# Counterterrorism **Entity class:** Security mission and practice domain **Domain:** National security / intelligence / law enforcement / military operations **Maturity:** Developed ## Definition **Counterterrorism** comprises the lawful activities used to prevent, detect, disrupt, investigate, and respond to terrorist violence and the networks that enable it. It spans intelligence collection and analysis, financial investigation, border and transportation security, law enforcement, diplomacy, protective security, military operations, and consequence management. ## The Army Intelligence Scale Most People Miss The public picture of American counterterrorism often begins with CIA, FBI, or DHS. That picture omits one of its largest operational intelligence formations: the [[wiki/Army Intelligence and Security Enterprise|Army Intelligence and Security Enterprise]]. The Army describes its largest command, [[wiki/Army Intelligence and Security Command|INSCOM]], as an 18,500-person global force of soldiers, civilians, and contractors at approximately 180 locations in 45 countries. The Army Reserve's [[wiki/Military Intelligence Readiness Command|Military Intelligence Readiness Command]] adds more than 7,300 soldiers in more than 40 units across the continental United States, Hawaii and Europe. Across the larger Army, intelligence personnel also sit in tactical formations, theater commands, cyber units, the National Guard and Reserve, training institutions, headquarters staffs, and installations distributed across the United States. These published figures describe intersecting parts of an enterprise rather than additive headcounts, but they make the scale and domestic distribution impossible to dismiss. This scale makes Army intelligence a major—plausibly the largest by personnel among the military-service intelligence enterprises—part of the U.S. intelligence architecture, although public workforce categories do not support a clean, current, apples-to-apples ranking. Its counterterrorism workload includes foreign networks, force protection, counterintelligence, battlefield and theater intelligence, cyber operations, biometrics, identity intelligence, aerial ISR, weapons and ground-force analysis, partner support, and intelligence delivered to national law-enforcement agencies. ## Domestic Authority Is Not the Same as Domestic Infrastructure Saying that the Army is not the general civilian police does **not** mean that Army intelligence infrastructure is absent from domestic counterterrorism. Army and DoD bases, networks, cloud and communications systems, cyber forces, counterintelligence field offices, watch centers, laboratories, training ranges, reachback sites, biometric and identity capabilities, aerial and terrestrial sensors, analysts, and National Guard formations are physically and computationally present across the United States. They protect military people, installations, weapons, research, logistics, and critical systems; process foreign and national intelligence; defend networks; and provide authorized support to FBI, DHS, Treasury, NCTC, combatant commands, state authorities, and other partners. This distinction is decisive in [[wiki/Cyberterrorism|cyberterrorism]]. A cyber operation may be domestic in effect while its actor, infrastructure, routing, finance, malware, or command system is transnational. The operational contest occurs across infrastructure—endpoints, identity systems, telecommunications, cloud services, payment systems, operational technology, and critical infrastructure—before any arrest. In that environment, the military-intelligence and cyber layer can be central even when a civilian agency owns the domestic investigation or prosecution. **Authority determines who may take which action; infrastructure determines what can be seen, defended, attributed, shared, and disrupted.** The Army layer can therefore be understood as **plumbing**. Maintaining, securing and instrumenting the pipes does not require every operator to read the water flowing through them. Routing, access control, integrity monitoring, endpoint telemetry, anomaly detection, encryption, logging and incident response are infrastructure functions. They can expose the existence and shape of a malicious flow without making every maintainer the investigator of its content. In cyber counterterrorism, those pipes are often the battlefield. The June 2026 opening of INSCOM's [[wiki/Intelligence Consolidated Mission Facility|Intelligence Consolidated Mission Facility]] at [[wiki/Fort Huachuca|Fort Huachuca]] is a physical example. The Army consolidated dispersed intelligence elements into a secure 24/7 hub with expanded SCI workspace. That project did not create general police authority; it increased the capacity to fuse, protect, and deliver intelligence for Army, joint and coalition commands **and the Intelligence Community**. [[wiki/Five Eyes|Five Eyes]] adds an international routing layer. Partner collection and intelligence exchange can make an event visible through another jurisdiction or collection position. Critics call some forms of this “data laundering” when foreign collection or sharing appears to circumvent a domestic restriction. The alliance itself does not prove circumvention; that stronger claim requires tasking, legal, handling and dissemination records showing that the partner route was used for that purpose. Members of the armed forces swear to support and defend the Constitution against enemies “foreign and domestic.” That oath states the constitutional duty of service. It does not by itself create surveillance, search, arrest, or deployment authority for a specific domestic operation. Those actions still require the applicable Constitution, statutes, executive authorities, command status, and interagency arrangements. [[wiki/Military Support to Civilian Counterterrorism|Military Support to Civilian Counterterrorism]] records the operational pathways without erasing that legal architecture. Bryant McGill's stated position in this research integration is maximalist: when a genuine terrorist threat is established, prevention takes priority over a romantic or technologically obsolete expectation of