Skip to content
Browse the docs

Security

Antinuke

Stop nukes and hacked accounts, whitelist, extra owners and safety alerts.

Antinuke watches the audit log and stops people β€” or hacked bots β€” who delete channels, roles, ban members, add bots, create webhooks and so on. It's free for every server.

Quick start#

  1. Put Miwi's role at the very top (Server Settings β†’ Roles) and give it Administrator. Miwi can only act on members below it.
  2. /antinuke enable β€” a four-step setup: choose what to protect, the punishment, a log channel (or let Miwi create one) and who to whitelist, then test mode (Miwi logs what it would do) or protect now.
  3. Whitelist more later: /antinuke whitelist add @YourModBot (m!wl add @bot).
  4. /antinuke settings shows every protection with an On/Off button beside it β€” tap one to switch it. After a day of reviewing /security logs, go live: /security test-mode enabled:false.
  5. Optional: /owner extra add user:@co-owner for someone who helps run security.

How fast it reacts#

  • Straight from the audit-log stream. Each action arrives with who did it, so there's no polling and no "latest entry wins" guessing. Delayed entries are correlated by type, target and time.
  • Containment and clean-up run in parallel. The attacker is punished while their channels, roles, webhooks and bots are removed or restored. Floods (created channels, roles, webhooks, bots) are deleted first.
  • Critical changes act on the first occurrence, whatever the threshold: vanity URL changes, 2FA-requirement changes, and dangerous permissions (Administrator, Manage Server…) given to @everyone.
  • Strict defaults: one dangerous role grant, one bot added, one prune or one integration by an untrusted member is enough. Change any threshold with /security protection.
  • Administrator is not trust. Only the owner, extra owners and whitelist entries are trusted.

The trust model#

TierWhoWhat it means
πŸ‘‘ OwnerThe server ownerAlways trusted. Manages everything.
πŸ”‘ Extra ownerAdded by the owner (/owner extra add)Whitelisted for every action, can manage security and the whitelist, opens the dashboard, can't be moderated by anyone but the owner, and gets safety alerts. Max 10.
βœ… TrustedUsers, roles or bots on the whitelistNot punished for actions in their scope. Optionally protected (regular mods can't moderate them) and AutoMod bypass (on by default). Can be temporary.

Administrator is not trust. A hacked admin account is exactly what antinuke is for.

Commands#

Everyday commands (/antinuke)

CommandWhat it does
/antinuke enableGuided setup (safe to re-run to change anything)
/antinuke settingsEvery protection with its on/off switch, punishment, log channel, whitelist size
/antinuke disableTurn antinuke off
/antinuke whitelist add user: Β· remove user: Β· listPeople and bots antinuke never punishes

Advanced (/security)

CommandWhat it does
/security setupThe same setup as options: log channel, punishment, test mode, alert role
/security statusThe overview plus the last 7 days and lockdown state
/security toggle enabled: Β· /security test-mode enabled:Switch it on/off; test mode on/off
/security protection group: …Per group: on/off, threshold, window, punishment, revert
/security trust add target: scope: level: duration: protected: automod_bypass: note:Whitelist a user, role or bot
/security trust remove target: Β· /security trust listManage the whitelist
/security logsRecent decisions with reasons
/security lockdown start reason: Β· end Β· statusEmergency: lock every channel for @everyone
/security snapshot create Β· list Β· diff Β· restoreServer structure backups (channels, roles, permissions)

Scopes: Everything Β· Channels & overwrites Β· Roles & dangerous permissions Β· Bans, kicks & prunes Β· Bot additions Β· Webhooks Β· Emojis & stickers Β· Server settings, integrations, events, AutoMod Β· Bulk message deletion. Adding a second scope to the same entry widens it.

Prefix aliases: m!an (= antinuke), m!wl add @user, m!extraowner, m!eo.

Safety alerts#

When antinuke acts (or would act in test mode), a raid starts, or a lockdown begins, Miwi DMs the owner and every extra owner β€” with a link to the log and a Mute alerts for this server button. Alerts are throttled so an attack doesn't flood your DMs.

  • /owner alerts server:false β€” off for everyone (owner only)
  • /owner alerts me:false β€” mute just yourself
  • /owner alerts test:true β€” send a test alert

Dashboard#

Security page: protections, the whitelist (scope, expiry, protection, AutoMod bypass), recent events. Only the owner and extra owners can change it. Access & alerts page: the alert switch.

Troubleshooting#

ProblemFix
"Antinuke could not fully stop an attack"Miwi's role isn't high enough or lacks Administrator. Run /owner scan.
A trusted bot got punished/antinuke whitelist add trusts it for everything; a scoped /security trust add entry only covers its scope.
Nothing happensStill in test mode, or the protection for that group is off: /antinuke settings.
Unattributed eventsDiscord didn't write an audit log entry; Miwi never punishes without one.

Still stuck? Ask in the support server β€” real people answer.

Antinuke Β· Docs Β· Miwi