OSINT Resources for Corporate Security

Top Indicators of Potential Workplace Violence

Written by Liferaft | September 02, 2026

When the FBI's Behavioral Analysis Unit studied 63 active shooter cases from 2000 to 2013, it found that each attacker had displayed an average of 4.7 concerning behaviors that were observable to the people around them. Someone noticed something in nearly every case. The same study found that in cases where leakage occurred, meaning the attacker communicated intent to a third party, none of the observed instances were reported to law enforcement.

Noticing is rarely where corporate security programs break down. Somebody usually notices. The difficulty comes after that, in whether the observation gets reported at all, who receives it, and whether that person can see it alongside other concerns raised about the same individual over the past two years.

This post covers the behavioral indicators that matter, the ones that get overlooked because they sit outside the employee population, and how open-source intelligence fits into a threat assessment process that can do something useful with them.

 

The Different Types of Workplace Violence

The typology developed by NIOSH and used widely across corporate security divides workplace violence into four categories. Each one produces a different set of indicators, which is why programs built around only one category tend to miss the others.

 

Essentially then, a program that only watches its own workforce is covering one of these four. Type II and Type IV threats arrive from outside the badge system entirely.

 

 

Top Indicators of Potential Workplace Violence

There is no profile of a violent employee, and the FBI study is explicit on this point. What exists instead is a set of behaviors that warrant assessment when they cluster and escalate. Any single item on the list below appears in plenty of people who will never harm anyone. The pattern is what carries the signal.

A grievance with a specific target

In the FBI sample, 79% of attackers appeared to be acting on some grievance. For 16%, that grievance stemmed from an adverse employment action. A grievance becomes a security concern when it stops being general frustration and acquires a name, a title, or a location.

Leakage

Leakage was observed in 56% of cases. It includes direct threats, but more often it looks like something else: a comment that a specific manager will 'get what is coming,' a social post about how a former employer will regret a decision, or a joke about an unusually detailed scenario. Leakage is the single most actionable indicator because it is intentional communication.

Escalation in interpersonal conflict

Problematic interpersonal interactions appeared in 57% of cases. Look for a change in trajectory rather than a snapshot. Conflicts that used to be resolved now recur, involve more people, and shift from disagreement to a grievance narrative.

Deterioration paired with externalized blame.

Declining work performance showed up in 46% of cases. Performance decline on its own is a management issue. Performance decline combined with a belief that the decline was caused by a hostile colleague or unfair supervisor is a different signal.

Fixation and target research

A person who begins gathering information about a specific individual, learning their schedule, their vehicle, or their home area, has moved from grievance to planning. In the FBI sample, 77% of attackers spent a week or longer planning.

Changes in relationship to weapons

Lawful ownership is not an indicator. New acquisition, a shift in how weapons are discussed, or the appearance of weapons in content directed at a grievance target is a change worth documenting.

Boundary and policy testing

 Repeated policy violations, refusal to accept supervision, and probing of access controls or after-hours entry all indicate someone testing what the organization will tolerate.

 

Other Indicators That Are Typically Overlooked

Most indicator lists are written for HR, which means they cover current employees and stop there. Security teams also have to account for people who never appeared on the payroll, or who left it years ago.

The former employee timeline

A grievance can outlast the job by years. Someone who felt their termination was unfair may still be carrying it long after the exit interview, and the day their badge gets deactivated is the day the company stops hearing about them. Managers no longer see them, and HR no longer takes reports. From that point, the only thing anyone can observe is what the person chooses to post publicly.

Third-party escalation

Customers, patients, tenants, litigants, and unsuccessful job candidates all generate grievances against organizations. These signals tend to sit in customer service logs, legal correspondence, and public review platforms, where security teams rarely look.

Domestic violence spillover.

The observable indicators usually come from the victim. You may see: an employee requesting a parking reassignment, unexpected visits to the lobby, a protective order that names the worksite. Cal/OSHA's plan requirements and most duty of care frameworks treat this as within scope.

Coworker avoidance behavior.

Increased absenteeism on a specific team, requests to transfer away from one individual, or reluctance to be scheduled alone with someone often precede any formal complaint. People adjust their behavior around a perceived threat before they report it.

The case that closed with no follow-up.

A concern that was investigated, deemed unsubstantiated, and closed is not the same as a concern that resolved. Without a scheduled review, the file becomes invisible while the underlying grievance continues.

Indicators split across departments

The performance write-up sits with HR. The demand letter from the terminated employee sits with legal, the odd after-hours badge activity with IT, and the parking lot argument with facilities. Nobody holding one of those pieces has much reason to call security about it on its own. They only mean something next to each other, and that is hard to arrange when they live in four separate systems.

Building Data With OSINT to Find Workplace Violence Triggers

Open-source intelligence contributes to workplace violence prevention by covering observation gaps that internal systems cannot reach, including, but not limited to, former employees, non-employee actors, and public expressions of grievance that have not yet been reported internally.

