Loitering as a Threat Signal: What AI Behavioral Detection Can and Cannot See in the Pre-Attack Window
The NCTC-JFRT-2026-00643 assessment documents preoperational surveillance in nearly a third of all terrorist plots. Here is what AI behavioral detection can flag in that window — and where its limits are.
Loitering is not a nuisance problem. It is a pre-attack behavior pattern with a documented intelligence record.
NCTC/DHS/FBI Joint Counterterrorism Assessment, Feb 2026
FBI Pre-Attack Behaviors of Active Shooters, 2000–2013
BLS Census of Fatal Occupational Injuries, Feb 2026
In February 2026, the National Counterterrorism Center (NCTC), the Department of Homeland Security, and the FBI jointly published Preoperational Surveillance and Indicators of Attack Planning (NCTC-JFRT-2026-00643). The assessment reviewed more than 300 domestic and international attack plots documented between 1990 and 2022 and reached a conclusion that should change how security directors evaluate loitering: in nearly a third of all documented plots, adversaries were observed conducting preoperational surveillance — watching the target, testing access, timing shift changes, or mapping camera coverage — before carrying out the attack.
The January 1, 2025 New Year's Day vehicle attack in New Orleans, Louisiana illustrates how recent this threat pattern remains. According to FBI post-incident reporting cited in the NCTC assessment, the perpetrator used commercially available smart glasses to conduct physical reconnaissance of the French Quarter approximately two months before the attack, recording video of pedestrian density, vehicle access points, and barrier configurations. The attack killed 14 people and injured dozens more. The pre-attack observation window was long, methodical, and conducted without triggering any existing detection system at the site.
This Intelligence report examines what the pre-attack surveillance window actually looks like, what behavioral AI detection systems can and cannot identify within it, and why loitering detection has become a foundational layer of any serious multi-threat security deployment — not because every loiterer is a threat, but because no pre-attack surveillance pattern is invisible when the right behavioral tripwires are set.
What preoperational surveillance looks like: the NCTC-JFRT-2026-00643 findings
The NCTC joint assessment defines preoperational surveillance as a specific set of observed behaviors that adversaries conduct in the weeks or months before an attack. These behaviors are not random. They follow a recognizable pattern shaped by the operational need to understand a target's vulnerabilities before committing to a method of attack.
The assessment documents that attack aspirants commonly visit a chosen target on multiple occasions, both on foot and by vehicle, over a period that ranges from several days to sometimes more than one year before execution. The behaviors observed during these visits include loitering and observing outside a location for an extended period of time, making repeated visits at the same time of day to establish shift-change or patrol patterns, photographing or videotaping security infrastructure and camera positions, timing security guard rotation or law enforcement response, conducting aerial reconnaissance via commercially available unmanned aerial systems (UAS), and probing access controls — testing whether doors are locked, whether staff challenge unknown individuals, and whether perimeter barriers are consistently staffed.
The May 2025 Michigan Army National Guard plot is a documented case of the aerial reconnaissance variant. According to federal charging documents cited in the NCTC assessment, the defendant flew a commercial UAS over a targeted military facility on multiple occasions, capturing overhead imagery of facility layout, entry points, and vehicle staging areas. The preoperational phase preceded the planned attack by several months.
What these documented cases share is a temporal window: the pre-attack surveillance period is measurable in days, weeks, or months. It is not an instantaneous event. This temporal exposure is exactly what behavioral AI detection is designed to identify — not the one-time presence of an unknown individual, but the pattern of repeated presence that distinguishes operational reconnaissance from ordinary pedestrian activity.
NSI: the institutional framework that produced the NCTC assessment
The NCTC-JFRT-2026-00643 assessment is grounded in the Nationwide Suspicious Activity Reporting (SAR) Initiative (NSI) — a DHS, FBI, and DOJ program that standardizes how state and local law enforcement collect and share suspicious activity reports. The NSI defines 16 specific Behavioral Indicators of suspicious activity considered potentially linked to terrorism. Loitering and observation — specifically "loitering and observing outside a location for an extended period of time" — is among the enumerated indicators. AI behavioral detection systems that flag extended loitering are, in effect, operationalizing the NSI's defined threat indicator set at machine speed and camera scale.
The FBI pre-attack window: what active shooter cases tell us about temporal exposure
The NCTC assessment is the most recent primary source on preoperational surveillance patterns. The FBI's 2019 study, Pre-Attack Behaviors of Active Shooters in the United States 2000–2013, provides the complementary domestic active-shooter dataset.
