Dechefr
Dechefr - A brief introduction
1. Introduction
Dechefr [de·che·pher] is a structured professional judgment (SPJ) tool that assesses threatening written communications to determine potential risk for targeted violence. It analyzes text against evidence-based risk indicators associated with mobilization to violence and presents the results in a structured way, so that a trained professional can combine Dechefr's analysis with their own judgment, case context, and additional intelligence. Dechefr empowers professionals to make rapid, data-informed decisions grounded in the latest research, and is built for maximum performance, accuracy, and safety in communication and threat assessment.
Dechefr can be applied to communication written in English from a wide range of sources, including social media, chat rooms, forum posts, emails, and traditional correspondence. To obtain a valid assessment, the analyzed text should contain 300 or more words. Texts of any length can be analyzed, but shorter texts do not yield a valid assessment.
Dechefr is a decision-support tool, not a decision-maker. It is not intended to be used as the sole source for threat assessment decision-making. The information generated by Dechefr must be evaluated by a trained threat assessment professional, incorporating additional intelligence, context, and relevant situational factors.
Who this guide is for
This guide describes how to use the Dechefr application: how to submit a communication for analysis, how to read and adjust the results, how to run similarity comparisons, and how to generate a report. It is intended for the broad group of professionals typically associated with violence threat assessment and management teams, including mental health, human resources, legal, student affairs, and security professionals, law enforcement, and military personnel.
Key concepts
The twelve Indicators
The twelve Indicators of Potentially Violent Behavior are risk factors specifically associated with lone actors who have mobilized to targeted violence. Each indicator is scored as present or not present. These indicators are more nuanced than the risk level, and the professional can review the underlying evidence and modify each indicator's status when the case context warrants it.
Percentile scores
Some scores in Dechefr are presented as percentiles. A percentile score illustrates a subject's position relative to a reference population (the general population in Dechefr's datasets). Unlike raw scores, which provide limited context, percentiles show how a subject compares to others, allowing for a more nuanced interpretation.
Professional judgment
Different subjects can share the same risk indicators without mobilizing to violence (multifinality), and different subjects can commit similar acts of violence without exhibiting the same warning behaviors (equifinality). The dynamic interaction of risk and protective factors — rather than their cumulative presence or absence — is the best indicator of threat level. This is why Dechefr keeps the professional's structured judgment at the center of every assessment.
How this guide is organized
-
Getting started — requirements, input formats, and account security.
-
Assessment overview — the risk level, the twelve indicators, and the similarity assessment.
-
Start a review of the assessment — manually assess the twelve indicators.
-
Text characteristics — salient words, named entities, and readability.
-
Synopsis — the downloadable summary of a finalized assessment.
-
The assessment framework — operational definitions of the twelve Indicators of Potentially Violent Behavior, and what to look for.
-
Case archive and data handling — what Dechefr stores, what it does not, and how to manage your archive.
-
Glossary — definitions of key terms.
-
FAQ and troubleshooting — answers to common questions.
2. Getting started
What you need
- A written (or translated) communication in English.
- The communication as a file (.doc, .docx, .txt, or .pdf) — or simply the text itself, which can be pasted directly into Dechefr.
Submitting a communication
-
Upload or paste Upload the file, or copy the text directly into the analysis field.
-
Start the analysis Text processing takes from a few seconds to several minutes, depending on the length of the communication.
-
Review the results When processing is complete, the results open in the Assessment Overview.
Account security
Dechefr supports two-factor authentication (2FA). Given the sensitivity of the material handled in threat assessment work, keeping two-factor authentication enabled is strongly recommended for all users. Passwords are stored using hashing algorithms, and all data is encrypted both in transit and at rest.
Note that Dechefr does not save the text that is run through the tool — see "Case archive and data handling" below for details on data handling and the case archive.
3. Assessment overview
The Assessment Overview provides a snapshot of the risk level associated with the analyzed communication, the presence or non-presence of the twelve indicators, and a similarity assessment tool.
The risk level
At the top of the Assessment Overview, Dechefr presents a radial gauge generated from a weighted combination of the risk indicators:
| Level | Description |
|---|---|
| 1 | None or few indicators of violent intention |
| 2 | Some indicators of violent intention |
| 3 | A moderate number of indicators of violent intention |
| 4 | A significant number of indicators of violent intention |
The risk level reflects the number and type of indicators present in the analyzed text. It is not a prediction of future behavior, and the assessment may change as new communications or new context become available.
