in bulk; a vandal deletes them all. |
dangerous_role | 2 in 60 seconds | Granting Administrator, Manage Server, Manage Roles, Ban Members and the rest. |
/antinuke limit action: channel_delete count: 3 seconds: 30Administrator is never handed out quietly
Every other permission is counted. Administrator is not: it is every permission at once, so the first grant by somebody who is not trusted is taken back immediately and logged. The same happens to a member who already has three warnings - they are not given dangerous permissions at all, whoever tries.
Stopping the attacker
| Punishment | What it does | When to pick it |
|---|---|---|
quarantine | Takes every role off the account, then times it out for a day. A timed-out member keeps only the right to read, so nothing they were given directly on a channel still works. | The default, and right for most servers. Reversible when it turns out to have been a mistake. |
kick | Removes them. They can come back with an invite, without their roles. | Rarely the right answer. |
ban | Removes them and keeps them out. | When the account is obviously not a member who made a mistake. |
/antinuke punishment kind: quarantineBots are always banned, whatever you pick. A bot's permissions live on its own managed role, which nobody can take off it - banning is the only thing that stops a bot whose token was stolen.
Putting it back
Every destructive action is written down with how to reverse it, from the object Discord sends at the moment it happens - newer than any backup, with every setting a backup does not keep. When an account is stopped, all of it is reversed in order: roles first, so restored channels can point their permissions at them; categories before the channels inside them.
| They did | Arklynn does |
|---|---|
Deleted channels or categories | Recreates them with name, category, position, permissions, topic, slowmode and NSFW flag |
Deleted roles | Recreates them with permissions, colour and position |
Created spam channels, roles or webhooks | Deletes them |
Banned members | Unbans them |
Renamed channels or changed their permissions | Sets them back |
Renamed the server or changed the icon | Sets it back |
Deleted emoji | Re-uploads them while Discord still has the image |
Gave out dangerous roles | Takes them back |
Two things cannot be undone. A restored role comes back empty - Discord does not tell a bot who had it. And kicks cannot be reversed; the people have to rejoin.
The alert has a Restore from backup button as well. It recreates anything still missing from the newest structure backup and leaves what exists alone, so pressing it twice is harmless. Only the owner and administrators can press it.
Backups
- 1A backup is taken every six hours and whenever you switch the module on. Save one by hand with /antinuke backup save after a big restructure.
- 2/antinuke backup list shows them, each timestamped. The newest 15 are kept.
- 3/antinuke backup restore recreates what is missing and leaves what exists alone.
When Arklynn cannot tell who it was
If the audit log does not name anybody - usually because Arklynn is missing View Audit Log - nobody can be punished. Instead of staying silent, the owner gets a message saying something destructive is happening and the attacker is unknown.
The scam filter
On by default on every server, and separate from the switch above: somebody who keeps the anti-nuke off still does not want free-nitro links in general. It deletes the message, times the account out for an hour - a scam is almost always a hacked account about to post the same thing everywhere - and counts it as a warning, so it runs through the same thresholds as one a moderator gave.
- Fake Discord and Steam links, including misspellings (dlscord, steamcommunlty) and the real name on somebody else's domain.
- Letters swapped for look-alikes: Cyrillic, Greek and leetspeak (n1tr0).
- @everyone with a link from somebody who is not allowed to ping everyone.
- Messages edited into a scam after they were posted.
- Scam phrases (free nitro, skins giveaways, crypto doubling) - only when the message also has a link, so asking about nitro in chat is fine.
/antinuke filter scam: on invites: Whitelisted roles onlyOne record
Everything the protection does to a member - a stopped attack, a scam, a tripwire catch - becomes a numbered case in the moderation log and an entry in that member's warning history. See Moderation for how the pieces fit together.
Checking an account
/antinuke check shows what Arklynn has seen of an account across every server it protects. Accounts that attacked a server or were caught by a tripwire elsewhere arrive already flagged.
From the website
The Anti-Nuke module in the dashboard is split into Protection, Who is trusted, Messages, Tripwire, Status and Limits. It has every limit as a number field, the trusted list, the tripwire channel with a Post tripwire button, and the backup buttons. Only the owner and trusted people can save it, and only the owner can change who is trusted.
Commands
Loading commands…