Raid protection

Vidar watches join patterns and flags coordinated raids — with a hard floor so a handful of organic joins never trips it.

The minimum-joins floor

The single most important setting is minimum joins. No matter how anomalous activity looks, Vidar will never declare a raid until at least this many accounts have joined inside the window. This is what keeps small, normal join waves from triggering alerts. Set it to comfortably above your busiest legitimate minute.

What it measures

Above the floor, Vidar scores the window on:

  • Velocity — joins in the window versus your configured baseline.
  • Fresh-account clustering — the share of joiners with brand-new accounts.
  • Shared networks / devices — many joins from one network block or device fingerprint (a strong bot indicator).
  • Username patterns — many joiners sharing a common username base.

Settings

  • Window length — the rolling period joins are counted over (default 120s).
  • Minimum joins — the floor described above (default 8).
  • Baseline joins per window — your server's normal rate, for velocity.
  • Trigger score — the raid score at/above which lockdown is recommended.
  • Fresh-account age — how new an account must be to count as “fresh”.

What happens on a raid

Vidar logs the event (visible in the dashboard's Raid events tab) and posts an alert to your moderator log channel with the score and contributing signals. Alerts are throttled to at most one per window so a raid doesn't spam the channel.

Automated lockdown

With Auto-lockdown enabled (default), a confirmed raid triggers protective action automatically:

  • The server's verification level is raised to Highest.
  • New joiners are handled per your Lockdown action: Hold keeps them pending review, or Remove brand-new accounts kicks accounts younger than your fresh-account age as they arrive.
  • Lockdown auto-lifts after the configured duration and the verification level is restored.

Moderators can engage or lift lockdown at any time with /lockdown state:on or /lockdown state:off.