The FBI study analyzed 63 active shooter incidents and found that 77% of shooters exhibited observable warning behaviors for a week or longer before their attacks. The study documented that attackers commonly engaged in location research — visiting the target site prior to the attack — as part of the planning process. In multi-victim workplace shooting cases in particular, the attacker was frequently a current or former employee or associate of the target location, with extended familiarity with the site's layout, access controls, camera coverage, and personnel routines.
The US Secret Service National Threat Assessment Center (NTAC) published complementary findings in Mass Attacks in Public Spaces 2016–2020, which studied 173 targeted mass violence incidents. NTAC found that the majority of attackers engaged in some form of planning behavior before the attack, and that for incidents in workplace, educational, and government settings, prior familiarity with the target was common. NTAC explicitly noted that most attackers did not suddenly snap — the pre-attack window was a structured period during which detection was possible in principle.
These three datasets — NCTC/DHS/FBI 2026, FBI 2019, and NTAC 2016–2020 — form the primary-source foundation for why behavioral detection during the pre-attack window is operationally meaningful rather than theoretical. The window exists. The behaviors within it are documented. The question is whether security technology is positioned to identify them.
What AI behavioral detection can see in the pre-attack window
Behavioral detection systems analyze continuous video feeds from existing camera infrastructure and apply computer vision models trained to identify specific visual patterns. For the pre-attack window, four detection modalities map directly onto the behaviors the NCTC and FBI studies document as operational indicators.
Pre-Attack Behaviors vs. AI Detection Coverage
| Pre-Attack Behavior (NCTC-JFRT-2026-00643) | AI Detection Modality | What the System Flags | Alert Trigger |
|---|---|---|---|
| Loitering outside a location for extended duration, on foot or in a vehicle | Loitering Detection | Person or vehicle present in a defined zone beyond a configured time threshold | Configurable: immediate alert to dispatch, or tiered (observation then escalation) based on dwell time |
| Photographing or mapping security infrastructure and camera positions | Unauthorized Zone Access | Entry into a restricted area or close approach to perimeter chokepoints outside permitted access patterns | Immediate alert when zone boundary crossed by unauthorized individual |
| Repeated visits at same time of day to establish patrol and shift-change patterns | Loitering Detection + Pattern Recurrence | Persistent presence detected on multiple separate occasions at the same zone | Alert per session; incident logging creates a documented behavioral record for pattern review |
| Drawn firearm visible during approach or final surveillance visit | Drawn Firearm Detection | Pixel-level identification of a visible, drawn firearm in the camera frame | Immediate high-priority alert routed to dispatch and first responders |
The loitering detection modality is the most directly relevant to the pre-attack surveillance window because it is the only detection type that operates on behavioral duration rather than a point-in-time object signature. A drawn firearm is a discrete visual event. Loitering is a continuous behavioral state. The detection threshold — a configurable minimum dwell time in a defined zone — is what transforms a camera from a recording device into an active tripwire for the reconnaissance pattern the NCTC study documents.
The configuration matters more than the technology. A loitering alert set at a two-minute threshold in a low-traffic exterior zone will produce a useful signal. The same threshold applied to a hospital waiting room will produce false positives that erode staff confidence in the system. A mature deployment matches the dwell-time threshold to the baseline pedestrian activity of the specific zone — a parking deck stairwell, a loading dock, a school entrance, or a government building exterior each has a different normal pattern against which anomalous persistence stands out.
What AI behavioral detection cannot see — and why that matters
Intellectual honesty about the limits of the technology is a prerequisite for deploying it well. Behavioral AI detection in the pre-attack window has four documented constraint areas that security directors must account for in their deployment design.
Aerial and standoff reconnaissance. The Michigan Army National Guard case illustrates the problem directly: a UAS flying at 200 feet above a facility is conducting preoperational surveillance that no ground-level camera system will detect. Camera-based behavioral detection covers what cameras can see. UAS-based reconnaissance requires a separate sensor layer. AI camera systems are not a counter-UAS capability.
Digital and open-source reconnaissance. A significant portion of modern pre-attack planning occurs in digital environments: satellite imagery analysis, review of online mapping tools for camera positions, social media review of target location photos, and dark web procurement of facility access credentials. None of this reconnaissance has a physical manifestation that camera-based detection can observe. The NCTC assessment explicitly notes the growing use of open-source intelligence by domestic attack aspirants as a method that does not require physical proximity to the target.