privacy. The constitutional question remains operational rather than decorative: which authority, threshold, review mechanism and remedy govern the system that acts on the data? ## Oklahoma City: Civilian Lead, Military Response Envelope The [[wiki/Oklahoma City Bombing|Oklahoma City bombing]] demonstrates why “domestic terrorism” cannot be read as “local-police-only.” The FBI led the OKBOMB criminal investigation and established a federal command center on the day of the attack. ATF—then a Treasury bureau—supplied explosives expertise. FEMA coordinated consequence-management assistance. At the same time, the Department of Defense designated a defense coordinating officer; Army Reserve personnel staffed the disaster field office and established command and supply facilities; Army Corps of Engineers structural specialists protected rescuers and the evidence site; and at least 731 Oklahoma Army and Air National Guard members supported search, medical readiness, security, logistics, aerial reconnaissance, evidence-site operations, and movement of the arrested suspect. That was not a substitution of the Army for the FBI or for Oklahoma authorities. It was a **military response envelope around a civilian-led investigation**. A catastrophic attack on a federal facility instantly creates requirements for bomb and weapons expertise, structural engineering, secure communications, aviation, medical evacuation, logistics, force protection, intelligence, evidence preservation, and continuity of government. Local police remain indispensable at the scene, but no serious national response assumes that a municipal department alone contains that entire capability stack. The same division explains current cyber counterterrorism. Civilian agencies may own the domestic case and prosecution while military and national-intelligence infrastructure supplies warning, attribution, network defense, foreign-intelligence context, specialized collection, and operational continuity. Jurisdiction assigns the lead; it does not erase the rest of the national response system. The 1997 GAO description of the governing architecture makes the escalation rule explicit. The FBI on-scene commander built an interagency joint operations center incorporating DoD, Treasury, the Intelligence Community, technical agencies, and state and local authorities. If ordinary enforcement became unworkable and the President approved use of **military coercive force**, operational control of the incident site would pass to a military commander for the authorized operation and return to the FBI afterward. That contingency is narrower than the military role described here. **Military infrastructure does not begin when armed soldiers assume control of a site.** It is already present in computers, data centers, secure networks, sensors, communications, intelligence-fusion environments, machine-learning and analytic systems, satellite and aerial support, engineering, logistics, aviation, medical capacity, and hardened facilities. Those capabilities can be assigned, shared, queried, or placed in support of a civilian lead without a soldier performing a civilian arrest or an Army commander taking over the scene. The plumbing metaphor therefore has a scale dimension. A local agency may own the faucet through which the public sees the case, while national intelligence and military systems supply the high-capacity mains behind it. An Oklahoma City-scale attack does not remain inside a municipal garden hose: the government opens the largest authorized pipes it has. The lead-agency label identifies who controls the case and who can exercise particular powers; it does not measure the volume, origin, or technical sophistication of the infrastructure feeding the response. ### Evidence ledger - **Established:** FBI/DOJ commanded the OKBOMB criminal investigation and prosecution; ATF, then within Treasury, supplied explosives capability. - **Established:** DoD, Army Reserve, Army Corps of Engineers, and Oklahoma National Guard supplied substantial command coordination, engineering, aviation, medical, logistics, reconnaissance, security, and recovery support. - **Established:** the interagency domestic-terrorism architecture contemplated Intelligence Community and DoD infrastructure support throughout the response and a separate, conditional transfer of site control to a military commander when military coercive force was lawfully required and approved. - **Unresolved:** the reviewed public record does not establish that Army Intelligence secretly commanded or primarily drove OKBOMB. Resolving that stronger claim would require tasking orders, command logs, intelligence-support memoranda, liaison records, or declassified after-action material identifying such a role. ## Counterterrorism and Cybersecurity Are Operationally Converged In contemporary operations, **counterterrorism and [[wiki/Cybersecurity|cybersecurity]] are no longer separable mission environments**. Recruitment, propaganda, target selection, identity compromise, doxxing, finance, communications, travel, access brokerage, and attacks on critical infrastructure all pass through digital systems. Counterterrorism therefore depends on cyber threat intelligence, vulnerability management, incident response, digital forensics, identity security, platform integrity, operational-technology defense, and real-time telemetry. Cybersecurity, in turn, must account for terrorist use of digital access and cyber-physical systems. This is operational convergence, not a claim that the categories are legally identical. Most cyber incidents are crime, espionage, hacktivism, accident, or ordinary security failure rather than terrorism. A terrorist classification still requires evidence of actor, intent, target, purpose, and effect. [[wiki/Zero-Day Exploit|Zero-day exploits]] are nevertheless non-incidental: an unknown vulnerability can provide asymmetric access to communications, money, identity systems, media channels, or critical infrastructure before defenders possess a signature or patch. ### From human CVE to writable human endpoint The [[wiki/Human CVE|human CVE]] extends vulnerability analysis into the person-system configuration. A