top of page

Before the Night in Moscow: Foreseeability vs. Predictability Through a BTAM Lens and Application of the SHIELD Rapid Triage™ Protocol

Updated: Aug 19


Introduction

The homicides of four University of Idaho students in Moscow, Idaho, shook the public not only because of their brutality, but because they reignited a recurring, and often misunderstood, question after targeted violence: Could this have been prevented? That question tends to trigger a search for certainty, who “should have known,” what warning sign “proved” intent, and why no one “predicted” the outcome. Behavioral Threat Assessment and Management (BTAM) offers a different, more operationally useful frame. BTAM is not built to predict the future with confidence, but rather, it is built to recognize when risk becomes reasonably foreseeable based on behavior, context, and trajectory, and to intervene in a way that is proportionate, defensible, and prevention-focused.

 

This article examines the Idaho murders through a BTAM lens to clarify an essential distinction: predictability vs. foreseeability. Predictability asks whether someone could have forecast, with meaningful accuracy, that a specific individual would commit a specific act at a specific time. In rare cases, predictability increases when there is high specificity (e.g., explicit threats, identifiable targets, overt planning). However, predictability typically remains low because human behavior is dynamic and targeted violence is a low–base rate event. Foreseeability is the more relevant standard for BTAM and for legal consideration. It asks whether, given what was known or reasonably knowable at the time, a serious harmful outcome was a plausible feared outcome that warranted structured attention and proportionate controls, even absent certainty that an attack would occur (OSHA, n.d.).

 

The goal here is not to litigate guilt, sensationalize tragedy, or claim perfect hindsight. It is to demonstrate how BTAM translates observable information into defensible prevention steps: identifying potential drivers and stressors, evaluating escalation and “pathway” indicators, assessing access and opportunity, and implementing interventions that reduce vulnerability while additional information is gathered. When the public asks, “Why didn’t anyone see this coming?” the BTAM-informed answer is rarely, “They should have predicted it.” The more accurate and more useful question is: Were there indicators that made severe harm foreseeable, and were there practical points of intervention that could have disrupted the trajectory? 


By anchoring the discussion in foreseeability rather than prediction, the analysis also clarifies what organizations, schools, and communities can reasonably be expected to do, what “reasonable steps” look like, and how BTAM strengthens both prevention and defensibility when the stakes are high.

 

A critical note at the outset: I neither have, nor had, any direct involvement in this case, no access to non-public information, and no role in any investigative, prosecutorial, defense, or university response efforts. This is an analytic piece intended to use a widely known incident as a learning example. The Idaho murders are a valuable case study precisely because they have drawn sustained public attention and professional debate around foreseeability, predictability, and preventability, and because they illustrate how easily the discussion can become anchored to “prediction” rather than structured prevention.

 

Contextual Case Overview

In the early morning of November 13, 2022, four University of Idaho students, Madison Mogen, Kaylee Goncalves, Xana Kernodle, and Ethan Chapin, were found murdered in an off campus home near the university in Moscow, Idaho, launching an intense multi agency investigation that drew sustained national attention. Investigators publicly released limited details early on, while quietly building a case. According to subsequent court filings and reporting, the case focused on a constellation of behavioral and forensic indicators rather than a single, causal factor. The publicly known investigative narrative includes a knife sheath recovered at the scene that was later linked to Kohberger through DNA testing, along with analysis of surveillance and video associated with a white Hyundai Elantra, and cellular records used to examine movement patterns and potential proximity to the area.

 

On December 30, 2022, authorities arrested Bryan Kohberger, then a criminology PhD student at nearby Washington State University, and he was charged with four counts of first degree murder and one count of felony burglary. The case proceeded through extensive pretrial litigation and high media scrutiny, with court records and timelines widely covered as the matter moved toward adjudication.