Insider familiarity. The FBI active-shooter data shows that in a substantial proportion of workplace incidents, the perpetrator was a current or former employee or associate with legitimate prior access to the target. An insider has already conducted their reconnaissance through normal presence. Loitering detection is designed to flag anomalous persistence by individuals who do not have a normal reason to be present — it provides minimal signal for individuals whose presence is baseline-normal to the camera's observed environment.
Intent identification. A camera system can detect that a person has been present at an exterior entrance for 18 minutes. It cannot determine whether that person is conducting operational reconnaissance or waiting for a ride. The behavioral flag is a tripwire for human investigation, not a binary determination of threat intent. Security protocols built around AI loitering alerts must include a human assessment step that the system triggers but does not replace.
Behavioral detection as a tripwire, not a verdict
The operational value of AI loitering detection is not that it identifies threat intent — it is that it converts a passive surveillance camera into an active alert system for behavioral anomalies that correlate with documented pre-attack patterns. The system creates a documented record of anomalous presence events, routes alerts to staff who can conduct contextual assessment, and does so at camera-to-screen scale that no human monitoring team can match. The human investigation step remains essential; AI detection provides the earliest possible trigger for it. A security director who builds a protocol that stops at the AI alert rather than using it to initiate a trained security officer response has misconfigured the deployment, not the technology.
Loitering detection by sector: high-value zones and configuration logic
The pre-attack surveillance behaviors documented by NCTC and FBI do not manifest the same way across every deployment environment. Sector context determines which zones carry the highest reconnaissance exposure, what dwell-time thresholds make operational sense, and how alert routing integrates with existing response protocols.
Loitering Detection by Sector: High-Value Zones and Configuration Logic
| Sector | Highest-Risk Loitering Zones | Baseline Activity | Recommended Dwell Threshold | Alert Routing |
|---|---|---|---|---|
| Healthcare / Hospital | ED entrances, parking deck stairwells, behavioral health unit exits, loading docks | Moderate — patients waiting, vendors staging | 5–8 minutes in low-traffic zones; 12–15 minutes in ED exterior | Security dispatch + charge nurse for clinical zones |
| K-12 / Education | Campus perimeters during school hours, athletic facility exits, parking areas | Low during class hours, high during transition | 3–5 minutes during class hours; suppressed during transition windows | School resource officer, front office, building administrator |
| Government / Courthouse | Building entrances, secured parking, public plaza adjacent to restricted perimeter | Moderate — constituents queuing, staff arriving and departing | 8–10 minutes at exterior zones; 3 minutes at secured perimeter | Courthouse security, federal protective service |
| Houses of Worship | Parking lots, exterior sanctuary entrances, fellowship hall exits during services | Low between services, high during gathering windows | 5 minutes outside service windows; 15 minutes during active service | Designated safety team, pastoral staff, direct-to-911 for escalation tier |
| Stadiums / Venues | Public plazas outside secured perimeter, vehicle drop-off areas, approach roads | High during events — sustained queuing is normal | Highly contextual; exclude queue areas; focus on non-queue perimeter zones | Venue security operations center; tiered alert by event phase |
| Manufacturing / Industrial | Exterior facility perimeter, gate access zones, loading dock approach roads | Low — vendor and employee traffic is scheduled | 3–5 minutes at perimeter; immediate alert for after-hours zones | Plant security, safety manager, shift supervisor |
The sector table reflects a core deployment principle: the same detection system requires fundamentally different configuration across environments. A government courthouse with a secured perimeter and trained federal protective service personnel can tolerate a very short loitering threshold and a direct escalation protocol. A stadium during an event must suppress alerts from the queue line while maintaining active detection on non-queue perimeter zones. Getting this configuration wrong in either direction degrades the signal-to-noise ratio that determines whether staff treat the alert system as a useful tool or a nuisance to be ignored.
For a deeper treatment of how AI detection applies in the government and public building context, see the Government and Public Buildings Sector Playbook. For healthcare-specific deployment, the Healthcare Workplace Violence AI Detection Playbook covers department-by-department configuration in detail.