Effective collection begins with defined requirements rather than broad monitoring. A workable set of collection requirements for a workplace violence program includes:

  • Entities to watch. Facility addresses and informal site names, subsidiary and legacy brand names, the names of publicly visible leaders and site managers, and specific individuals tied to an open, documented case.
  • Language and behavior of concern. Grievance framing aimed at the organization, threat and violent-intent language, references to specific locations or people, and content indicating capability or preparation.
  • Sources that matter. Mainstream social platforms cover part of the picture. Grievance content frequently surfaces first on fringe forums, alternative platforms, review sites, and paste sites, which is why deep and dark web coverage belongs in the source list alongside mainstream monitoring.
  • Scope boundaries. This is the part that determines whether a program survives legal review. Collection should be limited to information the subject has already made public, tied to an articulated security concern, and documented with a rationale for its initiation. Persistent monitoring of employees without a specific, recorded concern is a different activity and should not be confused with threat intelligence work.

Requirements like these work best when written down and reviewed quarterly with HR, legal, and privacy teams. Documented scope is also what allows a program to answer the inevitable question about what it collects and why.

How to Use OSINT Data to Your Advantage

Most of the difficulty comes after the alert lands, in the days between finding something and deciding what to do about it.

Corroborate before escalating

An anonymous post that names one of your buildings is a lead and not much else. Somebody has to establish that the account belongs to a real person with a real connection to the organization before it goes any further. Identity resolution matters at this stage because escalating on a misidentified account can cost the wrong person their job.

Assess against a structured method.

Validated instruments such as WAVR-21 give a threat management team a common language and a defensible record. Structured assessment also protects against the two failure modes analysts know well, which are dismissing a credible concern because the person seems unremarkable, and overreacting to crude language from someone with no capability or intent.

Route to a standing team

A single analyst should not carry an assessment decision. Multidisciplinary threat management teams that include security, HR, legal, and counsel are the accepted model precisely because these cases require judgment from several disciplines at once.

Keep one record

Everything gathered on a case belongs in one file with a documented rationale, a decision log, and a scheduled review date. A case manager who holds the full timeline is what allows the next analyst to pick up a two-year-old concern and understand where it sat when it was last reviewed.

Feed findings back into collection

A closed case usually reveals which sources produced value and which produced noise. That knowledge should update the collection requirements.

Stopping Workplace Violence Early is Key

The runway is longer than most people assume. In the FBI study, the first observable concerning behavior occurred at least three months before the attack in roughly 90% of cases, and at least two years before in more than half. Attackers move through a process of grievance, ideation, planning, preparation, and action, and that process leaves observable traces at multiple points.

Intervention early in that sequence also has more options available to it. A grievance that surfaces at the ideation stage can sometimes be addressed through mediation, an EAP referral, a schedule change, or a documented conversation. Once someone has begun preparation, the available responses narrow to protective measures and law enforcement referral. BLS Census of Fatal Occupational Injuries data recorded 470 workplace homicides in 2024, with the majority involving a firearm, which is a reminder of how little margin the late stages leave.

Early intervention also produces better outcomes for the person of concern. The majority of these cases resolve without termination or arrest when someone notices and engages while the situation is still workable.

Building A Workplace Violence Prevention Program

Indicators are only useful inside a program that can receive, assess, and act on them. The components that consistently distinguish mature programs:

The behaviors described throughout this post were visible in nearly every case the FBI examined. Building the connective tissue that lets an organization see them together, assess them consistently, and act on them early is the work that prevention actually consists of.

 

Frequently Asked Questions

 

How does Liferaft help organizations prevent workplace violence?

Liferaft gives security intelligence teams visibility into publicly available information that relates to a defined security concern. Teams use it to listen for grievance and threat language tied to their facilities, brands, and named personnel, to search deep and dark web sources where grievance content often surfaces first, to resolve online personas to real-world individuals during an investigation, and to keep the full timeline of a case in one record that a threat management team can work from. It supplements internal behavioral observation rather than replacing it, and it provides no covert access to private accounts, messages, devices, or location data.

What is OSINT data?

Open-source intelligence is information collected from publicly available sources and then analyzed to answer a specific question. In a corporate security context that includes social media, forums, news, public records, court filings, review platforms, and deep and dark web sources. The intelligence part is the analysis: raw public data becomes OSINT once it has been corroborated, assessed, and connected to a security requirement.

What else can I do with OSINT?

Corporate security teams apply the same collection and analysis discipline to executive protection, travel risk and duty of care, event and site security, brand and impersonation monitoring, insider risk, exposed credential detection, and geopolitical situational awareness. Most programs find that requirements built for one use case support several others.

Is workplace violence preventable?

Individual acts of violence cannot be predicted, and no reputable practitioner claims otherwise. Prevention is nonetheless achievable at the program level, because the pathway to violence unfolds over time and produces observable behavior along the way. Organizations that can collect those observations, assess them consistently, and intervene early do interrupt cases. The evidence base for threat assessment as a discipline rests on exactly that.