Threat Intelligence Guide
Surviving an Active Lethal Threat: What the Data Actually Says
Most response frameworks begin after the first human recognizes danger. This guide focuses on the overlooked window before escalation, when seconds of detection can become minutes of lead time.
The Problem With Every Response Framework
Every Protocol You Know Starts Too Late
Run-Hide-Fight, ALICE, Avoid-Deny-Defend, and NFPA 3000 are essential response frameworks, but they share one structural limitation: each depends on a person recognizing the threat first.
That recognition gap is not theoretical. A person has to notice the danger, interpret it correctly, overcome denial, find a phone, communicate location, and wait for dispatch. In a fast-moving event, those early minutes are the difference between passive recording and proactive response.
IntelliSee does not replace training, law enforcement, emergency planning, or command structure. It adds the missing first layer: autonomous visual detection across existing cameras before a human is forced to become the sensor.
The Response Time Gap
Two Timelines. One Outcome Difference.
The traditional timeline waits for recognition. A proactive safety timeline begins when the camera network sees the risk.
Without AI Detection
- T+0:00 Weapon Drawn A person enters or approaches with a visible weapon. No automated system interprets the scene.
- T+0:30 First Shots Fired The event begins before occupants have specific warning or confirmed location intelligence.
- T+2:00 Human Recognition Witnesses work through confusion, denial, noise, distance, and incomplete information.
- T+3:30 911 Call Placed A caller locates a phone, dials, explains the situation, and tries to communicate location.
- T+5:00 Dispatch Confirmed Officers are dispatched, but the facility is still operating from incomplete situational awareness.
- T+8-15 Law Enforcement Arrives Police arrive after the most compressed and dangerous phase has often already passed.
Result: Response begins after recognition. Traditional surveillance records evidence. It does not create lead time.
With IntelliSee
- T-2:00 Behavioral Context Loitering, perimeter movement, or unusual crowd patterns can flag areas that deserve attention.
- T+0:01 Weapon Detected Computer vision identifies a drawn firearm and generates an alert in real time.
- T+0:03 Notification Workflow Starts Security, administrators, and connected notification systems can receive location-specific context.
- T+0:05 Emergency Response Begins The organization can act from a verified visual event instead of waiting for human confirmation.
- T+0:30 Facility Actions Underway Lockdown, shelter, evacuation, or access decisions can begin with better threat location awareness.
- T+5-8 Responders Receive Context The visual timeline helps responders understand location, movement, and escalation pattern.
Result: Response starts with detection. The camera network becomes an active sensor layer, not just a forensic record.
Response Frameworks Analyzed
Every Protocol Shares the Same Blind Spot
The leading frameworks teach people what to do. They rarely define how the facility detects the threat before people are forced to decide.
Run-Hide-Fight
DHS / City of Houston response model
- Clear civilian response options
- Evacuate when a safe path exists
- Shelter when escape is unsafe
- Confront only as a last resort
It depends on knowing where the threat is and whether escape is safe.
ALICE
Alert, Lockdown, Inform, Counter, Evacuate
- Options-based response model
- Emphasizes information sharing
- Designed for dynamic decision-making
- Used across education and enterprise
The alert layer still requires fast, reliable threat recognition.
Avoid-Deny-Defend
ALERRT / Texas State University
- CISA-endorsed training model
- Uses inclusive civilian language
- Supports law enforcement alignment
- Focuses on practical options
Avoidance depends on situational awareness, not a generic exit route.
NFPA 3000
Active shooter / hostile event response standard
- Preparedness-response-recovery standard
- Promotes unified command
- Addresses rescue task force protocols
- Requires after-action review
The standard supports preparedness, but facilities still need the detection layer.
IntelliSee strengthens these frameworks by feeding them earlier, location-specific visual intelligence from cameras already in place.
AI Detection In Action
What IntelliSee Sees Before the First Shot
Detection is not a single event. It is a chain of visual signals that can start outside the building and continue through response and recovery.

Drawn Firearm Identified
A visual firearm event can trigger alert workflows before response depends on witness recognition.

Risk Seen Before Entry
Parking areas, entrances, and perimeter zones can become the first layer of warning.

Loitering Near Restricted Areas
Pre-incident behavior can be surfaced to security teams before escalation.

Unusual Gathering Detected
Anomalous congregation can indicate confusion, escalation, or blocked movement.

Injured Person Located
Fall detection can help responders locate people who need attention after the scene is secured.

Camera Gaps Become Visible
A risk assessment shows where the first detection failure would occur today.
The Three Phases
Before. During. After.
Survival planning is not a single drill. It is a layered operating model that changes what the facility can know and do at each phase.
01Before the Threat
Prevention Starts Weeks, Sometimes Months, Before an Attack
FBI research on active shooter incidents has found that perpetrators often display observable concerning behaviors before violence. The threat rarely appears from nowhere; it often moves through stages that people, processes, and cameras can miss.
Preparation combines behavioral threat assessment, facility hardening, emergency planning, and AI-powered detection into one layered system.
- 1 Conduct a formal risk assessment Map entries, camera blind spots, high-occupancy zones, and notification paths.
- 2 Build a threat management team Use a multi-disciplinary group to triage concerning behavior before escalation.
- 3 Deploy behavioral analytics Loitering detection and perimeter monitoring help surface pre-incident patterns.
- 4 Test the emergency action plan Drills should include communication trees, lockdown zones, and notification workflows.

