Anyone can help! Whenever you spot a page that has been vandalised, you are encouraged to edit it and clean it up, and/or warn the vandal using an appropriate warning template. See What to do if you spot vandalism below.
If you find yourself cleaning up vandalism frequently, you might be interested in patrolling recent changes. Note that participation is entirely voluntary. Also, you are not required to enlist anywhere.
There are various tools to help you. See the Tools section below.
1. Revert the vandalism by viewing the page's history and selecting the most recent version of the page prior to the vandalism. Use an edit summary such as 'rvv' or 'reverted vandalism' and click on the button "Publish changes".
See also the section below for tools to help with reverting.
2. Warn the vandal. Access the vandal's talk page and warn them using an appropriate template.
See this overview of the most commonly used warning templates and this table for a wider selection of warning templates.
3. Report vandals who continue to vandalise after having received a final warning. Most cases of vandalism should be reported to WP:AIV. Cases that are not simple vandalism can be reported to WP:AN/I. WP:LTA may be used for reporting particular vandals who persistently return (e.g. via sockpuppets).
Civility is one of the pillars of Wikipedia. Avoid being rude, no matter how aggressive or obnoxious the vandal is. Some of them may want you to become angry and lose your temper: Don't fall for that!
Don't bite the newcomers. Not all bad edits are necessarily intentional vandalism. Some of them may just be test edits by newer editors.
On many ISPs, IP addresses are shared by many users, so be extra-careful not to be rude in your messages, as people seeing them may not be the same ones who vandalised.
Content disputes are not vandalism: If a user is adding biased content or you disagree with the information added, that doesn't mean the editor is vandalising. This includes violations of Wikipedia's Neutral Point of View policy. Corollary: 3RR rule still applies since it's not blatant vandalism. Instead of constantly reverting, discuss edits on talk pages and obtain community consensus. See resolving disputes.
The old school way is to load recent changes and check the (diff) links. It can be filtered according to featured articles, good articles, living people, new editors' contribs, IPs' contribs and mobile contribs (as these are more prone to vandalism, see Help:Recent changes). Searching for articles by their namespace and specific tags (e.g. VisualEditor, possible BLP issue or vandalism, etc) can also be done. If they contain harmful edits, you revert to the previous version. However, the high volume of edits that occur each second makes this difficult to accomplish most of the time, and several tools have been created to simplify the process:
Vandal Fighter, the original anti-vandalism program, is a Java program that displays the Recent Changes feed from Wikipedia's IRC bots and allows filters to focus on certain types of changes (e.g. unregistered users). It also maintains a personal list of trusted users, watched articles, etc.
Lupin's Anti-Vandal Tool monitors the RSS feed and flags edits with common vandalism terms. It also has a live spellcheck feature. This tool works in monobook skin only.
WikiMonitor is a Windows program that enables users to monitor recent changes, their watchlist, users' contributions, and other feeds in real time as well as providing multiple tools to aid in semi-automated editing and reversion. It is compatible with all Wikimedia wikis.
WikiGuard is a Mac OS X program that monitors the IRC feed and attempts to approximate each edit's risk.
RC birds is a Java program that emits different bird sounds for the RC feed depending on the user.
The IRC Bot, pgkbot, by Pgk, runs on the IRC channels below.
IRC Bots reporting at the #cvn-wp-enconnect channel on the freenode network list suspected vandalism edits (for example: blankings, edits made by blacklisted users, etc.) (Use this link to open the IRC channel on a web browser.)
WikiAlerter, a Windows program for patrolling new pages, and deleting/tagging them. Designed primarily for CSD, but supports AfD and ProD. Currently in beta, but there is a release.
Huggle is a fast diff browser which parses edits from users and sort them by predicted level of vandalism. Once identified, malicious edits can be reverted in the click of a button. Due to the fast-paced nature of the program, users on the English Wikipedia must have the rollback permission to use it; however, this is not a requirement on other wikis.
WatchlistBot is an XMPP bot that sends messages in realtime when articles are modified. Users with a Jabber account can subscribe to the bot and watch both articles and users.
WikipediaVision is a web-based world map visualization of unregistered edits to the English (and the German, French, Spanish, Swedish) Wikipedia, almost the same time as they happen.
STiki is a Java program that consists of (1) a server-side component that listens to the RC feed and scores edits in a machine-learning fashion (using 12+ features, many of which are not language-based) -- and (2) A client-side Java GUI application that presents likely vandalism found on the server-side to human users for inspection/reversion. Using STiki without rollback requires either approval from the developer or 1000 article-space edits. It can revert WP:AGF edits while leaving a friendly message on the talkpage of the editing user.
RCMap - Geolocates anonymous edits from the IRC live feed and displays them on a world map, with links to diffs. Supports multiple languages in a unified interface.
WikiPatroller is an Android app for monitoring the recent changes feed.
Snuggle is a browser-based newcomer observation and support system, introduced in 2013. It gives a compact visual display of edits and talk page entries for accounts whose first edit was made within the past 30 days. It can be used equally to welcome well-intentioned new editors or to monitor problematic ones.
These tools extend the rollback feature by allowing you to specify a summary when using rollback. They may also offer additional features:
Navigation popups are a set of utilities that appear when hovering over wikilinks. Particularly, hovering over links of old versions provides a "revert" link.
Twinkle gives both non-administrators and administrators three types of rollback functions. Other functions include a full library of speedy deletion functions, user warnings, pseudo-automatic reporting of vandals, and more.
Template:Vandalism information, a tool used as an indication of the current overall level of vandalism that is taking place on Wikipedia. On the page, click the edit button below the vandalism meter to change its level from 5 to 1 and/or add a short comment; 5 indicates very low levels of vandalism, and 1 indicates extremely high. You can add the vandalism information template to your userpage to stay up to date. See Template talk:Vandalism information for different styles.