HomeFeaturesAnti-nuke

Moderation

Anti-nuke

One compromised admin can empty a server in minutes. Anti-nuke watches the audit log, strips roles when thresholds trip, and alerts you — without false-firing on real owner work.

  • Audit-log driven
  • Mass delete / mass ban trips
  • Role strip + alert
  • Structure snapshot recovery

Why teams turn it on

Audit-log aware

Mass channel/role deletes and mass bans are tied to real moderation events — not vibes from a single missing channel.

Fail closed on uncertainty

Better to miss a borderline case than strip a real admin on a guess. Dry-run mode lets you observe before you enforce.

Trusted exemptions

Owner and trusted actors stay exempt so legitimate rebuilds, migrations, and cleanups are not treated as attacks.

Recover the shell

Optional structure snapshots capture roles and channels so you can recreate what a nuke deleted — not just stop the actor.

How it works

  1. 1. Watch the audit log

    Destructive admin actions are counted per actor over a short window.

  2. 2. Threshold trips

    Non-trusted actors who exceed mass-delete or mass-ban limits are treated as a nuke attempt.

  3. 3. Contain, alert, recover

    Roles can be stripped and operators alerted. If a pre-nuke structure snapshot exists, restore missing roles and channels from the dashboard.

Real situations

Stolen admin token

A script starts deleting channels. Anti-nuke strips the actor mid-run and pings staff; restore brings categories back from the last snapshot.

Rogue co-owner drama

A trusted-list mistake still needs dry-run first — then enforce once thresholds match your risk tolerance.

Planned rebuild

Owner/trusted exempts and temporary disable (if you choose) keep real migrations safe.

FAQ

Can it demote the real owner?

Owner and configured trusted actors are exempt. Still keep owner accounts locked down.

Should I start in dry-run?

Yes for most servers — watch trips for a while, then flip enforce when thresholds look right.

Does restore put everything back perfectly?

It recreates missing roles and channels by name (categories first). Permission overwrites, exact positions, and renames may still need a human pass.