ohShield
ohShield Discord Bot
# ohShield — Discord Security That Just Works
Add the bot. It's protected. Global Rules (impersonation, scam links, mention abuse, fake jobs) are active the second ohShield joins — zero configuration.
## Why It's Different
### Impersonation detection that actually works — Scans username, global name, and nickname against homoglyph patterns (Cyrillic/Greek lookalikes) on every join and every name change. Targets fake users copying popular bot names (MEE6/MEE9) or "Announcement" — the exact vectors attackers use. Runs on raw gateway events, so it catches them even when Discord's cache is empty. No other bot does this.
### Scam links caught at the source — 50+ obfuscation patterns + hourly-updated threat intelligence feed + automatic shortener resolution (t.co, bit.ly, etc. followed to final domain). Phishing links hidden in markdown, spaced out, or encoded — caught.
### Image scanning for the #1 scam pattern — Detects 4+ images in a single message with no text — the classic phishing/seed-phrase dump. Threshold modes: exact / greater / greater-or-equal. Excluded roles bypass cleanly. Originals stored to operator channel with automated retention. Composites thumbnails into a filmstrip for alerts.
### Verification that stops alts — Three modes: Emoji, Math Captcha, or 2048 Game (web-based, one-time link, Discord can't pre-fetch). The game is a stress-free but powerful antibot measure. Attempt limiting with escalating lockouts. Auto-kick unverified after X hours.
### Scam reports: one command, fully automated — !scam (reply to message). Role-gated. Rate-limited. No dedicated alert channel needed — the reporter's permissions drive instant actions (delete/timeout/ban/kick). Moderators decide with a single click on the alert buttons (Ban, Timeout, Kick, Ignore). Evidence thread auto-created. Telegram + owner alerts for confirmed bans.
### Setup in 2 Minutes
/start → 9-step wizard walks you through:
1/ Private channels created
2/ Bot connectivity confirmed
3/ Every channel's permissions audited — fix buttons per category
4/ Role hierarchy checked
5/ Scam report roles configured
6/ Recurring security reminders enabled
7/ Moderator visibility set
8/ Moderator capabilities assigned
9/ Done — hub for verification & advanced roles
Progress bar, overview jump, back/next, restart anytime.
### Battle-Tested at Scale
- Months of real tests against 100k+ members server with organic activity
- ReDoS-safe patterns — every regex stress-tested in isolated worker thread before acceptance
- Backtest gate — new rules rejected if they match any known-good message
### Telegram Alerts Without the Hassle
No webhook, no public HTTPS. Long-polls Telegram. Pair via button → deep link → /start <code> in PM or group. Multiple chats per server. Gets every security action instantly.
## The Philosophy
Safe by default. Global Rules on. Penalties configurable per category (timeout/kick/ban/alert-only). Duration overridable per guild.
Chill moderation. Every user is part of the system. Verification makes them human. Scam reports make them defenders. Global Rules protect them silently. The bot doesn't sit on top of your community — it's woven into it.
/start and you're done.
Reviews
No reviews yet.