Campaigns and incidents
A campaign is network-wide correlation between qualified indicators. Its status can be:- First seen — qualified activity has started.
- Spreading — recent activity is reaching more participating servers.
- Contained — the campaign no longer needs an active response.
- Dormant — no longer recently active.
- Indicator type, without the raw shared indicator
- Severity and status
- Number of local matches
- Distinct affected accounts and channels
- Recent local event timeline
- Notification and retro-hunt status
A campaign can be active without creating an incident for your server. Your
dashboard shows an incident only when tenant-isolated local events match.
Automatic incident handling
When a confirmed network indicator matches recent local history, Thea can:- Create or update the local incident.
- Alert the configured AutoMod log channel.
- Start a bounded retro-hunt for eligible messages that were previously logged.
- Activate temporary hardening if you enabled it.
Moderator playbooks
Open an Open or Investigating incident to see its actions.Contain now
Contain now starts a background response job. It can:- Delete up to 50 linked, still-actionable messages.
- Apply a one-hour timeout to up to 10 affected members.
- Treat an already-deleted message or a member who already left as resolved.
Warn exposed channels
Warn exposed channels posts a security notice to up to five distinct affected channels. The notice tells members who opened a link or downloaded a file to change the affected password, enable multi-factor authentication, and review active sessions. The action deduplicates channels. Running it again can post a new notice, so use it only when another reminder is needed.Resolve contained
Use Resolve contained when the required response has already happened or no further playbook action is needed. This changes incident state; it does not delete messages or time out members by itself. Thea will not resolve an incident while one of its playbooks is running. Pending work is cancelled after the incident is resolved so a worker cannot act on stale state.False positive
Use False positive only when the underlying detection was wrong. This resolution:- Dismisses the local incident.
- Marks its linked network evidence as approved and cancels remaining retro-hunt or playbook work for that incident.
- Labels eligible shadow-learning features as negative.
- Recomputes the shared verdict so independent human corrections can suppress or retract it.
Failed and partial actions
Response jobs record how many messages were deleted, members were timed out, and notices were posted.- Temporary Discord or rate-limit failures are retried.
- Missing permissions or invalid Discord targets stop unsafe repeated attempts; the incident stays open instead of reporting success.
- A resolved or no-longer-actionable incident cancels pending work.
- Two workers cannot claim the same job at once.
Review safety
Human review always takes priority over queued automation:- Approve means the finding was a false positive; Uphold confirms the detection.
- An approved finding is excluded from new retro-hunt and response targets.
- The worker reauthorizes the event immediately before every delete, timeout, or notice.
- Network consumption must still be enabled when network-owned background work is claimed.
- A false-positive correction contributes only through the privacy-preserving verdict process.