02During the Incident
Situational Awareness Decides Whether the Right Protocol Is Possible
Run-Hide-Fight breaks down when occupants do not know where the threat is. The safest action depends on location, movement, exits, and timing.
AI detection provides real-time threat context so teams can respond to a specific event rather than a generic instruction.
- 1 Use the specific alert Response choices should be based on where the threat is, not just where the nearest exit is.
- 2 Evacuate when path is clear Move away from the threat path rather than toward a default exit.
- 3 Shelter when movement is unsafe Lock, barricade, silence phones, and remain away from doors and windows.
- 4 Act on verified automation When detection and notification systems trigger, delay becomes part of the risk.

03Aftermath
The Aftermath Begins the Moment the Incident Ends
Law enforcement arrival does not end the operational burden. Facilities still face medical triage, reunification, evidence preservation, trauma support, and after-action review.
AI detection logs can help reconstruct the event timeline and identify locations that may need immediate attention.
- 1 Wait for official all-clear Secondary risks and confusion can extend the dangerous window.
- 2 Locate injured persons Fall detection can help surface locations where people may need help.
- 3 Preserve event records Detection logs and video records support investigation and operational learning.
- 4 Run a 72-hour review NFPA 3000 emphasizes after-action review; AI timelines make that review more concrete.

The Fundamental Shift
Reactive Security vs. Proactive Safety
Reactive Security
Traditional surveillance records what happened. It cannot prevent recognition delay.
- Cameras record events but cannot interpret them autonomously.
- Human monitoring is vulnerable to attention fatigue and missed frames.
- Response begins after someone recognizes and reports the threat.
- Video evidence is usually used after the fact.
- Pre-incident behavior can disappear inside normal camera volume.
Proactive Safety – IntelliSee
AI detection turns existing cameras into an active safety intelligence layer.
- Weapon detection can trigger alerts before shots are fired.
- Autonomous monitoring works across the full connected camera network.
- Notification workflows can begin from verified visual evidence.
- Behavioral analytics add context before escalation.
- No facial recognition and no camera replacement.
Intelligence Brief
Privacy by Design: Detection Without Knowing Who Someone Is
The question behind AI security is not only whether the technology works. It is whether it can improve safety without turning every facility into a biometric surveillance environment.
IntelliSee operates without facial recognition. It analyzes objects, behaviors, motion, and visual conditions: a drawn firearm, loitering near restricted areas, unauthorized access, unusual crowd patterns, falls, smoke, fire, or other safety events.
That distinction matters for schools, healthcare, houses of worship, government facilities, and other environments where identity-based surveillance may be prohibited or unacceptable. The system does not need to know who someone is to detect what is happening.
DHS SAFETY Act QATT Designation Qualified Anti-Terrorism Technology designation awarded November 2025.
Industry Applications
Active Lethal Threats Occur Everywhere. The Detection Gap Changes by Sector.
Each environment has a different risk profile, but every facility depends on the same first question: how quickly can you know what is happening?
K-12 Education
Schools need early warning across entrances, parking areas, hallways, and gathering spaces, with workflows that support lockdown and reunification planning.
Healthcare
Hospitals face open access, emotional volatility, high traffic, and patient care constraints that make fast location awareness essential.
Corporate & Enterprise
Workplace violence planning depends on integrating camera intelligence with access control, reception, HR, and emergency action plans.
Houses of Worship
Open-door environments often operate with limited security staff, making automated camera intelligence a critical force multiplier.
Common Questions
Frequently Asked Questions
Clear answers for security leaders evaluating active threat planning and AI detection.
What is an active lethal threat?
An active lethal threat is an ongoing event in which someone is actively attempting to kill or seriously harm people in a populated environment. The situation is dynamic, meaning location and timing change the correct response.
Why do response frameworks need detection technology?
Frameworks tell people what to do once they know danger exists. Detection technology helps answer the earlier question: how does the facility know a threat is present before recognition depends on witnesses?
Can IntelliSee detect threats without facial recognition?
Yes. IntelliSee detects visual events such as weapons, loitering, unauthorized access, crowd anomalies, falls, smoke, and fire without identifying who a person is.
Does this require replacing existing cameras?
No camera replacement is required in typical deployments. IntelliSee layers AI detection onto compatible existing surveillance infrastructure.
What should a facility do first?
Start with a risk assessment. Map entry points, camera coverage, blind spots, notification workflows, lockdown areas, and where human recognition is currently the first point of failure.
Take the Next Step
Your Cameras Are Already Watching. Make Them Think.
IntelliSee layers proactive safety intelligence onto compatible existing camera infrastructure. A risk assessment shows where your detection gaps are and what it would take to close them.