 

For purposes of this article, this overview provides the minimum context needed to analyze the event through a BTAM frame, a high impact targeted violence incident, a complex investigation built from multiple information streams, and a case that, because of its visibility, has become a reference point in ongoing discussions about what was predictable versus what may have been foreseeable and therefore potentially interruptible with the right structures and information pathways.

 

A Storm Warning

This section synthesizes reported and alleged pre-incident behaviors attributed to Kohberger as described in released investigative documents and subsequent media reporting. These accounts largely reflect witness perceptions, interview summaries, and investigative notes, not adjudicated findings about pre-attack conduct. The purpose is contextual, to illustrate how BTAM practitioners separate low-specificity “concern” information from higher-specificity indicators of boundary testing, fixation, approach, and trajectory.

 

Interpersonal Relations and Engagement with Women at Washington State University

In the months before the homicides, multiple graduate students and faculty reportedly described Kohberger as condescending, conflict-seeking, and particularly disparaging toward women. Witnesses described him as argumentative in class and prone to prolonged verbal sparring with professors, often attempting to position himself as the most dominant or important person in the room. (Boone, 2025; Gainor, 2025) Peers also described repeated “intense staring” that they interpreted as a dominance behavior, and a pattern of positioning himself near women in ways that made them uncomfortable. Several accounts characterized his presence as persistently unsettling rather than simply socially awkward. (Gainor, 2025) 

 

Boundary Intrusions and Controlling Behaviors

In multiple accounts, the most concerning features were not isolated comments but repeated boundary intrusions in ordinary campus settings. A faculty member reportedly told investigators that Kohberger would enter an office where female graduate students worked and physically block the doorway, prompting her to intervene after hearing a student express she “needed to get out.” (Boone, 2025) Other reports described him trailing peers after class, blocking someone’s path when they tried to disengage, or standing close enough to “trap” someone at a desk. One professor reportedly described Kohberger attempting to prevent him from leaving his office, refusing to leave when directed, and then following him into the hallway when the professor tried to end the interaction (Gainor, 2025).

 

Program-Level Concern and Attempts to Address Behavior

Reporting based on the released investigative files indicated the department received multiple complaints about Kohberger’s conduct, including rude and belittling behavior toward women, and that the program held meetings focused on his behavior and expectations. (Boone, 2025). Faculty discussions reportedly included consideration of altering his funding and teaching assistant role because he was viewed as “highly problematic,” and one faculty member was quoted as warning colleagues that if he later became a professor, he could harass, stalk, or sexually abuse students, reflecting the degree of alarm some staff described (Boone, 2025; Gainor, 2025).

 

Informal Protective Actions

Across several accounts, peers described informal protective behaviors that often emerge when a group feels someone’s boundaries are unreliable, such as intercepting him when a woman appeared uncomfortable, inserting themselves into conversations, or acting as a “buffer” between him and a female coworker or student. These narratives are notable because they suggest a shared perception among some peers that normal social exit cues were not reliably respected.

 

Pre-Incident Concerns Near the Victims’ Residence

Separately, released documents and reporting describe pre-incident concerns raised by at least one victim about feeling watched, and unusual observations at the Moscow residence such as a door found ajar or appearing damaged. Reporting emphasizes that these incidents were not confirmed as directly linked to Kohberger, but they became part of the investigative record as potential context around vulnerability and perceived surveillance (Associated Press, 2025).

 

Mental Health Concerns as Context, Not Causation

In later court-related reporting, Kohberger disclosed that he received four diagnoses in February 2025: autism spectrum disorder, obsessive compulsive disorder (OCD), attention deficit hyperactivity disorder (ADHD), and avoidant/restrictive food intake disorder (ARFID), an eating disorder characterized by persistent food avoidance or restriction due to sensory sensitivities, fear of negative consequences like choking or vomiting, or low interest in eating, leading to significant nutritional, weight, or functional impairment without concerns about body image (State of Idaho v. Kohberger, CR01-24-31665, 2025). Kohberger did not claim these diagnoses rendered him incompetent or not of sound mind for purposes of his plea. This information may be relevant for clinical context discussions, but it does not, on its own, explain targeted violence, nor should it be treated as causal (Spargo, 2025).