Pre-Attack Surveillance: The Numbers
What the primary-source record shows about the pre-attack window
Attack plots reviewed in the NCTC/DHS/FBI joint assessment spanning 1990 to 2022, establishing the statistical basis for preoperational surveillance as a documented indicator
NCTC-JFRT-2026-00643, Feb 2026
Specific Behavioral Indicators defined by the NSI as potentially linked to terrorism, with loitering and observation enumerated as one of the 16
DHS Nationwide SAR Initiative (NSI)
Duration of the pre-attack reconnaissance window in the New Orleans New Year's Day 2025 vehicle attack, conducted using smart glasses to scout pedestrian density and access points
FBI post-incident reporting, NCTC-JFRT-2026-00643
Targeted mass violence incidents analyzed by the US Secret Service NTAC, the majority involving observable pre-attack planning behavior in a structured window
NTAC Mass Attacks in Public Spaces 2016–2020
Typical time from appliance installation to initial detection coverage in a multi-site AI behavioral detection deployment, layering on existing camera infrastructure
IntelliSee deployment data
Detection-to-alert pipeline duration from camera frame to dispatched security response for high-confidence threat events
IntelliSee platform specification
How the detection pipeline works: from perimeter camera to security dispatch
Understanding the technical architecture of AI behavioral detection is essential for security directors evaluating whether the technology fits their infrastructure, and for communicating the deployment to facilities managers, IT security teams, and legal counsel who will ask the right questions about data handling, false positive management, and system integration.
The IntelliSee detection architecture operates in five stages. In stage one, the platform connects to existing IP cameras through the facility's video management system (VMS). Milestone XProtect, Genetec Security Center, and most major VMS platforms are supported. No camera replacement is required. In stage two, video analysis runs on a dedicated 1U rack-mounted appliance installed in the facility's server room. Frames are processed locally, and video does not leave the facility network for detection processing — the cloud is not in the detection path. This matters for HIPAA and other regulatory compliance, and for operational resilience during network disruption.
In stage three, computer vision models analyze each camera frame for defined threat signatures. For loitering detection, the model identifies the presence of a person or vehicle in a defined zone and begins tracking elapsed dwell time. When dwell time crosses the configured threshold for that zone, an alert event is generated. In stage four, configured alert routes deliver the event to designated responders through existing dispatch infrastructure: security consoles, mobile notifications, radio integration, overhead paging through systems like Singlewire InformaCast, or directly to first responders through RapidSOS. In stage five, each detection event is logged with timestamp, zone, camera, detection type, and alert routing record — creating a documented behavioral incident record that supports post-event investigation and regulatory compliance documentation.
The DHS SAFETY Act Full Designation that IntelliSee holds as a Qualified Anti-Terrorism Technology (QATT) provides liability protection for covered facilities in the event of a terrorism incident while the platform is deployed. For government facilities, educational institutions, houses of worship, and other targets that appear in the NCTC's documented threat landscape, this liability posture is a material deployment consideration. For a deeper look at what Full Designation means for facility liability, see the DHS SAFETY Act Designation analysis.
From theory to deployment: a pre-attack detection readiness checklist
A security director building a behavioral detection deployment aimed at pre-attack surveillance identification should work through seven configuration decisions before the appliance goes live.
First, map the reconnaissance exposure zones. Using the NCTC behavioral indicators as a reference frame, identify which camera zones cover the approaches, entrances, and perimeter areas that a surveillance-oriented adversary would observe. Parking structures, exterior entrances, and adjacent public spaces are typically the highest-value zones.
Second, establish baseline pedestrian activity per zone. For each identified zone, document what normal looks like: how many people typically pass through, at what times, and for how long. This baseline determines the dwell-time threshold that will produce a useful signal without generating false-positive fatigue.
Third, configure time-of-day suppression and exception windows. Shift changes, delivery windows, and scheduled gatherings create legitimate high-dwell-time activity that should not trigger loitering alerts. Most behavioral detection platforms support scheduled suppression windows for specific zones during defined time periods.
Fourth, define the human response protocol for each alert tier. An AI alert without a defined human response protocol is a notification that no one knows what to do with. For each zone and alert tier, the pre-deployment planning should specify who receives the alert, what their initial response action is, and at what point they escalate to law enforcement contact.
Fifth, integrate with existing security infrastructure. AI behavioral detection is most effective when it maps onto the other layers of the physical security program — access control, mass notification, guard dispatch, and first-responder coordination. Mapping the detection alert to existing Code response protocols before deployment prevents the system from operating as a parallel alert track that staff monitor separately.
Sixth, establish an incident documentation review cadence. The incident log produced by the detection system should be reviewed at least weekly to identify patterns that individual events might not surface. Multiple loitering events at the same zone across different days, even if each was investigated and cleared, constitute a behavioral pattern that warrants a higher-level threat assessment.
Seventh, train staff on what the system detects and what it does not. The documented limits of the technology — aerial reconnaissance, digital surveillance, insider familiarity — must be part of the staff briefing when a behavioral detection system is deployed. A staff that understands the system's scope will use it correctly. A staff that believes it covers everything will develop a false-security posture that can be exploited by exactly the adversaries the NCTC documents as operational planners.
