Documentation menu

Security and AutoMod

AutoMod rules with strikes and escalation, anti-raid, quarantine, lockdown and security incidents.

The Security module is on by default, but every AutoMod rule is off until an administrator turns it on.

AutoMod#

AutoMod checks messages against the enabled rules. It ignores bots, the server owner, staff with MODERATOR or above, and anyone or anywhere you exempt. One message produces at most one decision.

Built-in rules include spam, flooding, duplicate messages, mention spam, capital letters, emoji, invites, link filters, word and regex filters, scam links, token leaks, unicode abuse, message length and ghost pings. You can create custom word, regex, URL or scam rules.

  • Actions: delete the message and/or a punishment (WARN, TIMEOUT, QUARANTINE, KICK, BAN), with severity and strike points.

  • Strikes and escalation: hits add strikes; an escalation ladder such as 3:timeout:10m,5:timeout:1h,8:kick decides what happens as they add up. Strikes expire after a time you choose.

  • Start with /automod rule-list, then enable and configure rules one at a time.

Anti-raid, quarantine and lockdown#

  • Anti-raid watches for waves of new members and can alert, quarantine, kick or ban, and trigger an automatic lockdown. Configure it with /security raid config.

  • Quarantine takes a member's roles away behind a quarantine role and gives them back on release.

  • Lockdown denies @everyone Send Messages in every text channel Aurora can manage and restores each channel exactly as it was when the lockdown ends.

  • Incidents record what the security engines found; resolve or dismiss them with /security incidents.

Commands

Generated from Aurora's command registry. The command reference has search and filters.

CommandWhat it doesWho
/automod escalation-setSet the ladder, e.g. 3:timeout:10m,5:kick,12:tempban:7dAdministrator group
/automod escalation-showShow the strike escalation ladderAdministrator group
/automod exempt-addExempt a role, channel or user from AutoModAdministrator group
/automod exempt-removeRemove an AutoMod exemptionAdministrator group
/automod rule-actionSet what a rule does: delete, punishment, severity, pointsAdministrator group
/automod rule-addAdd an entry to a rule list (words, patterns, domains)Administrator group
/automod rule-configChange one threshold of a rule (for example count or windowSeconds)Administrator group
/automod rule-createCreate a named custom word, regex, URL or scam ruleAdministrator group
/automod rule-deleteDelete a custom ruleAdministrator group
/automod rule-disableTurn a rule offAdministrator group
/automod rule-enableTurn a rule onAdministrator group
/automod rule-listList every AutoMod rule and whether it is onAdministrator group
/automod rule-removeRemove an entry from a rule listAdministrator group
/automod rule-showShow one rule with its thresholdsAdministrator group
/automod settings-quarantine-roleSet or clear the quarantine roleAdministrator group
/automod settings-security-logSet or clear the security log channelAdministrator group
/automod settings-strike-ttlSet how many days a strike countsAdministrator group
/automod strikes-addGive a user strikes by hand (counts towards escalation)Moderator group
/automod strikes-viewShow the active strikes of a userModerator group
/security incidentsList recent security incidentsSecurity Manager group
/security lockdown endEnd the lockdown and restore every channelSecurity Manager group + Manage Channels
/security lockdown startStop @everyone from writing everywhere (restorable exactly)Security Manager group + Manage Channels
/security lockdown statusShow whether a lockdown is activeSecurity Manager group
/security quarantine addQuarantine a member (their roles are saved)Moderator group + Manage Roles
/security quarantine listList quarantined membersModerator group
/security quarantine releaseRelease a member and give their roles backModerator group + Manage Roles
/security raid configConfigure join-wave detection and the responseAdministrator group
/security raid statusShow the anti-raid configurationSecurity Manager group
/security resolveResolve or dismiss an incidentSecurity Manager group
/security statusShow threat level, lockdown, rules and engine statusSecurity Manager group
/security threatSet the threat level by handSecurity Manager group