Indicators of Potentially Violent Behavior
Next to the gauge, the twelve Indicators of Potentially Violent Behavior are listed. Dechefr automatically evaluates each indicator, determining whether it is present. Indicators that are present in the communication are highlighted with a checkmark. The twelve indicators are described in "The assessment framework" below. You can uncheck the checkmark if you do not agree with the assessment.
Similarity assessment
The Similarity Assessment presents a side-by-side, graphical comparison of the risk indicator profiles of two or more communications. Rather than reading each indicator in isolation, you can see at a glance where two texts align and where they diverge across the same set of indicators.
The comparison is built on twelve indicators.
Using the + Add comparison button, you can:
- View profiles side by side for quick visual comparison
- See which indicators the communications share and where they differ
- Compare the analyzed communication against cases from your own archive
Comparing against your own archived cases is particularly useful in nuanced situations — for example, when assessing whether several communications may share an author, or whether a series of communications from the same subject reflects escalation or de-escalation over time. As with the rest of Dechefr, the Similarity Assessment supports your judgment rather than replacing it: a high degree of overlap between two profiles is a prompt for closer review, not a conclusion in itself.
4. Start a review of the assessment
To start a review of the assessment, press Click here in the text box in Indicators of Potentially Violent Behavior (see below). The review will guide you through the assessment.
Reviewing an indicator
For each indicator, you can review Dechefr's analysis of the text. The sentences — and in some cases the specific words — associated with the indicator are presented and highlighted in the text.
- Review the sentences to understand what triggered the indicator. Press the eye symbol to see the sentence in the original text.
- If a specific sentence should not count toward the indicator (for example, quoted material, sarcasm, or jargon common to the subject's environment), you can omit that sentence.
- If a sentence includes characteristics of the indicator, click the checkbox next to the sentence.
- If the case context warrants it — such as known characteristics of the subject including ability, culture, or common use of jargon — you can omit the entire indicator.
- Go to the next indicator by first clicking Yes (if you have marked a sentence) or No (if no sentence is marked and you want to omit the entire indicator), and then clicking Next in the upper right corner.
Modifications are part of the intended workflow, not an exception: the twelve indicators require the application of structured professional judgment that considers the specific context of the case under review. Document your rationale for any modification in the report's comments section.
Complete your assessment
When you reach the last indicator (Legacy and martyrdom creation), a text box appears stating that the assessment is complete. Finalize the assessment by clicking Finalize in the text box. Remember to press Save changes in the upper right corner during your assessment so that a case is created. Throughout the assessment you can change the case name in the upper left corner and save changes as you go.
5. Text characteristics
To the left of the Assessment Overview panel, Text Characteristics provides further data about the analyzed communication.
Word cloud
To give a quick idea of what the text is about, the most frequently used words are displayed in different sizes: the more frequently a word is used, the larger its font size. Hover over a word to see its number of occurrences. Function words (words with little or no meaningful content) are removed before frequencies are calculated. The 20 most frequently used words are displayed.
Named entities
Dechefr automatically extracts named entities from the text, grouped by person(s), organization(s), and location(s) mentioned. Selecting a named entity adds it to a highlighted list on the right of the page. Highlighted entities appear on the generated report, which can assist in prioritizing resource allocation — for example, identifying potential targets or affiliations that need protective attention.
Readability (Flesch–Kincaid)
Text Characteristics includes a Flesch–Kincaid grade level, a readability measure based on word length and sentence length that indicates how difficult a text is to understand. The score can provide insight into the approximate education level — and sometimes age — of the writer, and can assist in questions of authorship across multiple communications or possible deterioration over time.
Supporting values (word count, average letters per word, and average words per sentence) are included. Interpret grade-level scores with caution: grammar-assist tools, AI writing support, and copied text can all distort them.
6. Synopsis
Dechefr can generate a document that provides a general overview of the assessment of the communicated threat. The synopsis is created when you have finalized the assessment. The report consists of the following sections:
- Indicators of Potentially Violent Behavior — present indicators and non-present indicators.
- Preoccupation/Interests.
- All the sentences that are expressed in the different indicators.