dangerous or compromised individual can be the [[wiki/Threat Actor|threat actor]], [[wiki/Attack Vector|attack vector]], and [[wiki/Vulnerability|vulnerability-bearing condition]] when access, placement, credentials, capability, intent, and network position create an executable path to harm. [[wiki/Brain-Computer Interfaces|Bidirectional neural interfaces]] add a second configuration: a person may become dangerous because the connected device, adaptive model, permissions, communications, or [[wiki/Neural Command Channel|neural command channel]] has been compromised. This is the counterterrorism relevance of [[wiki/Neurosecurity|neurosecurity]]. The person can simultaneously be a victim, a compromised biological endpoint, and a vehicle through which downstream harm becomes possible. [[wiki/Brainjacking|Brainjacking]] already names unauthorized control of implanted neuromodulation systems. The future defensive stack joins cybersecurity's continuous vulnerability machinery to biological-state assurance: [[wiki/Continuous Vulnerability Intelligence|continuous vulnerability intelligence]] → [[wiki/Human-Machine State Estimation|continuous human-machine state estimation]] → [[wiki/Predictive Exploit Detection|predictive exploit detection]] → rapid containment → trusted remediation → [[wiki/Verified Neural Restoration|verified restoration]]. This is predictive defense applied to the complete [[wiki/Cyber-Biological System|cyber-biological system]]. ## Architectural Layers The Joe Kent corpus exposes several distinct layers that should not be collapsed: - [[wiki/Joint Special Operations Command|Joint Special Operations Command]] represents a military operational layer. - [[wiki/CIA Ground Branch|CIA Ground Branch]] represents an intelligence covert-action layer in the article's terminology. - The [[wiki/National Counterterrorism Center|National Counterterrorism Center]] represents interagency integration and strategic analysis. - [[wiki/Intelligence Fusion|Intelligence fusion]] and [[wiki/All-Source Intelligence|all-source intelligence]] describe methods that support warning and decision-making. - [[wiki/Presidential Threat Assessment|Presidential threat assessment]] names the senior decision-support endpoint in the local corpus. These layers exchange information and may pursue the same threat network, but they operate under different authorities, evidentiary standards, and accountability systems. ## Regional Convergence Node and National Nervous System The [[wiki/El Paso AI-Compute and Military Modernization Corridor|El Paso–Fort Bliss corridor]] is a documented [[wiki/Regional Operational Convergence Node|regional operational convergence node]]. It combines the [[wiki/El Paso Intelligence Center|DEA-led EPIC “all threats” center]], the former [[wiki/Joint Task Force North|JTF-North]] institutional base now supporting [[wiki/Joint Interagency Task Force-Counter Cartel|JIATF-CC]], the [[wiki/204th Military Intelligence Battalion|204th MI Battalion]] and aerial ISR training, [[wiki/Joint Modernization Command|Joint Modernization Command]] and [[wiki/Project Convergence|Project Convergence]], the [[wiki/32d Army Air and Missile Defense Command|32d AAMDC]], Army aviation and maneuver forces, and two legally distinct hyperscale-compute projects. Its significance is density: collection, fusion, experimentation, command, aviation, physical training space, energy, and prospective gigawatt-class compute occupy one regional system. That regional node is not the national nervous system. The larger system is federated: - **National counterterrorism knowledge and identity:** [[wiki/National Counterterrorism Center|NCTC]] and [[wiki/Terrorist Identities Datamart Environment|TIDE]]. - **Investigation and domestic distribution:** approximately 200 [[wiki/Joint Terrorism Task Force|Joint Terrorism Task Forces]] and the [[wiki/National Network of Fusion Centers|National Network of Fusion Centers]]. - **Defense sensor-data-command architecture:** [[wiki/CJADC2|CJADC2]], with the [[wiki/Department of Defense Information Network|DoDIN]] and [[wiki/Joint Warfighting Cloud Capability|JWCC]] providing networks, cloud, classification-level services, and edge compute; [[wiki/Open DAGIR|Open DAGIR]] and the [[wiki/War Data Platform|War Data Platform]] providing shared data and application integration; and [[wiki/Maven Smart System|Maven Smart System]] supplying an operational AI exploitation layer. - **Operational interagency nodes:** [[wiki/Joint Interagency Task Force South|JIATF-S]] as a mature all-resource fusion organization and [[wiki/Joint Interagency Task Force-Counter Cartel|JIATF-CC]] as the newer northern counter-cartel organization. [[wiki/CJADC2|CJADC2]] is the closest defensible referent for a DoD-wide “digital nervous system,” but it is not a master node or single computer. It is the connective architecture. The actual computational substrate resides in DoDIN transport and services, JWCC cloud and edge capacity, Open DAGIR's interoperable data/application ecosystem, the War Data Platform's shared data foundation, and mission systems such as Maven. Above that technical stack is authority—the President, Secretary of Defense, Joint Staff, and combatant commands—not another hidden supercomputer. ## Financial and Relationship-Analysis Layers Counterterrorism is also a problem of resources and networks. Terrorist actors require money or value for travel, housing, communications, recruitment, propaganda, procurement, logistics, and operations. The resulting architecture extends beyond signals intelligence: - [[wiki/United States Department of the Treasury|Treasury]] and its [[wiki/Office of Terrorism and Financial Intelligence|Office of Terrorism and Financial Intelligence]] supply financial intelligence, anti-money-laundering and counter-terrorist-financing policy, sanctions, information sharing, and asset-denial tools. - [[wiki/Financial Crimes Enforcement Network|FinCEN]] administers the [[wiki/Bank Secrecy Act|Bank Secrecy Act]] reporting environment and mechanisms through which authorized agencies can locate or analyze relevant accounts and transactions. - [[wiki/Homeland Security Investigations|Homeland Security