 

From “Creepy” to Credible: Why Subjective Perception Still Matters in BTAM

Perception, standing alone, is subjective. Terms such as creepy, weird, or unsettling describe an observer’s internal reaction, not an objective fact, and BTAM does not treat those labels as evidence of intent or as a substitute for behavioral assessment. A person’s discomfort may be influenced by individual experience, culture, context, or sensitivity to threat, which is why subjective impressions must be handled carefully and never elevated above observable conduct.

 

The BTAM value of such perceptions lies not in the label itself, but in what prompts it and whether that concern is corroborated. The relevant lesson is one of pattern recognition, not retrospective validation of intuition. When multiple independent observers, across settings and over time, report similar concerns and those concerns can be tied to specific behaviors, such as blocking exits, interfering with disengagement, intrusive proximity, repeated staring, following after class, or persistent contact after clear social cues to stop, the significance comes from the convergence of the reports and the consistency of the conduct. In that context, the subjective descriptor is not the finding, it is merely a cue to examine the underlying behavior more closely.

 

BTAM therefore asks structured, behavior-based questions: Are the same actions being reported by different people? Do the reports describe repeated boundary violations rather than isolated awkwardness? Is the conduct persistent, escalating, or spreading across environments? Are others changing their own behavior in response, seeking buffers, escorts, or other protective adjustments? These questions move the inquiry away from intuition and toward corroboration.

 

This distinction matters because BTAM is designed to identify risk under conditions of uncertainty. A single uneasy interaction may have little meaning. A documented pattern of similar, observable conduct reported by multiple sources is different. It allows a team to move from impression to analysis, from anecdote to pattern, and from fragmented concern to a more reliable understanding of foreseeable harm in the immediate environment.

 

Application of the Pathway to Violence

(Calhoun & Weston, 2003, 2016; Talbot & Dias, 2025).

In BTAM, the pathway-to-violence model is used to organize facts into a multi-interval trajectory, not to claim certainty about an outcome. Talbot and Dias (2025) caution that pathway models should not be read as a fixed, stepwise sequence. In practice, movement toward harm is often nonlinear and iterative, people can advance, pause, regress, or oscillate as stressors shift, consequences land, access changes, and the environment responds. Some individuals show late stage behavior with little visible buildup; others linger in early stages for long periods and then accelerate quickly after a destabilizer. The absence of a clear “later stage” indicator at a given moment therefore does not equal stability, it reflects only what is known at that time. This is why BTAM requires centralized documentation and ongoing reassessment. Pathway analysis is best treated as a living formulation that is updated as new information emerges, with the goal of recognizing directional change and applying timely, proportionate interventions that can disrupt momentum and reduce foreseeable risk (Talbot & Dias, 2025).


The core question that the application of the pathway model aims to answer, is whether there is evidence of movement from early precipitating stressors or grievance-driven dynamics into contemplation, planning, preparation, and approach. The accounts from peers and faculty depict a pattern of conflict-seeking, condescension, and dominance-oriented interactions, particularly toward women, coupled with repeated complaints across observers. BTAM would not treat rudeness as predictive on its own, but it would recognize that persistent antagonism and entitlement, especially when reinforced through repeated clashes, can function as an early driver of escalation in interpersonal violence cases.

 

The next interval asks whether there is evidence of ideation, meaning thoughts of harming others, fantasizing about harm, or framing violence as a solution. Though accessible reports do not clearly document statements of intent to harm specific people or direct expressions of violent ideation, BTAM would still consider the presence of behaviors that can precede ideation such as coercive interpersonal control, repeated boundary intrusions, and persistent unwanted proximity. In many real-world cases, teams must work with incomplete information at this stage, which is precisely why structured documentation and follow-up interviewing matter.