- Additional comments — the section in which you can note comments to prompt follow-up, and record outstanding questions, observations, conclusions, and recommendations for mitigation.
Use the Additional comments section to document the rationale for any indicator you modified or omitted, so that the report remains a defensible record of both the automated analysis and your professional judgment.
As a structured professional judgment tool, Dechefr is not intended to be used as the sole source for threat assessment decision-making. The information summarized in the report must be evaluated by the trained threat assessment professional, incorporating additional intelligence, context, and relevant factors.
You can download the synopsis by clicking Download synopsis in the upper right corner.
7. The assessment framework: twelve indicators of violent behavior
Dechefr's twelve indicators are grounded in the research on warning behaviors. For each indicator: its definition, and what to look for when reviewing a communication.
01 — Anger
Expressions that indicate anger in the communication — strong hostility, frustration, or resentment, often aimed at individuals, groups, or institutions.
What to look for
- Aggressive or hostile language
- Insults or personal attacks
- Threats or violent statements
- Emotional intensity, such as excessive punctuation (!!!), use of ALL CAPS, or language conveying rage
02 — Grievance
A perceived sense of injustice or unfair treatment — an unmet need fueling a sense of being wronged that can compel revenge or retribution.
What to look for
- Complaints about unfair treatment or being mistreated
- Statements indicating loss, exclusion, or being denied something "deserved"
- References to revenge, justice, payback, or "setting things right"
- Repeated narratives of victimhood or personal suffering
03 — Othering
Us-versus-them thinking that marginalizes a "them" group as an outgroup — portraying it as inferior, dangerous, or corrupt — which can justify exclusion, discrimination, or violence.
What to look for
- Frequent use of third-person plural pronouns: they, them, those people
- Dehumanizing or belittling language toward a group
- Stereotyping or generalizations
- Claims that a group is corrupt, harmful, or a threat
- Justifications for exclusion, hostility, or violence
04 — Leakage
Communication of an intent to cause harm — directly through explicit threats or indirectly through hints, suggestions, or boasts. May indicate planning, preparation, or justification for future violence.
What to look for
- Direct threats toward a person, group, or location
- Indirect hints such as "you'll see," "something is coming," or "they'll regret this"
- Statements about upcoming actions or plans
- Boasting about the possibility of committing violence
- References to past attackers or violent events as inspiration
- Language that implies justification for harming others
05 — Influences from previous offenders
Admiration for, identification with, or attempts to emulate individuals who have committed acts of violence. References may be direct or subtle, and often reveal ideological alignment or a desire to replicate past actions.
What to look for
- Praise or admiration for known attackers
- References to past acts of violence, including names, dates, or locations
- Mentions of manifestos, videos, or writings left behind by previous offenders
- Discussion of attack methods (e.g., weapons used, tactics, planning details)
- Recognition of attack anniversaries or symbolic dates
- Comparisons between the author's personal situation and that of a known attacker
06 — Warrior mentality
Viewing oneself as a soldier, fighter, or avenger engaged in a personal or ideological battle — often with glorification of violence and military-style language or imagery outside any formal military role.
What to look for
- References to combat, war, missions, or duty
- Language describing the self as a "soldier," "fighter," or "warrior"
- Mentions of weapons, tactical gear, or combat training
- Talk of fighting a "necessary" or "righteous" battle
- Romanticized or heroic portrayals of violence or self-sacrifice
07 — Preoccupation
An intense and ongoing fixation on a specific person, cause, ideology, or grievance — repetitive language and a narrow focus that may suggest escalating emotional investment or obsessive thinking.
What to look for
- Repeated mentions of the same individual, group, topic, belief system, or event
- Obsessive focus on a grievance, perceived injustice, or ideological cause
- Little variation in topic across multiple communications
- Escalating intensity or emotional charge in repeated references
08 — Linguistic alignment
Adoption of radical beliefs that justify hostility or violence toward perceived enemies — expressed through ideological language, group identity, or moral justifications for harm.
What to look for
- Use of known extremist terms, slogans, symbols, or coded language
- References to conspiracy theories or ideological doctrines
- Justifications for violence in the name of a belief system (e.g., religion, politics, race, gender)
- Strong in-group identity vs. a perceived corrupt or dangerous out-group
- Language that portrays violence as necessary, righteous, or overdue
09 — Preparation activities
Statements about acquiring tools, skills, or knowledge that could enable an act of violence — especially when such content appears out of place or escalates over time.
