Most server spam comes from hijacked members, not throwaways. Aegis learns each member's normal behavior, spots the takeover the moment it happens, and contains it — without banning the victim.
Stolen tokens turn trusted members into spam cannons. Generic rate-limit bots miss it — or ban your regulars.
Aegis remembers how each member normally acts. A dormant account that suddenly link-blasts five channels deviates from its own history — flagged instantly.
Established members get quarantined — roles stripped, messages purged, recovery steps DMed. Throwaway spam accounts get banned. The right response for each.
Community blocklists, homoglyph-folding lookalike detection (dіѕсоrd-n1tro ≠ discord), and campaign lure phrases catch brand-new scam domains.
Join-rate spikes pause invites and DMs via Discord's native security actions, gate young accounts at the door, and run every detector hot.
Provisions Discord's native AutoMod rules so baseline protection holds even if the bot goes down.
A burst of destructive audit-log actions from one account is the signature of a hijacked moderator. Aegis alerts before the damage spreads.
Every message feeds a decaying per-user pressure score. Bursts of suspicious behavior cross thresholds; normal chat never does. Known phishing links skip the queue entirely.
pressure ≥ 45 → delete · ≥ 70 → quarantine · ≥ 110 → ban
every threshold tunable per server
Invite the bot, run one command, done. Every server gets its own config, thresholds, and quarantine role.