Explore Cases Government Threat Prevention

Threat Prevention

Protectee Threat Escalation: The Fixated Letter Writer

The newest letter is angry, but the real question lives across years of correspondence. Has the language changed? Has a grievance become more specific? Has online fixation turned into physical proximity? Protective intelligence depends on seeing whether separate communications and behaviors form an escalating pattern.

Capabilities

Behavioral Analysis Document & Media Forensics Entity Resolution Evidence & Case Packaging Geospatial Mapping Open Source & Social Media Predictive Modeling Timeline Reconstruction

Overview

A single threatening or fixated communication rarely answers the question protective teams care about most: whether a subject’s behavior is changing in a way that raises concern. That assessment depends on longitudinal evidence—language, frequency, identity across platforms, stated intent, approach behavior and proximity to relevant venues.

CoAnalyst360 organizes that history as one body of evidence for human review. New communications can be compared with earlier material, accounts can be assessed for common identity, and behavior can be structured against an established threat-assessment framework. Location signals can be compared with public event information where appropriate, giving human reviewers a clearer timeline for assessment and mitigation planning.

Protective Intelligence Board
Protective Intelligence Board — Escalation Timeline
Protective Intelligence Board — Language Risk
Protective Intelligence Board — Convergence Map
Protective Intelligence Board — Mitigation Status

Key features

  • Corpus comparison and stylometry Compare each new communication against the full prior corpus for authorship indicators, and track how language, tone and specificity shift over months — instead of reading each item in isolation.
  • Cross-platform identity resolution Pivot on handle reuse and recovery-address overlap to assemble one subject file rather than several unlinked accounts, with the linking evidence shown for each.
  • Structured behavioral assessment Structure observed behavior against an established pathway-to-violence framework over a rolling window, so escalation is measured and defensible rather than sensed — with the evidence behind every factor visible to the reviewer.
  • Movement and venue overlap Test lawfully available location signals from the subject's own activity against the protectee's published schedule, surfacing venue probing that separate systems would never connect.
  • Escalation timeline Assemble communications, account activity and location evidence into one timeline that shows trajectory rather than a list of incidents.
  • Referral and mitigation tracking Compile the threat-management referral with lawful intervention options and venue security gaps, and track mitigation status through to the event.

See CoAnalyst360 on your own data

Bring your existing data sources into a coordinated investigative workflow. See how CoAnalyst360 can help your team move from a question to evidence-backed findings faster.

Request a demo

Illustrative scenario. The incidents, investigations, individuals, organizations, communications, identifiers, and investigative findings depicted here are fictional and created for demonstration purposes. Real-world locations, geographic features, public infrastructure, and other contextual references may be used to make the scenario realistic. Their inclusion does not indicate that the events shown actually occurred or that any real person or organization was involved.