 

The pathway then considers research and planning. Here, BTAM looks for observable behaviors suggesting the person is studying targets, environments, routines, or methods, or rehearsing scenarios. The accessible information reflects interpersonal and boundary behaviors rather than clear planning signals, so a BTAM team would likely code this stage as “insufficient information,” while actively testing for it through additional information gathering. In practice, that means asking structured questions about escalating behaviors, schedule probing, repeated presence in certain locations, attempts to learn routines, or any talk suggesting curiosity moving beyond academic discussion.

 

The fourth interval, preparation, focuses on steps that increase capability or reduce barriers, such as acquiring tools, testing access, arranging transportation, or modifying routines to enable an act. The information depicts, and what BTAM would treat as operationally important, preparation for interpersonal control and access within the campus context, for example, using proximity, blocking exits, lingering near desks, or leveraging a teaching assistant role in ways that peers reportedly experienced as intrusive. Even if those acts are not indicative of preparing for homicide, BTAM recognizes that they are forms of rehearsal for violating boundaries and normalizing coercive dynamics, and they elevate foreseeable risks of harassment, intimidation, and retaliatory behavior.

 

Finally, the pathway model assesses approach behavior, meaning movement toward the target, the target environment, or circumstances where harm becomes more immediately possible. In the reported narratives from Washington State University, approach-like behaviors appear in the form of trailing peers after class, timing exits, and repeated unwanted proximity in offices and work areas. These are not approach behaviors toward a lethal attack, but they are approach behaviors within a harassment or stalking-like frame, where physical closeness and obstruction function as control tactics, and personal boundaries are disregarded. BTAM would treat repeated approach-like conduct, especially when it continues after clear disengagement cues, as a meaningful escalation signal that warrants immediate controls.

 

The BTAM conclusion from this pathway framing is not that the later violence was “predictable” from these campus behaviors alone. It is that the institution plausibly had enough information to recognize an escalating pattern of coercive boundary violations and fixation-like proximity behaviors, which are foreseeable precursors to harm in the environment, and therefore warranted structured assessment, centralized case management, and proportionate mitigation.

 

Application of Pre-Attack Warning Behaviors

(Meloy et al., 2012; Talbot & Dias, 2025)

BTAM also uses pre-attack warning behavior concepts to separate vague discomfort from observable indicators that often show up before targeted violence or other serious harm. When applied to this case, the most salient category is fixation. Multiple reports describe persistent staring, repeated proximity seeking, and a tendency to remain in the general area of people who did not want contact, along with timing exits and following them after class. A BTAM team would document these as fixation-like behaviors because they reflect repeated attention and approach that appears resistant to social cues and avoidance attempts.

 

A second relevant category is novel aggression. BTAM looks for new or increasing acts of intimidation, coercion, or boundary violations that represent a change in baseline or usual behavior. Reports say that when he blocked doorways, trapped people at their desks, got in the way of exits, or refused to let others walk away, it showed a new and more serious form of aggressive behavior because he was using his body to limit someone else’s ability to move freely. Even without overt, physical violence, novel aggression is relevant because it reflects a willingness to impose control in a way that can intensify over time, particularly if the person experiences consequences or rejection. All such behavior is “novel” in that there is no apparent, direct link to the quadruple homicide he would go on to commit.

 

BTAM also screens for leakage, which involves communicating intent, justification, or fascination with a violent outcome to third parties, directly or indirectly, and typically not directly to the intended target(s). In this matter, there is no clear pre-incident evidence of classic leakage about harming the Idaho victims. However, the post-incident comments in the next section may be appreciated as post-offense concern-relevant communications because they suggest identification with the act and cognitive engagement with the offender’s performance. Those statements, if accurately reported, are not pre-incident leakage, but they do illustrate the kind of content BTAM teams treat as meaningful in understanding the dynamics of the offender when occurring prospectively.