What to look for
- Mentions of combat training, weapons practice, or tactical drills
- References to purchasing or using firearms, explosives, or body armor
- Language about visiting, surveilling, or "checking out" specific locations or individuals
- Discussions of security weaknesses, escape routes, or how to bypass systems
- Sudden or obsessive interest in attack methods, tactical gear, or operational planning
- Any logistical or technical planning that would facilitate violence
10 — Last resort & desperation escalation
A perception that all non-violent options have been exhausted and that action — often violent — is inevitable or urgent. Often expressed as hopelessness, pressure, or a "point of no return."
What to look for
- Language like "I have no other choice," "this is my only way," or "nothing else works"
- References to time pressure, countdowns, or deadlines (e.g., "it's happening tomorrow," "only days left")
- Escalating urgency or determination to act
- A shift from passive frustration to active resolve
- Statements that reject peaceful alternatives or imply inevitability of violence
11 — End-of-life & finality
Expressions suggesting the author is preparing for death, disappearing, or ending their current existence — direct or symbolic, often as farewell messages, legacy content, or signs of detachment.
What to look for
- Phrases like "this is my final message," "you won't see me again," or "goodbye"
- Posts that suggest closure, departure, or death
- References to giving away personal belongings or wrapping up affairs
- Mentions of content that will be discovered after the author is gone
- Symbolic or emotional farewell themes, including goodbye letters or last posts
12 — Legacy & martyrdom
Creating or referencing content designed to outlive the author — to justify violence, explain motives, or ensure the actions are remembered. Reflects a desire for posthumous recognition, ideological impact, or symbolic status.
What to look for
- Mentions of writing a manifesto, final statement, or explanatory video
- Content framed as something to be discovered after the act ("you'll understand later," "this will explain everything")
- References to becoming a symbol, hero, or martyr
- Statements about wanting to be remembered, make history, or leave a permanent impact
8. Case archive and data handling
What Dechefr does not store
To protect the confidentiality of data, Dechefr does not save any text that is run through the tool unless you choose to save it. Your data is not used to train Dechefr and the only one who has access to your data is you.
Your case archive
- The results of each assessment you perform are saved in your own case archive only, allowing you to maintain historic records and to conduct case comparisons (see "Assessment overview" above).
- You can delete cases from your archive at any time.
- Deletion is permanent. Because cases are not maintained on Dechefr's servers, documents deleted from your archive cannot be restored.
Security
All data is encrypted in transit and at rest, passwords are stored using hashing algorithms, two-factor authentication is supported, and the platform undergoes regular third-party-led penetration testing.
9. Glossary
| Term | Definition |
|---|---|
| Affective violence | Impulsive or reactive violence that occurs in response to emotional triggers and is typically unplanned; contrasted with targeted violence. |
| Assessment factor | One of the eight higher-level constructs Dechefr evaluates (emotionality, social index, identification, linguistic alignment, leakage, preoccupation, preparation activities, and mobilization), each comprising one or more indicators. |
| Behavioral threat assessment and management (BTAM) | A systematic, fact-based process for identifying, assessing, and managing individuals who may pose a risk of violence to themselves or others. |
| Case archive | The user's own record of performed assessments, used for historic reference and case comparison. Archived cases are held by the user, can be deleted at any time, and cannot be restored after deletion. |
| Emotionality | A construct assessing the extent to which a subject expresses anger, anxiety, disgust, and grievance in a communication, compared to the general population. |
| Equifinality | The principle that different subjects can engage in similar acts of violence without exhibiting the same pre-attack warning behaviors. |
| Flesch–Kincaid grade level | A readability measure based on word length and sentence length that indicates how difficult a text is to understand; can offer insight into a writer's approximate education level and assist in authorship questions. |
| Risk level | Dechefr's automated risk assignment, generated from a weighted combination of risk indicators and designed to minimize false positives. Expressed as one of four levels. Not a prediction of future behavior. |
| Indicators of Potentially Violent Behavior | The twelve risk indicators specifically associated with lone actors who have mobilized to targeted violence. Each is scored present or not present and can be modified by the professional based on case context. |
| Leakage | Communication to a third party or public audience of intent to do harm to a target. |
