How do you prepare a Discord server for an attack?
7
Configuration steps
5
Final tests
4
Errors solved
~8 min
Reading time
The answer
The short answer
Preparing a Discord server for an attack is five things done in advance: auditing the administrative permissions and requiring 2FA, backing up the roles and configuration, setting the protection thresholds (verification, AntiRaid, content protection), enabling the logs, and writing down a procedure saying who does what during an incident. In Venon Security you make a copy with /backup create or in Panel → Server → Backups, and you will find emergency mode in Panel → Security → Emergency mode — it is manual-first, so a lockdown and a restore both require human approval.
The content is checked against the bot's configuration — last verified: 2026-08-06.
Context
What the problem is
During an attack the team has a few minutes and plenty of adrenaline. Without preparation, costly mistakes come easily: somebody grants themselves permissions in a hurry, somebody else clears the channels along with the evidence, and the community gets no information at all and starts to panic on its own. Most of the work has to be done while nothing is happening.
Without an extra bot
What you can do with Discord alone
- 01
Review every role with the Administrator and Manage Server permissions — remove them from those that do not need them.
- 02
In the server settings, require 2FA for moderation actions.
- 03
Check the list of installed bots and remove the ones nobody uses any more.
- 04
Create a private crisis channel for the staff, outside the main channel tree.
- 05
Prepare a ready template for the community announcement in case of an incident.
Venon Security
What Venon Security adds
A backup saves the roles, the channels and the module configuration, and before every restore an automatic safety copy is created.
AntiRaid, verification and content protection work together — the gate, the thresholds and the filters close the three most common attack vectors.
Emergency mode (Venom Shield) runs containment and recovery in a manual-first model: the bot prepares the decision, but an administrator approves it.
Configuration
Configuration step by step
0 of 7 steps
Audit the permissions
Discord server settings → RolesThe greatest damage in an attack is done not by bots, but by compromised accounts with excessive permissions. Start by narrowing what anyone can do.
- List the roles with the Administrator permission — that should be individual people, not a category.
- Take Manage Channels, Manage Roles and Manage Webhooks away from everyone who does not need them for their work.
- Require 2FA for moderation actions in Server settings → Moderation.
- Remove unused webhooks and integrations — a common route to compromise.
Split panel access
Panel → Server → Panel accessAccess to the bot's configuration should be separate from Discord administrator permissions. That way, one compromised account does not mean everything is compromised.
- Add operators by Discord ID instead of giving them the server administrator role.
- In Panel → Server → Commands set Power Role, so moderators only have the commands they actually use.
- Panel → Server → Change log will then show who changed what.
Make a backup
Panel → Server → Backups/backup createA copy is your point of reference after an incident. Make one before every larger change to the server's structure and before campaigns that bring in a lot of new people.
- Describe the copy — before a promotional campaign, say — because in a month the date will tell you nothing.
- The copy covers roles, channels and the module configuration.
- Restoring overwrites the current configuration, so it requires confirmation, and an automatic safety copy is created beforehand.
- You can also check the list of copies with /backup list.
Set the protection thresholds
Panel → SecurityThresholds set in calm are realistic. Thresholds set in panic are always either too strict or too loose. Each module's details are covered in separate guides.
- Raid protection: Join wave (joins/min), Message spam (msg/5s), Slowmode, and possibly Automatic lockdown.
- Accounts and risk: AntiFake enabled plus a Quarantine role instead of an immediate ban.
- Content protection: AutoMod active, Anti-spam, Mention limit, LinkShield active.
- Community → Onboarding and verification: Verification active and Min. account age (days).
Prepare emergency mode
Panel → Security → Emergency modeEmergency mode handles containment and a controlled restore of the server. It works in a manual-first model, so a human makes the lockdown and recovery decisions and the bot prepares them.
- Enable the Shield policy and set an Execution mode matching how ready you are.
- Emergency notification channel: a staff channel outside the main structure, so alerts arrive even while the server is locked down.
- Incident notifications and the Digest window decide how often you get summary reports.
- Rehearse the sequence with the team: containment → review → recovery, before it is genuinely needed.
Enable the logs and alerts
Panel → Moderation → the Logs tabAfter an incident, only what was recorded counts. Logs enabled in advance are the difference between analysis and guesswork.