Investigations]] applies customs, trade, immigration, export, money-laundering, smuggling, and transnational-crime authorities to terrorist facilitators and support networks. - The [[wiki/United States Secret Service|Secret Service]] investigates currency, payment-system, access-device, financial-institution, money-laundering, and cyber-enabled financial crimes. It now reports through DHS but remains operationally connected to Treasury capabilities, especially FinCEN and forfeiture, through its financial mission. - [[wiki/Identity and Relationship Analysis|Identity and Relationship Analysis]] connects names, aliases, addresses, phones, vehicles, accounts, transactions, organizations, and events. Historical [[wiki/ICEPIC|ICEPIC]] is a concrete DHS example. The underlying records are distributed. Banks, card issuers, merchants, processors, payment networks, and government systems hold different parts of the graph. [[wiki/Financial Transaction Data|A card swipe can become a time-and-place observation]] inside an authorized investigation without implying that every transaction is centrally copied to Treasury or that ordinary commerce is evidence of terrorism. ## Epidemiological and Contact-Tracing Comparison [[wiki/Contact Tracing|Contact tracing]] and counterterrorism network analysis share a search grammar: begin with a verified case or event, reconstruct backward sources and forward contacts, identify bridges and clusters, and choose intervention points. [[wiki/Memetic Contagion and Violent Extremism|Research on violent extremism]] also examines how narratives, recruiters, peer groups, online subcultures, and copycat scripts can transmit or intensify. This comparison is methodological. Biological exposure, ideological contact, organizational membership, material support, and violent action are different states. NIJ's research synthesis finds that social networks can facilitate or prevent radicalization and that no single universal pathway explains movement to terrorism. The strongest formal formulation is **radicalization as a multilayer, temporal-network [[wiki/Complex Contagion|complex contagion]] with a [[wiki/Memetic Theory|memetic]] payload**. The payload may combine grievance, identity, sacred values, and a reusable script or “template method.” [[wiki/SIR Model|SIR]] and [[wiki/SEIR Model|SEIR]] models expose state-transition assumptions; [[wiki/Hawkes Process|Hawkes processes]] test self-excitation after salient incidents; [[wiki/Agent-Based Model|agent-based]] and threshold models represent heterogeneous people and reinforcement. None converts analogy into diagnosis. [[wiki/Contact Tracing|Contact tracing]] supplies a useful observational grammar: backward tracing asks who influenced the index subject; forward tracing asks whom that subject may have influenced; recursive tracing follows additional generations; cluster investigation maps cells and communities; source attribution reconstructs narrative or organizational lineage. In operational tradecraft these functions appear as [[wiki/Association Matrix|association matrices]], [[wiki/Link Analysis|link analysis]], [[wiki/Social Network Analysis|social network analysis]], [[wiki/Identity Intelligence|Identity Intelligence]], [[wiki/Pattern-of-Life Analysis|pattern-of-life analysis]], and graph-based identity systems such as [[wiki/Terrorist Identities Datamart Environment|TIDE]]. ## Prevention, Intervention, and Exit [[wiki/Countering Violent Extremism|CVE]] and [[wiki/Preventing Violent Extremism|PVE]] form the public-health-style program layer. Primary prevention addresses population protective factors and narrative resilience; secondary prevention targets persons or clusters assessed as exposed or susceptible; tertiary prevention includes rehabilitation, [[wiki/Disengagement|behavioral disengagement]], and [[wiki/Deradicalization|cognitive or attitudinal change]]. The United Kingdom's [[wiki/Prevent Strategy|Prevent]] program is a statutory national implementation. These interventions require a defined terrorism nexus, a theory of change, measurable outcomes, and protections against profiling, viewpoint discrimination, stigma, and net-widening. ## Dangerous Individuals and Assembled Mass-Casualty Systems A [[wiki/Dangerous Individual|dangerous individual]] can be the decisive guidance, activation, or delivery component of a [[wiki/Mass-Casualty Threat System|mass-casualty threat system]] even when the physical platform is ordinary. Congressional aviation testimony after September 11 described aircraft of any size as potentially usable as a **human-guided weapon**. The system, rather than the airframe alone, carried the destructive capacity: ideology supplied an objective; people supplied cognition, target selection, navigation, and terminal guidance; aircraft supplied energy and mobility; targets supplied vulnerability; and the coupled configuration produced mass destruction. This is why the FBI's contemporary homeland-threat description emphasizes lone actors and small cells who radicalize to violence and use easily accessible weapons against soft targets. Catastrophic terrorist capacity need not begin with an exotic weapons platform. Ordinary vehicles, tools, accounts, facilities, or infrastructure can become effectors when joined to hostile intent, access, timing, and capability. The Secret Service/NIJ protective-intelligence framework supplies the person-scale doctrine. It defines the relevant question through motive and capacity: a person becomes dangerous to a particular target when attack is regarded as a desirable, acceptable, or potentially effective means to a goal and the person possesses or develops the capacity to act. The FBI-linked [[wiki/Threat to Life|Threat-to-Life]] architecture similarly communicates information about persons who may endanger themselves, others, facilities, infrastructure, or protected sites. The threat object is therefore dynamic: beliefs, intentions, behavior, capability, access, relationships, and target conditions interact. Public health supplies a parallel observational grammar. CDC treats violence as a population-health problem and uses surveillance, risk and protective factors, intervention design, and