Workflow
AntiFakeEvent
A new account joins the server. The account module assesses its age, avatar, name pattern and how it joined. A risk score is an observation, not yet an incident.
Example: An account created 40 minutes earlier, with no avatar and a randomly suffixed name.
SecuritySignal
Each observation is recorded as a signal with a type, confidence, source and privacy class. A single signal has little meaning; several appearing together tell a clearer story.
Example: Six joins in 90 seconds, all with the same name pattern and using the same invite.
SecurityIncident
Signals of the same type within one time window form an incident with a severity and operating mode. The incident records its window, signal count and recommended action, which has not yet been executed.
Example: A join-wave incident: HIGH severity, 6 signals, a 90-second window and a recommendation to raise the verification level.
ShieldSession / SecurityAction
New servers start in SHADOW mode: incidents are recorded and reported, but no action happens automatically. Execution requires the administrator to explicitly enable manual mode or limited automation.
Example: The administrator approves the action in the dashboard. The actor, time and grounds for the decision are recorded.
ChannelPermissionSnapshot
Before permissions change, their previous state is saved. Lifting a lockdown can then restore the exact previous configuration.
Example: The wave ends after 12 minutes. Lifting the lockdown restores 14 channels’ permissions from the snapshot.
The flow is one-way up to stage 4: an observation cannot trigger an action without an incident, and an incident cannot bypass the mode chosen by the administrator. Stage 5 reverses the effects using the saved permission snapshot.
Security Operations Center
| Type | Severity | Mode | State | Signals | Window | Notes |
|---|---|---|---|---|---|---|
| Join wave | HIGH | MANUAL | OPEN | 6 | 90 s | Six accounts with the same name pattern, using one invite. |
| Link spam | MEDIUM | SHADOW | OPEN | 3 | 4 min | The same shortened link posted in three channels. |
| Mass mentions | LOW | SHADOW | CLOSED | 2 | 2 min | Closed without action — the threshold was not reached. |
SHADOW mode means that an incident was recorded and reported without taking action. Every server starts this way. Automation begins only when the administrator explicitly allows it and sets its limits.
MSIoU dossier
przyklad_alfa · 100000000000000001
Passport: Enabled by the user — server counts are visible, server names are hidden
Details and source files: Trust Center .