Security and AutoMod
AutoMod rules with strikes and escalation, anti-raid, quarantine, lockdown and security incidents.
The Security module is on by default, but every AutoMod rule is off until an administrator turns it on.
AutoMod#
AutoMod checks messages against the enabled rules. It ignores bots, the server owner, staff with MODERATOR or above, and anyone or anywhere you exempt. One message produces at most one decision.
Built-in rules include spam, flooding, duplicate messages, mention spam, capital letters, emoji, invites, link filters, word and regex filters, scam links, token leaks, unicode abuse, message length and ghost pings. You can create custom word, regex, URL or scam rules.
Actions: delete the message and/or a punishment (
WARN,TIMEOUT,QUARANTINE,KICK,BAN), with severity and strike points.Strikes and escalation: hits add strikes; an escalation ladder such as
3:timeout:10m,5:timeout:1h,8:kickdecides what happens as they add up. Strikes expire after a time you choose.Start with
/automod rule-list, then enable and configure rules one at a time.
Anti-raid, quarantine and lockdown#
Anti-raid watches for waves of new members and can alert, quarantine, kick or ban, and trigger an automatic lockdown. Configure it with
/security raid config.Quarantine takes a member's roles away behind a quarantine role and gives them back on release.
Lockdown denies
@everyoneSend Messages in every text channel Aurora can manage and restores each channel exactly as it was when the lockdown ends.Incidents record what the security engines found; resolve or dismiss them with
/security incidents.
Commands
Generated from Aurora's command registry. The command reference has search and filters.
| Command | What it does | Who |
|---|---|---|
/automod escalation-set | Set the ladder, e.g. 3:timeout:10m,5:kick,12:tempban:7d | Administrator group |
/automod escalation-show | Show the strike escalation ladder | Administrator group |
/automod exempt-add | Exempt a role, channel or user from AutoMod | Administrator group |
/automod exempt-remove | Remove an AutoMod exemption | Administrator group |
/automod rule-action | Set what a rule does: delete, punishment, severity, points | Administrator group |
/automod rule-add | Add an entry to a rule list (words, patterns, domains) | Administrator group |
/automod rule-config | Change one threshold of a rule (for example count or windowSeconds) | Administrator group |
/automod rule-create | Create a named custom word, regex, URL or scam rule | Administrator group |
/automod rule-delete | Delete a custom rule | Administrator group |
/automod rule-disable | Turn a rule off | Administrator group |
/automod rule-enable | Turn a rule on | Administrator group |
/automod rule-list | List every AutoMod rule and whether it is on | Administrator group |
/automod rule-remove | Remove an entry from a rule list | Administrator group |
/automod rule-show | Show one rule with its thresholds | Administrator group |
/automod settings-quarantine-role | Set or clear the quarantine role | Administrator group |
/automod settings-security-log | Set or clear the security log channel | Administrator group |
/automod settings-strike-ttl | Set how many days a strike counts | Administrator group |
/automod strikes-add | Give a user strikes by hand (counts towards escalation) | Moderator group |
/automod strikes-view | Show the active strikes of a user | Moderator group |
/security incidents | List recent security incidents | Security Manager group |
/security lockdown end | End the lockdown and restore every channel | Security Manager group + Manage Channels |
/security lockdown start | Stop @everyone from writing everywhere (restorable exactly) | Security Manager group + Manage Channels |
/security lockdown status | Show whether a lockdown is active | Security Manager group |
/security quarantine add | Quarantine a member (their roles are saved) | Moderator group + Manage Roles |
/security quarantine list | List quarantined members | Moderator group |
/security quarantine release | Release a member and give their roles back | Moderator group + Manage Roles |
/security raid config | Configure join-wave detection and the response | Administrator group |
/security raid status | Show the anti-raid configuration | Security Manager group |
/security resolve | Resolve or dismiss an incident | Security Manager group |
/security status | Show threat level, lockdown, rules and engine status | Security Manager group |
/security threat | Set the threat level by hand | Security Manager group |