 

The model also considers direct threats which are among the higher-specificity indicators because they provide a clearer window into intent and target selection. The available information does not describe Kohberger making direct threats toward identified individuals, which is important. A BTAM team would not invent them but would actively test for their presence through structured interviews and review of prior complaints, communications, and conduct documentation. The absence of a direct threat does not eliminate risk, but it changes how the team calibrates concern and interventions; in many completed attacks, direct threats did not precede targeted attacks.

 

Another warning behavior construct is identification, which can include adopting the role of a predator, aligning with violent actors, or signaling a self-concept tied to dominance or harm. In this case, identification shows up more subtly in the alleged dominance behaviors and the repeated need to control interactions and space, rather than in explicit ideological statements. BTAM would treat that as a hypothesis, not a conclusion, and would look for corroborating indicators such as statements of admiration for offenders, self-referential comparisons, or escalating “predator-like” language, while being careful to avoid confirmation bias. However, additional information would emerge post-incident suggesting the relevance of this concept to Kohberger.

 

Johnston (2025) highlights Kohberger’s reported interest in Elliot Rodger, the 2014 Isla Vista perpetrator whose violence was framed around grievance, rejection, and misogynistic retaliation. According to Johnston, classmates recalled that while Rodger’s case prompted discomfort in many students, Kohberger appeared unusually engaged and “fascinated,” suggesting more than routine academic curiosity. Johnston also discusses the possibility that Kohberger may have examined passages associated with Rodger’s manifesto, and she notes the thematic parallels some commentators have drawn between Rodger’s narrative of resentment in a college-town environment and aspects of the Idaho case. Relatedly, she addresses the unverified “Papa Roger” online posts, emphasizing that if authored by Kohberger, the username and content could reflect an identification dynamic, namely adopting an offender-adjacent role by analyzing the crime in a way that appears to align with, rationalize, or “teach” about offender behavior.

 

Framed within BTAM warning behavior concepts, these points are best treated as potential indicators of identification only when they converge with other corroborated risk signals, such as grievance themes, persistent boundary violations, fixation-like behavior, or escalating hostility. Academic exposure to violent cases is common in criminology and is not inherently concerning; the concern here is the quality and pattern of engagement that may suggest psychological alignment rather than detached study.

 

Finally, BTAM assesses energy burst and last-resort dynamics, meaning sudden increases in activity, agitation, or desperation, often associated with a perceived crisis or narrowing options. The pre-incident WSU information does not strongly document such patterns, though it does describe repeated concerns and potential institutional consequences being discussed. A BTAM team would note that impending disciplinary action and role loss can function as destabilizers in some cases and would treat that as a reason to tighten monitoring, clarify boundaries, and ensure support and accountability are both present.

 

This application supports that the behaviors that matter most aren’t vague opinions about someone, they’re the repeated actions that many different people notice, the way those actions keep happening even after others ask the person to stop, and the way people around them start changing their own behavior to stay safe. A BTAM team uses these constructs to document patterns, calibrate concern, and justify proportionate interventions that reduce foreseeable harms, whether or not a catastrophic outcome is predictable.

 

Post-Incident Shifts and Comments from Peers

Some peers reportedly described behavioral changes in Kohberger after the homicides, including altered phone habits, appearing more disheveled, or avoiding discussion of the murders. One report also described Kohberger making comments about the offender being “pretty good” and speculating the murders might have been a “one and done” event, as relayed in interview summaries (Boone, 2025). Other documents also described digital activity including a search for a police scanner site in the early morning hours of November 13, 2022, and other behavior framed as consistent with monitoring the students’ environment, though these details are part of the broader investigative narrative rather than “pre-incident” conduct (Ruiz & Rumpf-Whitten, 2025).

 

Information Sharing as Prevention Infrastructure

Risk rarely arrives as a clear, complete story. It emerges as fragments scattered across people, offices, and systems. One professor experiences a “difficult” student. A graduate student reports being followed after class. A staff member hears concerns about staring. Another person observes doorway blocking. A coworker feels the need to buffer a colleague. If these remain separate, each fragment can be minimized as an isolated incident, personality conflict, or social awkwardness. In silos, no one sees frequency, persistence, escalation, or patterning. The organization stays trapped in a realm of “not enough to act,” right up until hindsight makes the pattern suddenly obvious.