| Linguistic alignment | Linguistic cues or markers indicating that a subject is influenced by an ideology or subculture, expressed in Dechefr as percentages of alignment with major extremist groups or causes. |
| Multifinality | The principle that different subjects can share the same risk indicators yet differ in outcome — for example, because situational or personality factors inhibit mobilization to violence. |
| Named entity | A person, organization, or location automatically extracted from the analyzed text. Highlighted entities appear on the report and can assist in prioritizing protective resources. |
| Percentile score | A score illustrating a subject's position relative to a reference population (the general population in Dechefr's datasets), allowing more nuanced interpretation than a raw score. |
| Person of concern | The individual whose communication is the subject of a threat assessment. |
| Preoccupation | Extreme occupation with a person or a cause; corresponds to the concept of fixation in the threat assessment literature. |
| Similarity assessment | An analysis comparing an analyzed communication and user-archived cases. |
| Social index | A construct assessing the extent of self-orientation, othering, social connection, and group orientation in a communication, compared to the general population. |
| Structured Professional Judgment (SPJ) | An assessment approach that combines structured, evidence-based indicators with the informed judgment of trained practitioners, rather than relying on unstructured judgment or purely actuarial scoring. |
| Targeted violence | Violence that is planned and goal-directed toward a specific person, group, or location. |
| Warrior mentality / military terminology | Use of military jargon and adoption of a warrior perspective, including identification with military or law-enforcement paraphernalia or a pseudo-commando identity. |
10. FAQ and troubleshooting
Does Dechefr save the text I analyze?
No. Dechefr does not save any text that is run through the tool. Assessment results are saved only in your own case archive, which you control. Deleted cases cannot be restored.
How much text do I need?
A valid assessment requires 300 or more words. If a single communication is shorter, it may be possible to combine several communications from the same subject — but consider questions of provenance and time span when interpreting the results.
Which languages does Dechefr support?
Dechefr currently analyzes English-language texts. Communications in other languages can be assessed in translation; note in the report that a translation was used, since translation can affect linguistic indicators.
Which file formats can I upload?
Files in .doc, .docx, .txt, or .pdf format. You can also paste text directly into the analysis field.
How long does an analysis take?
From a few seconds to several minutes, depending on the length of the communication.
Is the risk level a prediction of violence?
No. The risk level reflects the indicators present in the analyzed text. It is designed to minimize false positives and to support — not replace — structured professional judgment. It is not a prediction of future behavior.
Can I override Dechefr's assessment of an indicator?
Yes. Select the indicator to review the highlighted sentences, omit specific sentences, or omit the entire indicator if the case context warrants it. Document your rationale in the report's Additional comments section.
Why does an indicator show as present when the text seems benign?
Dictionary- and model-based extraction can be triggered by quoted material, song lyrics, fiction, sarcasm, or jargon that is common in the subject's environment. This is exactly why the review exists: review the highlighted sentences and omit those that do not reflect the subject's own expression.
I have lost access to my two-factor authentication method.
Contact your organization's Dechefr point of contact to have your sign-in settings reset. Do not share authentication codes with anyone.
References
Dechefr is grounded in more than ten years of research on intelligence analysis, terrorism, risk assessment, and threat assessment in digital environments, conducted by the tool's developers and their collaborators. The publications below relate to the research underlying the development of Dechefr.
Lundmark, L., Kaati, L., Silver, J., & Shrestha, A. (2025). When words become warnings: Assessing threats in online spaces. Lecture Notes in Computer Science. Springer.
Lundmark, L., Kaati, L., & Shrestha, A. (2024). Visions of violence: Threatful communication in incel communities. In 2024 IEEE International Conference on Big Data (BigData). IEEE.
Kaati, L., Shrestha, A., & Akrami, N. (2024). Linguistic alignments: Detecting similarities in language use in written communication. In Proceedings of the 2023 IEEE/ACM International Conference on Advances in Social Networks Analysis and Mining (ASONAM '23) (pp. 619–623). Association for Computing Machinery.
Kaati, L., Shrestha, A., & Akrami, N. (2023). General Risk Index: A measure for predicting violent behavior through written communication. In 2023 IEEE International Conference on Big Data (BigData). IEEE.