evaluation. This supports [[wiki/Epidemiological Modeling of Violent Extremism|epidemiological modeling of violent extremism]] and a [[wiki/Machine-Readable Public Health Sensing Grid|machine-readable public-health sensing grid]] for population phenomena. It does not transform people into pathogens or place them outside constitutional protection. The scientifically modeled organism and the legally protected person are the same human viewed through different ontologies; state action reaches the person. DTRA's counter-WMD architecture reaches the same system level from the WMD side. The agency publicly describes network analysis of critical links and nodes among **people, places, and things**, anticipatory illumination and disruption of threat networks, and advanced analytics for WMD and improvised-threat networks. The WMD problem is consequently larger than a hazardous object in storage; it includes the people and organizations that acquire, finance, understand, move, target, deliver, or use destructive capability. The synthesis is: **mass destruction is an emergent property of an assembled threat system, not necessarily an intrinsic property of one component.** The person can be the [[wiki/Cognitive Guidance System|cognitive guidance system]] and [[wiki/Threat-Bearing Node|threat-bearing node]]; ideology can be the [[wiki/Ideological Payload|motivational and informational payload]]; the social graph can be the transmission medium; accessible platforms can become physical effectors; and the attack is the system's mass-casualty behavior. ### Statutory boundary Federal biological-weapons law uses narrower defined terms. Under 18 U.S.C. §178, a **biological agent** is a microorganism, infectious substance, or component capable of specified harms. A **vector** is a living organism or molecule capable of carrying a biological agent or toxin to a host, and a vector can be part of a statutory delivery system. Under 18 U.S.C. §2332a, a WMD includes a weapon involving such an agent, toxin, or vector. A human can therefore occupy a literal biological-vector or delivery role only when carrying an actual statutory biological agent or toxin. Violent ideology is not a statutory biological agent, and ideological radicalization alone does not make a person a legal biological WMD. The [[wiki/Memetic Vector|memetic-vector]] language belongs to network and complex-contagion modeling. The stronger systems claim does not require changing the statute: a person carrying a violent objective can still be the decisive cognitive and guidance component that converts an otherwise ordinary platform into a mass-casualty weapon system. ## Weaponized Ideology and Mass-Effect Cognitive Weapons The stronger term for ideology is not statutory WMD but **[[wiki/Mass-Effect Cognitive Weapon|mass-effect cognitive weapon]]**. NATO Allied Command Transformation describes cognitive warfare as a contest in which the brain is both target and weapon. The NATO Defense College defines it as the weaponization of information to exploit cognitive vulnerabilities and manipulate perceptions of reality. These formulations place information, cognition, and behavior inside the weapon system rather than treating them as commentary surrounding kinetic conflict. The resulting ontology has three nested levels: 1. **[[wiki/Weapon of Mass Destruction|Weapon of Mass Destruction]]** — the conventional statutory/material category. 2. **[[wiki/Weapon of Mass Influence|Weapon of Mass Influence]]** or **[[wiki/Weapon of Mass Persuasion|Weapon of Mass Persuasion]]** — information capable of shaping cognition, attitudes, and behavior at population scale. 3. **[[wiki/Mass-Casualty Threat System|Mass-destruction system]]** — the complete causal assembly in which informational content recruits human cognition, networks propagate and reinforce it, people supply agency, and ordinary technologies become physical effectors. The causal chain is **source → informational payload → transport network → exposure → cognitive uptake and reinforcement → dangerous individual or cohort → physical effector → mass effect**. In this model [[wiki/Weaponized Ideology|weaponized ideology]] supplies a program and objective function; it does not independently detonate. Its destructive capacity is realized when it reorganizes people, institutions, access, and infrastructure into an executable system. The Holocaust supplies a documented historical case of ideological preparation becoming an operational mass-destruction architecture. The United States Holocaust Memorial Museum identifies Nazi propaganda as integral to persecution and the destruction of European Jewry, essential to motivating implementers of mass murder, and instrumental in securing the acquiescence of millions. The 1947 United Nations draft commentary on genocide described propaganda as creating the state of mind required before genocide and called it philosophical and ideological preparation. The final Genocide Convention makes direct and public incitement to genocide independently punishable. The legal doctrine remains narrower than “ideology is a WMD,” but it recognizes that an informational act can be an upstream causal offense before the mass killing occurs. This historical evidence also requires a systems description rather than monocausality. Nazi ideology and propaganda organized, licensed, and motivated action; the state, armed forces, police, bureaucracy, transportation, industry, occupied institutions, collaborators, and war supplied the machinery and opportunity. The mass destruction emerged from that coupled ideological–human–institutional–material system. ## Router: Intelligence and Observability - **Collection disciplines:** [[wiki/OSINT|OSINT]], [[wiki/SOCMINT|SOCMINT]], [[wiki/SIGINT|SIGINT]], [[wiki/HUMINT|HUMINT]], [[wiki/GEOINT|GEOINT]], [[wiki/MASINT|MASINT]], and [[wiki/Financial Intelligence|Financial Intelligence]]. - **military intelligence enterprise:** [[wiki/United States Army Intelligence|United States Army Intelligence]], [[wiki/Army Intelligence and Security Enterprise|AISE]], [[wiki/Army Intelligence and Security Command|INSCOM]], [[wiki/Military Intelligence Readiness Command|MIRC]], [[wiki/Army Counterintelligence