Frequently asked questions
How is AI loitering detection different from a motion-activated camera alert?
A motion-activated alert fires when any movement occurs in a zone, which in most environments generates constant alerts with no security signal value. AI loitering detection is specifically a duration-based behavioral alert: it tracks how long a specific person or vehicle has been present in a defined zone and triggers only when dwell time crosses a configured threshold. This eliminates noise from ordinary movement and focuses the alert on the persistent, extended presence that the NCTC and FBI identify as a pre-attack indicator.
Does loitering detection require identifying individuals to work?
No. IntelliSee's platform detects behavioral patterns — presence, movement, dwell time, zone boundary crossing — without performing facial recognition or computing any identity-based biometric. The detection layer identifies that a person is present in a zone for an anomalous duration. It does not identify who that person is. This architecture is what makes the platform deployable in environments with strict privacy requirements, including healthcare, education, and government facilities.
What false positive rate should a security director expect?
False positive rate is almost entirely a function of configuration rather than the underlying detection model. A loitering alert set with an appropriately calibrated dwell-time threshold for a given zone's baseline activity should produce a false positive rate low enough that security staff treat alerts as worth investigating. Deployments that generate alert fatigue are almost always the product of misconfigured thresholds or missing time-of-day suppression windows. The tuning period, typically one to two weeks after initial deployment, is specifically designed to calibrate these parameters before the system enters operational use.
Can AI behavioral detection be used in a law enforcement referral?
The incident log produced by the detection system — with timestamps, camera IDs, zone designations, dwell times, and alert records — can be a component of a documented threat assessment and can be provided to law enforcement as part of a suspicious activity report under the NSI framework. The footage captured during a detection event can be exported from the VMS for law enforcement review. AI detection does not make threat determinations, but the documented behavioral record it creates can support a threat referral with more specificity than an undocumented staff observation.
How does AI loitering detection address vehicle-based reconnaissance?
Vehicle detection operates on the same behavioral-duration principle as pedestrian loitering detection. A vehicle parked or idling in a defined exterior zone beyond a configured time threshold triggers the same alert framework. The January 2025 New Orleans attack used a vehicle as both the reconnaissance platform and the weapon of attack. Vehicle loitering detection at perimeter zones creates a behavioral tripwire for exactly the kind of extended vehicular observation the NCTC assessment documents as a pre-attack indicator.
Should loitering detection be running during events when extended presence is normal?
Yes, with carefully configured zone exclusions and time-of-day adjustments. During events, detection should be maintained on non-queue perimeter areas, vehicle drop-off zones outside the controlled perimeter, and approach roads, while excluding queue lines where sustained presence is normal. Most behavioral detection platforms support named detection profiles that can be switched by event phase.
What is the typical deployment timeline for adding behavioral detection to an existing camera network?
A typical deployment reaches initial detection coverage within 48 to 72 hours of appliance installation. A one to two week tuning period follows, during which detection zones are refined, false-positive thresholds are calibrated per zone and time of day, and alert routing is tested through the facility's existing emergency response workflows. A structured risk assessment before deployment will surface the architecture choices that determine project scope for a specific facility.
Continue the research
This report covers the pre-attack surveillance window and the role of AI behavioral detection within it. For related research:
- Loitering Detection solution overview — technical architecture, zone configuration, and alert routing specifics for IntelliSee's behavioral detection modality.
- Healthcare Workplace Violence: The AI Detection Playbook — sector-specific treatment of behavioral detection deployment in hospital environments, including ED-specific configuration and Code Gray integration.
- Government and Public Buildings: The 2026 AI Physical Security Sector Playbook — how courthouses, municipal facilities, and federal buildings deploy behavioral AI within ISC and federal compliance frameworks.
- DHS SAFETY Act Full Designation analysis — what QATT designation means for liability protection at facilities targeted in the NCTC threat landscape.
- Security legislation tracker — actively maintained database of state and federal physical security mandates.
- How IntelliSee Works — the complete on-premises detection architecture, from camera ingestion to alert routing, without cloud dependency or biometric collection.
More intelligence like this
New IntelliSee research drops monthly at most. Subscribe and get the next sector playbook, technology briefing, or threat intelligence report in your inbox the day it ships.
Get a Risk Assessment
Talk to an IntelliSee security specialist. No sales pitch — a structured conversation about your environment, your threat profile, and whether computer vision is the right fit.
Request a Risk Assessment