 

A BTAM model relies on the opposite approach: a single intake channel, a single case record, and a process that consolidates disparate reports into one coherent timeline. A centralized repository is not an administrative convenience; it is a core violence-prevention control. It allows a team to evaluate the whole trajectory rather than evaluating each report as a standalone problem. It reduces gaps created by informal conversations, fragmented documentation, and the assumption that someone else is managing the issue. It also makes responses fairer and more defensible, because decisions are tied to patterns and corroboration rather than a single reporter’s subjective impression.

 

When information is shared, the picture resolves. The team can apply consistent thresholds, identify plausible feared outcomes, implement least-restrictive controls, and reassess as new data arrives. When information is siloed, the picture remains incomplete, interventions are delayed or inconsistent, and the organization is left reacting to fragments instead of managing a trajectory.

 

SHIELD Rapid TriageTM: A Conceptual Application to Pre-Incident Observable Behavioral Risk Indicators

SHIELD Rapid Triage™ (Dias & Talbot, 2026) is a structured intake screening and prioritization tool designed to help teams organize early case information, identify information gaps, guide proportionate interim measures, and support early coordination using known and reasonably available facts. Ratings reflect the information available at the time of triage and are expected to be reassessed as information is verified, developed, or circumstances change. 


SHIELD is not a comprehensive risk assessment and does not predict violence or assign a probability of harm. Rather, it structures early decision-making by helping teams determine what the available information supports, what remains unknown, and what those findings require operationally. It does not replace clinical judgment, comprehensive BTAM processes, Structured Professional Judgment (SPJ), legal or HR review, student conduct procedures, law enforcement response, emergency management, or applicable organizational policies, statutes, or directives.


Because intake information is often incomplete or evolving, users must distinguish between what the available information affirmatively supports and what has simply not yet been established. This distinction is central to the revised SHIELD rating protocol.


Domain Rating Protocol

Each of SHIELD's six domains is rated using four possible designations:

  • 0 - Supported Absence: Reasonably credible information supports that the domain is not present.

  • 1 - Partial Presence: Reasonably credible information indicates that the domain is present to some degree, but the available information does not support clear presence.

  • 2 - Supported Presence: Reasonably credible information clearly supports that the domain is present.

  • U - Unknown: Information necessary to determine whether the domain is absent, partially present, or clearly present is missing or insufficient. 

 

The distinction between 0 and U is particularly important. A rating of 0 is an affirmative finding: available information supports absence. A U is an information-status designation, not a numeric rating, and means the team does not yet possess sufficient information to make that determination. U therefore must not be converted to 0 or 1, averaged into the score, or otherwise interpreted as a degree of presence. 

 

Likewise, a rating of 1 should not be dismissed as insignificant simply because it represents the lowest level of affirmative presence. A 1 means something relevant is actually present. The available information supports the domain to some degree, although the evidence is limited, emerging, incomplete, or insufficiently developed to justify a 2. Operationally, that distinction matters: a 1 can identify precisely where additional inquiry, monitoring, intervention, or reassessment should be focused.

 

SHIELD consists of four risk-enhancing domains and two protective-factor domains:

  • S - Stability: Current destabilization affecting functioning, coping, judgment, impulse control, or self-regulation.

  • H - Harm Potential: Practical capability, access, opportunity, and feasibility relevant to the identified feared outcome.

  • I - Isolation: Functional social disconnection, reduced structured routine, and diminished natural visibility or oversight.

  • E - Escalation & Engagement Pattern: Observable progression or meaningful change in concerning behavior over time, including changes in persistence, boundary crossing, target focus, approach behavior, planning, preparation, or other movement beyond the prior pattern.