- Automatic setup creates the full set of log channels and sets the permissions.
- Enable the categories: Moderation, Deleted messages, Roles, Invites, Server.
- Set the RaidWatch alert channel in Panel → Security → Raid protection.
Write the procedure down and rehearse it
A three-sentence procedure everyone knows is worth more than a ten-page document nobody has read. The key part is naming one person who decides.
- Who declares a lockdown, and on what basis.
- Who writes the community announcement and where they publish it.
- Who collects the evidence, before anyone starts clearing channels.
- Who contacts trusted partners, if the attack concerns their servers too.
- Arrange a short exercise once a quarter — a dry run through the procedure is enough.
The steps you tick are saved in your browser — you can come back and finish later.
Verification
How to check the configuration worked
- 1
The list of roles with the Administrator permission fits in a few entries, and each of them is justified.
- 2
Panel → Server → Backups shows a copy from the last few days, with a readable description.
- 3
A test account with no roles is stopped at the verification gate.
- 4
The RaidWatch alert channel gets an entry after a threshold test — if it stays quiet, the alerts are not configured.
- 5
Every member of the staff can say who declares a lockdown without opening the document.
Diagnostics
When something does not work
A backup exists, but nobody knows exactly what it covers.
- Cause
- Copies created with no description and with no check of what a restore covers.
- Fix
- Describe every manual copy, and remember that restoring overwrites the current configuration. An automatic safety copy is created before a restore, so you have a way back.
During an incident nobody knows who makes the decisions.
- Cause
- No named decision-maker and no deputy.
- Fix
- Write the main person and their deputy into the procedure by name, plus the channel you use to reach each other. Without it every minute goes on establishing who is in charge.
After an attack the evidence is missing.
- Cause
- Somebody cleared the channels before the logs were secured.
- Fix
- Write the rule into the procedure: collect the evidence first, clean up second. An enabled Deleted messages log category saves the situation even when somebody moves too fast.
Emergency mode does not act automatically.
- Cause
- That is deliberate — Venom Shield works manual-first.
- Fix
- Approve containment, a lockdown or recovery in the panel. Automation is deliberately suspended here, so the bot does not lock the server down on a false alarm.
Honestly
What this configuration does not solve
A backup does not save messages. It restores roles, channels and configuration, but not the content of conversations.
Restoring channels is a risky operation and is off by default — deliberately, because it can duplicate the existing structure.
Venon will not protect you from the server owner's account being compromised. Only 2FA, a hardware key and login hygiene help there.
No configuration replaces people. Automation buys time, but the decisions in disputed situations are still made by the staff.
The bot will not recover a server deleted by its owner, and will not undo actions taken beyond its reach — by another integration with administrator permissions, for instance.
Commands
The commands used in this guide
Read on
Related guides
How do you protect a Discord server from a raid?
How to protect a Discord server from a raid: entry verification, AntiRaid thresholds, content protection and logs. Concrete settings, a test and the usual mistakes.
Read the guideHow do you set up verification on Discord?
How to set up verification on Discord: the entry channel, the access role, the verification type, a minimum account age and a test on a second account.
Read the guideHow do you check Discord moderation logs?
How to check Discord moderation logs: the audit log, the bot's log categories, the penalty channel, the access role and data retention.
Read the guide
FAQ
FAQ – common questions
Does a small server need an attack plan too?+
Yes, and more than a large one. A small team has fewer people to react and more often works alone, so preparation and automation matter more than on a server with a large moderation team.
How often should you back the server up?+
Before every larger change to the structure and before campaigns that bring in a lot of new people. Beyond that, a monthly rhythm is enough — configuration changes less often than it seems.
What should you do in the first minute of an attack?+
Stop the inflow: turn on slowmode or a lockdown, announce in the staff channel that an incident is under way, and only then clean up. Clearing channels before securing the evidence is the most common mistake.
Will emergency mode lock the server down by itself?+
No. Venom Shield is manual-first — it prepares containment and recovery, but execution requires an administrator's approval. An automatic lockdown on crossing the thresholds is enabled separately on the Raid protection screen.
Set this up in your own Venon Security panel
Every screen mentioned in the guide is in the web panel. You save the configuration by hand and see its state before anything takes effect on the server.
