Reverse Security
Log in with Discord

Protection modules

Anti-raid, anti-nuke, anti-spam, phishing, webhooks, bots, NSFW, risk, staff guard, impersonation.

Anti-raid

Counts joins in a rolling window. When the threshold is crossed, a lockdown starts: verification level is raised, invites are paused and, optionally, channels are locked. The lockdown is stored in the database, ends automatically after its duration (even across restarts), and restoration only reverts values that staff did not change in the meantime. Accounts younger than the minimum age can be timed out, kicked or banned.

Anti-spam

Detects floods, repeated content, the same message across channels, mass mentions and mention bursts, invites to other servers, and giant messages (estimated rendered height, empty lines, invisible characters). Strikes escalate from deletion to timeout and optionally kick. Messages from user-installed apps are attributed to the invoking user only when Discord provides that information; nobody is punished on a guess. Staff exemption roles skip routine checks, but compromise detection (phishing, floods, mention bursts from staff accounts) still applies.

Coordinated raids

Near-identical messages (3-gram similarity) from several distinct accounts within a window are deleted together, participants can be timed out, and detections of the same wave are grouped into one incident with evidence.

Anti-nuke

Uses Discord's audit log to attribute channel/role deletions, mass bans and kicks, prunes, webhook creation, dangerous permission grants and server changes to a specific account. When an account exceeds a threshold it is neutralised (roles removed and timed out, kicked or banned; malicious bots banned and proposed for human blacklist review), the owner is alerted, deleted channels and roles are rebuilt from the gateway cache or the latest backup, and bans made during the attack are lifted. Dangerous permissions granted to @everyone and private channels opened publicly are reverted immediately. The bot's own restoration actions are excluded by identity, so restoration never triggers another incident. If the bot lacks a permission or is below the attacker's role, the incident and module health say so.

Anti-phishing

Links are extracted (including obfuscated forms), normalised (IDN/punycode, registrable domain) and checked against maintained threat feeds, your allow/block lists, lookalikes of well-known brands (homoglyphs, edit distance, mixed scripts) and fake-Nitro lures. Links are never opened. Feed freshness and failures are visible in Diagnostics and on the status page.

Anti-webhook

Webhook messages are rate-checked and scanned; abusive webhooks are deleted. Webhook creation, updates and deletions are logged with the actor. The platform's own logging and bridge webhooks are recognised and never treated as abuse.

Bot quarantine

New bots lose roles with dangerous permissions (and their own integration role is stripped when possible) until the owner approves from the dashboard or a DM button. Approval restores only permissions the bot itself can legally grant; anything above the bot's role is reported, not silently ignored. While pending, attempts by others to give the bot dangerous roles back are reverted.

NSFW filter

Text rules resist spacing, punctuation, leetspeak and homoglyph tricks while avoiding common false positives. Image analysis (optional, requires an image provider) samples GIF frames within resource limits. Detection is never infallible.

Risk score

An explainable 0–100 score from account age, default avatar, reviewed reputation (platform blacklist, network bans, prior incidents), impersonation similarity, suspicious names and joining during a raid. Weights are configurable and automatic sanctions are off by default. A high score is a signal for review, not proof.

Staff guard and anti-impersonation

Sensitive roles granted to new or risky accounts are removed and saved for owner-reviewed restoration. Names and, where available, avatar perceptual hashes are compared with owner and staff identities.