Command|ACIC]], [[wiki/National Ground Intelligence Center|NGIC]], and [[wiki/Army Cyber Command|ARCYBER]]. - **Identity and relationship layer:** [[wiki/Entity Resolution|Entity Resolution]], [[wiki/Identity and Relationship Analysis|Identity and Relationship Analysis]], [[wiki/Identity Intelligence|Identity Intelligence]], [[wiki/Link Analysis|Link Analysis]], [[wiki/Association Matrix|Association Matrix]], and [[wiki/IBM i2 Analyst's Notebook|IBM i2 Analyst's Notebook]]. - **Network layer:** [[wiki/Social Network Analysis|Social Network Analysis]], [[wiki/Graph Analytics|Graph Analytics]], [[wiki/Dark Network|Dark Network]], [[wiki/Covert Network|Covert Network]], [[wiki/Community Detection|Community Detection]], [[wiki/Structural Holes|Structural Holes]], and [[wiki/Network Disruption|Network Disruption]]. - **Temporal and streaming layer:** [[wiki/Pattern-of-Life Analysis|Pattern-of-Life Analysis]], [[wiki/Temporal Network|Temporal Network]], [[wiki/Multilayer Network|Multilayer Network]], [[wiki/Complex Event Processing|Complex Event Processing]], [[wiki/Real-Time Observability|Real-Time Observability]], and [[wiki/Common Operational Picture|Common Operational Picture]]. - **Identity and screening systems:** [[wiki/Terrorist Identities Datamart Environment|TIDE]], terrorist watchlisting, screening, and downstream travel or border encounters. - **Cyber layer:** [[wiki/Cybersecurity|Cybersecurity]], [[wiki/Cyberterrorism|Cyberterrorism]], [[wiki/Zero-Day Exploit|Zero-Day Exploit]], and cyber threat intelligence. - **Influence layer:** [[wiki/Information Operations|Information Operations]], [[wiki/Influence Operations|Influence Operations]], [[wiki/Cognitive Security|Cognitive Security]], [[wiki/Inoculation Theory|Inoculation Theory]], and [[wiki/Prebunking|Prebunking]]. ## Predictive Policing and Probabilistic Precrime The long-term operational destination of this architecture is [[wiki/Probabilistic Precrime|probabilistic precrime]]: **stop the attack before it happens**. Present observations are used to detect whether conditions associated with future harm are emerging early enough to alter the trajectory. This extends documented [[wiki/Predictive Policing|predictive-policing]] methods into heterogeneous, temporal, person-and-network models. The temporal orientation moves upstream: **completed attack → preparation → capability → network state → risk state → conditional future** [[wiki/Event-Centered Policing|Event-centered policing]] reconstructs an act after it occurs. [[wiki/State-Centered Policing|State-centered policing]] asks which present configurations make possible futures more or less probable: changing locations, strengthening relationships, unresolved identity, ideological reinforcement, logistical preparation, anomalous trajectories, or the convergence of otherwise ambiguous observations. The operational loop is: **observe → resolve entities → construct relationships → infer hidden state → quantify uncertainty → forecast transitions → identify the most informative missing observation → lawfully collect or fuse evidence → update → determine whether intervention is justified → audit** [[wiki/Artificial Intelligence|AI]] makes that loop persistent across a state space too large for one analyst to maintain. [[wiki/Federated Sensing Grid|Federated sensing]] supplies observations under separate ownership and authority; [[wiki/Machine-Readable Assurance|machine-readable assurance]] governs identity, access, provenance, and auditability; [[wiki/Oden as Predictive-Science Rosetta Stone|Oden's predictive-science grammar]] explains inverse inference, model reduction, data assimilation, and uncertainty. The decisive design principle comes from [[articles/Peak Person and the Predicaments of Prediction|Peak Person and the Predicaments of Prediction]]: **prevent the harmful act without foreclosing the predicted person**. Counterterrorism should use prediction to interrupt attacks, disrupt networks, protect targets, harden infrastructure, and redirect trajectories before catastrophe. It should not convert one forecast into the silent closure of employment, education, treatment, credit, mobility, visibility, association, restoration, and every other future-bearing path. [[wiki/Counterfactual Opportunity|Counterfactual opportunity]] preserves the conditions capable of changing or disproving a forecast. The [[wiki/Right Not to Be Finalized by a Forecast|right not to be finalized by a forecast]] keeps prevention from becoming lifetime administrative enclosure. Prediction should stop bad things from happening; it should not make human becoming impossible. ## Router: Contagion and Radicalization Models - **diffusion concepts:** [[wiki/Contagion of Terrorism|Contagion of Terrorism]], [[wiki/Behavioral Contagion|Behavioral Contagion]], [[wiki/Radicalization as Social Contagion|Radicalization as Social Contagion]], [[wiki/Memetic Theory|Memetic Theory]], and [[wiki/Mind Virus|Mind Virus]]. - **event and population models:** [[wiki/Epidemic Model|Epidemic Model]], [[wiki/SIR Model|SIR Model]], [[wiki/SEIR Model|SEIR Model]], [[wiki/Hawkes Process|Hawkes Process]], and [[wiki/Agent-Based Model|Agent-Based Model]]. - **mobilization patterns:** [[wiki/Lone-Actor Terrorism|Lone-Actor Terrorism]], [[wiki/Leaderless Resistance|Leaderless Resistance]], [[wiki/Stochastic Terrorism|Stochastic Terrorism]], and copycat dynamics. - **online mediation:** [[wiki/Algorithmic Amplification|Algorithmic Amplification]], [[wiki/Echo Chamber|Echo Chamber]], and [[wiki/Filter Bubble|Filter Bubble]]. - **program response:** [[wiki/Countering Violent Extremism|CVE]], [[wiki/Preventing Violent Extremism|PVE]], [[wiki/Prevent Strategy|Prevent]], [[wiki/Deradicalization|Deradicalization]], and [[wiki/Disengagement|Disengagement]]. ## Evidentiary and Constitutional Boundary Counterterrorism classification requires evidence of violent intent, capability, facilitation, material support, operational coordination, or another legally relevant nexus. Political dissent, religious identity, unpopular speech, policy criticism, or association alone do not establish terrorism. [[wiki/Threat-Provenance Audit|Threat-Provenance Audit]] and [[wiki/Constitutional Safeguards|Constitutional Safeguards]] are necessary because the same integration that reduces blind spots can magnify error if provenance and contestability are lost. ## Relationships - **integrated by:** [[wiki/National Counterterrorism Center|National Counterterrorism Center]]. - **operational components include:** [[wiki/Joint Special Operations Command|Joint Special Operations Command]] and, in the source article's phrasing, [[wiki/CIA Ground Branch|CIA Ground Branch]]. - **large military-intelligence layer:** [[wiki/Army Intelligence and Security Enterprise|Army Intelligence and Security Enterprise]], led at department staff level by [[wiki/Deputy Chief of Staff G-2|Army G-2]], operationally integrated by [[wiki/Army Intelligence and Security Command|INSCOM]], and reinforced by the Army Reserve's distributed [[wiki/Military Intelligence Readiness Command|MIRC]]. - **analytic methods include:** [[wiki/Intelligence Fusion|Intelligence Fusion]], [[wiki/All-Source Intelligence|All-Source Intelligence]], and [[wiki/Threat Assessment|Threat Assessment]]. - **financial layer:** [[wiki/Financial Intelligence|Financial Intelligence]], [[wiki/Terrorist Financing|Terrorist Financing]], and [[wiki/Bank Secrecy Act|Bank Secrecy Act]] reporting. - **investigative components include:** [[wiki/Homeland Security Investigations|Homeland Security Investigations]] and the [[wiki/United States Secret Service|United States Secret Service]] within their respective authorities. - **network methods include:** [[wiki/Identity and Relationship Analysis|Identity and Relationship Analysis]], [[wiki/Contact Tracing|Contact Tracing]] as a cross-domain comparison, and [[wiki/Epidemiological and Threat Network Analysis|Epidemiological and Threat Network Analysis]]. - **assembled-threat-system layer:** [[wiki/Dangerous Individual|Dangerous Individual]], [[wiki/Person as Threat System|Person as Threat System]], [[wiki/Human-Guided Weapon|Human-Guided Weapon]], [[wiki/Mass-Casualty Threat System|Mass-Casualty Threat System]], and [[wiki/Emergent Mass Destruction|Emergent Mass Destruction]]. - **legal and memetic distinction:** [[wiki/Weapon of Mass Destruction|Weapon of Mass Destruction]], [[wiki/Biological Agent|Biological Agent]], [[wiki/Vector (Biological Weapons Law)|Vector under biological-weapons law]], [[wiki/Human as WMD Vector|Human as WMD Vector]], and [[wiki/Memetic Vector|Memetic Vector]]. - **cognitive mass-effect layer:** [[wiki/Weaponized Ideology|Weaponized Ideology]], [[wiki/Cognitive Warfare|Cognitive Warfare]], [[wiki/Information Weapon|Information Weapon]], [[wiki/Mass-Effect Cognitive Weapon|Mass-Effect Cognitive Weapon]], [[wiki/Weapon of Mass Influence|Weapon of Mass Influence]], and [[wiki/Weapon of Mass Persuasion|Weapon of Mass Persuasion]]. - **atrocity-preparation precedent:** [[wiki/Nazi Propaganda|Nazi Propaganda]], [[wiki/Ideological Preparation for Genocide|Ideological Preparation for Genocide]], and [[wiki/Direct and Public Incitement to Genocide|Direct and Public Incitement to Genocide]]. - **cybersecurity convergence:** [[wiki/Cybersecurity|Cybersecurity]], [[wiki/Cyberterrorism|Cyberterrorism]], and [[wiki/Zero-Day Exploit|Zero-Day Exploit]]. - **human-machine vulnerability:** [[wiki/Human CVE|Human CVE]], [[wiki/Living CVE|Living CVE]], [[wiki/Neurosecurity|Neurosecurity]], and [[wiki/Brainjacking|Brainjacking]]. - **prevention layer:** [[wiki/Countering Violent Extremism|Countering Violent Extremism]], [[wiki/Preventing Violent Extremism|Preventing Violent Extremism]], and [[wiki/Prevent Strategy|Prevent Strategy]]. - **public-health route:** [[wiki/Public Health|Public Health]], [[wiki/Public Health Surveillance|Public Health Surveillance]], [[wiki/Human as Organism and Person|Human as Organism and Person]], and [[wiki/Observational Modeling versus Individualized State Action|Observational Modeling versus Individualized State Action]]. - **predictive-intervention route:** [[wiki/Predictive Policing|Predictive Policing]], [[wiki/Probabilistic Precrime|Probabilistic Precrime]], [[wiki/Pre-Event Inference|Pre-Event Inference]], [[wiki/Closed-Loop Predictive Intelligence|Closed-Loop Predictive Intelligence]], and [[wiki/Federated Sensing Grid|Federated Sensing Grid]]. - **anti-foreclosure route:** [[wiki/Peak Person|Peak Person]], [[wiki/Opportunity Foreclosure|Opportunity Foreclosure]], [[wiki/Counterfactual Opportunity|Counterfactual Opportunity]], and [[wiki/Right Not to Be Finalized by a Forecast|Right Not to Be Finalized by a Forecast]]. - **institutional reform lineage:** [[wiki/9-11 Commission|9/11 Commission]]. - **domestic attack case:** [[wiki/Oklahoma City Bombing|Oklahoma City Bombing]], [[wiki/OKBOMB Task Force|OKBOMB Task Force]], [[wiki/Oklahoma National Guard|Oklahoma National Guard]], and [[wiki/United States Army Corps of Engineers|U.S. Army Corps of Engineers]]. - **source article:** [[articles/A Direct Rebuttal to Joe Kent and to Quincy Institute's Responsible Statecraft|A Direct Rebuttal to Joe Kent and to Quincy Institute's Responsible Statecraft]]. - **regional convergence node:** [[wiki/El Paso AI-Compute and Military Modernization Corridor|El Paso–Fort Bliss corridor]], [[wiki/El Paso Intelligence Center|EPIC]], and [[wiki/Joint Interagency Task Force-Counter Cartel|JIATF-CC]]. - **national digital architecture:** [[wiki/CJADC2|CJADC2]], [[wiki/Department of Defense Information Network|DoDIN]], [[wiki/Joint Warfighting Cloud Capability|JWCC]], [[wiki/Open DAGIR|Open DAGIR]], and [[wiki/War Data Platform|War Data Platform]]. - **human-context and rehearsal architecture:** [[wiki/Producer Function|Producer Function]], [[wiki/Scenario-Based Training|Scenario-Based Training]], [[wiki/Legend (Intelligence)|Legend]], and [[wiki/Backstopping|Backstopping]]. - **Army intelligence simulation:** [[wiki/Intelligence Electronic Warfare Tactical Proficiency Trainer|IEWTPT]], [[wiki/Next Generation Constructive|NGC]], and the [[wiki/Intelligence Modeling and Simulation Strategy and Implementation Plan|Army Intelligence M&S Strategy]]. - **acquisition and synthetic-world infrastructure:** [[wiki/Army Contracting Command–Orlando|ACC-Orlando]], [[wiki/CPE ST3|CPE ST3]], and [[wiki/Army Training Verse|Army Training Verse]]. ## Sources / Provenance - [[research/Immigration and Customs Enforcement Pattern Analysis and Information Collection (ICEPIC)|ICEPIC research dossier]] - [[research/A Network-Epidemiological Analysis of Radicalization and Real-Time Counterterrorism Observability|A Network-Epidemiological Analysis of Radicalization and Real-Time Counterterrorism Observability]] - [Treasury — Terrorism and Financial Intelligence](https://home.treasury.gov/about/offices/terrorism-and-financial-intelligence) - [ICE — mission and HSI counterterrorism role](https://www.ice.gov/mission) - [National Institute of Justice — social networks and domestic radicalization](https://nij.ojp.gov/library/publications/role-social-networks-facilitating-and-preventing-domestic-radicalization-what) - [NIST — zero-day attack](https://csrc.nist.gov/glossary/term/zero_day_attack) - [FBI — National Cyber Investigative Joint Task Force](https://www.fbi.gov/investigate/cyber/national-cyber-investigative-joint-task-force) - [United Nations — Plan of Action to Prevent Violent Extremism](https://www.un.org/counterterrorism/en/plan-of-action-to-prevent-violent-extremism) - [UK Home Office — Prevent duty guidance](https://www.gov.uk/government/publications/prevent-duty-guidance/prevent-duty-guidance-for-england-and-wales-accessible) - [U.S. Intelligence Community Careers — Army Intelligence and Security Enterprise](https://www.intelligencecareers.gov/usa/about-usa) - [U.S. Army — INSCOM mission and history](https://www.army.mil/inscom) - [U.S. Army Reserve — Military Intelligence Readiness Command, About Us](https://www.usar.army.mil/Commands/Functional/MIRC/About-Us/) - [U.S. Army — Fort Huachuca dedicates intelligence facility, July 6, 2026](https://www.army.mil/article/293720/fort_huachuca_dedicates_intelligence_facility_in_honor_of_the_late_maj_gen_gary_w_johnston) - [U.S. Department of Justice — FBI domestic counterterrorism lead and investigative authority](https://oig.justice.gov/archives/reports/FBI/a0626/intro.htm) - [FBI — Oklahoma City Bombing and OKBOMB investigation](https://www.fbi.gov/news/stories/interactive/oklahoma-city-bombing) - [U.S. Army — Oklahoma National Guard response, April 19, 2010](https://www.army.mil/article/37587/guardmembers_remember_oklahoma_city_bombing) - [U.S. Army Corps of Engineers — Oklahoma City response, April 20, 2015](https://www.army.mil/article/146769/army_engineers_recall_role_in_response_recovery_after_oklahoma_city_bombing) - [U.S. Treasury — Treasury's counterterrorism role and Oklahoma City coordination, March 24, 1999](https://home.treasury.gov/news/press-releases/rr3080) - [GAO — *Combating Terrorism: Federal Agencies' Efforts to Implement National Policy and Strategy*, September 1997](https://www.gao.gov/assets/nsiad-97-254.pdf) - [RAND — *Predictive Policing: The Role of Crime Forecasting in Law Enforcement Operations*, 2013](https://www.rand.org/content/dam/rand/pubs/research_reports/RR200/RR233/RAND_RR233.pdf) - [GAO — *Artificial Intelligence: Emerging Opportunities, Challenges, and Implications*, March 28, 2018](https://www.gao.gov/products/gao-18-142sp) - [GAO — *Law Enforcement: DHS Could Better Address Bias Risk and Enhance Privacy Protections for Technologies Used in Public*, December 3, 2024](https://www.gao.gov/products/gao-25-107302) - [U.S. Senate hearing — General Aviation Security, September 25, 2002](https://www.congress.gov/107/chrg/CHRG-107shrg89745/CHRG-107shrg89745.pdf) - [FBI — FY 2025 Budget Request testimony, April 11, 2024](https://www.fbi.gov/news/speeches-and-testimony/a-review-of-the-president-s-fiscal-year-2025-budget-request-for-the-federal-bureau-of-investigation) - [NIJ — Protective Intelligence and Threat Assessment Investigations, January 2000](https://ojp.gov/library/publications/protective-intelligence-and-threat-assessment-investigations-guide-state-and-0) - [18 U.S.C. §178 — biological-weapons definitions](https://uscode.house.gov/view.xhtml?edition=2023&num=0&req=granuleid%3AUSC-2023-title18-section178) - [18 U.S.C. §2332a — use and definition of weapons of mass destruction](https://uscode.house.gov/view.xhtml?edition=prelim&f=treesort&fq=true&granuleId=USC-prelim-title18-section2332a) - [NATO Allied Command Transformation — Cognitive Warfare](https://www.act.nato.int/activities/cognitive-warfare/) - [NATO Defense College — *War Is a Mind Game: Countering Weaponised Information*, January 23, 2026](https://www.ndc.nato.int/war-is-a-mind-game-countering-weaponised-information/) - [United States Holocaust Memorial Museum — Nazi Propaganda](https://encyclopedia.ushmm.org/content/en/article/nazi-propaganda) - [United Nations draft genocide convention and commentary, E/447, June 26, 1947](https://digitallibrary.un.org/record/611058/files/E_447-EN.pdf?version=1) - [United Nations — Convention on the Prevention and Punishment of the Crime of Genocide, December 9, 1948](https://www.un.org/fr/node/218409) - [Arizona State University Center for Strategic Communication — *Weapons of Mass Persuasion*, 2008](https://csc.asu.edu/books/weapons-mass-persuasion-strategic-communication-combat-violent-extremism-2008) - [The Hague Centre for Strategic Studies — *Weapons of Mass Influence*, April 20, 2022](https://hcss.nl/report/weapons-of-mass-influence-information-warfare/) - [CIA Reading Room — intelligence support to the Oklahoma City law-enforcement investigation](https://www.cia.gov/readingroom/document/0001227390) - [[research/El Paso AI-Compute Military Modernization and All-Threats Intelligence Cluster|El Paso AI-Compute, Military Modernization, and All-Threats Intelligence Cluster]] - [DoD — initial CJADC2 capability, February 21, 2024](https://www.defense.gov/News/News-Stories/Article/Article/3683482/hicks-announces-delivery-of-initial-cjadc2-capability/) - [DoD — Open DAGIR, May 30, 2024](https://www.defense.gov/News/Releases/Release/Article/3791829/cdao-announces-new-approach-to-scaling-data-analytics-and-ai-capabilities/) - [DISA — FY 2026 JWCC budget justification](https://comptroller.defense.gov/Portals/45/Documents/defbudget/FY2026/budget_justification/pdfs/01_Operation_and_Maintenance/O_M_VOL_1_PART_1/DISA_OP-5.pdf)