Kaati, L., Shrestha, A., & Akrami, N. (2022). Predicting targeted violence from social media communication. In Proceedings of the 2022 IEEE/ACM International Conference on Advances in Social Networks Analysis and Mining (ASONAM '22). IEEE.
Kaati, L., Shrestha, A., & Akrami, N. (2022). A machine learning approach to identify toxic language in the online space. In Proceedings of the 2022 IEEE/ACM International Conference on Advances in Social Networks Analysis and Mining (ASONAM '22). IEEE.
Kaati, L., Cohen, K., & Pelzer, B. (2021). Heroes and scapegoats: Right-wing extremism in digital environments. European Commission, Directorate-General for Justice and Consumers, Publications Office.
Pelzer, B., Kaati, L., Cohen, K., & Fernquist, J. (2021). Toxic language in online incel communities. SN Social Sciences, 1, 213.
Shrestha, A., Akrami, N., Kaati, L., Kupper, J., & Schumacher, M. R. (2021). Words of suicide: Identifying suicidal risk in written communications. In 2021 IEEE International Conference on Big Data (Big Data) (pp. 2144–2150). IEEE.
Shrestha, A., Akrami, N., & Kaati, L. (2020). Introducing Digital-7: Threat assessment of individuals in digital environments. In IEEE/ACM International Conference on Advances in Social Networks Analysis and Mining (ASONAM). IEEE.
Shrestha, A., Kaati, L., & Cohen, K. (2020). Extreme adopters in digital communities. Journal of Threat Assessment and Management, 7(1–2), 72.
Shrestha, A., Kaati, L., & Akrami, N. (2019). PRAT - a tool for assessing risk in written communication. In 2019 IEEE International Conference on Big Data (Big Data) (pp. 4755–4762). IEEE.
Akrami, N., Fernquist, J., Isbister, T., Kaati, L., & Pelzer, B. (2019). Automatic extraction of personality from text: Challenges and opportunities. In 2019 IEEE International Conference on Big Data (Big Data) (pp. 3156–3164). IEEE.
Akrami, N., Shrestha, A., Berggren, M., Kaati, L., Obaidi, M., & Cohen, K. (2018). Assessment of risk in written communication: Introducing the Profile Risk Assessment Tool (PRAT). The Hague: European Police Office.
Kaati, L., Lundeqvist, E., Shrestha, A., & Svensson, M. (2017). Author profiling in the wild. In 2017 European Intelligence and Security Informatics Conference (EISIC) (pp. 155–158). IEEE.
Johansson, F., & Kaati, L. (2016). Countering lone wolf terrorism: Weak signals and online activities. In Understanding lone actor terrorism: Past experience, future outlook, and response strategies. Routledge.
Kaati, L., Shrestha, A., & Cohen, K. (2016). Linguistic analysis of lone offenders' manifestos. In 2016 IEEE International Conference on Cybercrime and Computer Forensics (ICCCF) (pp. 1–8). IEEE.
Figea, L., Kaati, L., & Scrivens, R. (2016). Measuring online affects in a white supremacy forum. In Proceedings of the IEEE Intelligence and Security Informatics Conference (IEEE ISI). IEEE. (Authors listed in alphabetical order.)
Johansson, F., Kaati, L., & Sahlgren, M. (2015). Detecting linguistic markers of violent extremism in online environments. In Combating violent extremism and radicalization in the digital era. IGI Global.
Kaati, L., Omer, E., Prucha, P., & Shrestha, A. (2015). Detecting multipliers of jihadism on Twitter. In 2015 IEEE International Conference on Data Mining Workshop (ICDMW) (pp. 954–960). IEEE.
Cohen, K., Johansson, F., Kaati, L., & Mork, C. M. (2014). Detecting linguistic markers for radical violence in social media. Terrorism and Political Violence, 26(1), 246–256.
Brynielsson, J., Horndahl, H., Johansson, F., Kaati, L., Mårtenson, C., & Svenson, P. (2013). Harvesting and analysis of weak signals for detecting lone wolf terrorists. Security Informatics, 2, 11. (Authors listed in alphabetical order.)
Dahlin, J., Johansson, F., Kaati, L., Mårtenson, C., & Svenson, P. (2012). Combining entity matching techniques for detecting extremist behavior on discussion boards. In Proceedings of the International Symposium on Foundations of Open Source Intelligence and Security Informatics.