  • L - Leverage: Credible supports, relationships, resources, and intervention opportunities that can be activated to engage, stabilize, redirect, or constructively influence the person or situation.

  • D - Deterrence: Credible constraints, accountability mechanisms, oversight, and enforceable controls capable of establishing boundaries, restricting opportunity or access, increasing accountability, or supporting response to violations. 


Retrospective Application to the Moscow Case

Applied retrospectively to Kohberger using only the alleged behavioral information reasonably available before the homicides, the resulting configuration is:


S = U | H = U | I = U | E = 2 | L = 1 | D = 1

The strongest affirmative risk-enhancing signal is Escalation & Engagement Pattern (E = 2). The available information describes repeated reports of persistent boundary violations, unwanted proximity or following, approach-like behavior, increasing intrusiveness, and behavioral persistence across time. Rather than relying on subjective characterizations such as someone being "creepy," this domain focuses attention on observable behavior and progression. The reported pattern aligns with the domain's focus on persistence, boundary crossing, proximity, approach behavior, and meaningful movement beyond an isolated incident. Importantly, however, that concern should not be allowed to inflate unrelated domains. SHIELD requires each domain to be rated independently based on the information relevant to that domain. A concerning overall case does not independently justify increasing individual ratings. 


Accordingly, Stability, Harm Potential, and Isolation are more appropriately rated U rather than 1:

  • For Stability (S = U), the available pre-incident information does not sufficiently establish Kohberger's current functioning relative to baseline, including coping, judgment, self-regulation, or deterioration. Interpersonal conflict or concerning behavior does not, by itself, establish current destabilization.


  • For Harm Potential (H = U), the available information does not sufficiently establish the practical capability, means, access, opportunity, or feasibility relevant to the feared outcome. Harm Potential concerns the existence of a practical pathway to harm, including access, proximity, resources, skills, and opportunity, not simply whether a person is behaving concerningly. 


  • For Isolation (I = U), descriptions of interpersonal difficulties may generate legitimate questions but do not establish functional social disconnection. The domain requires information concerning relationships, structured routine, participation, natural visibility, oversight, and meaningful changes in those areas. 

 

These three U ratings are therefore not reassuring findings. They identify significant gaps in the available case picture.

 

Why the Two Ratings of 1 Matter

The protective-factor domains of Leverage and Deterrence are each rated 1, and these ratings are operationally meaningful. Leverage (L = 1) reflects partial presence. Identifiable institutional leverage points included faculty, program personnel, university resources, peers, supervisory relationships, and opportunities for structured engagement or intervention. The available information does not establish whether these resources were sufficiently accessible, coordinated, activated, or capable of exerting meaningful influence to support clear presence at a 2.

 

Similarly, Deterrence (D = 1) reflects the partial presence of potential accountability and control mechanisms. The university environment provided behavioral expectations, faculty or program authority, reporting mechanisms, potential administrative consequences, and the ability to establish and enforce boundaries. Less clear is whether those controls were coordinated, consistently enforced, salient to Kohberger, or sufficiently robust to support a rating of 2.

 

These low ratings should not be interpreted as inconsequential. 1 means the factor is affirmatively present to some degree; it is not merely suspected or unknown. That creates targeted operational questions. For Leverage: Which relationships or institutional resources could actually influence engagement, stabilization, or behavior? For Deterrence: Which boundaries and consequences existed, were they communicated, and what happened when they were tested?

 

Thus, even a low affirmative rating provides direction. It identifies an existing foothold that may be strengthened, tested, coordinated, or reassessed as the case develops.

 

Interpreting the Configuration: The Score Is Not the Story

Because three domains are U, a complete SHIELD operational score cannot be calculated. The numerically rated domains would produce:

  • Risk Enhancers: E = 2

  • Protective Factors: L = 1 + D = 1

  • Provisional calculation: 2 − 2 = 0

 

However, SHIELD specifically distinguishes an overall operational score of 0 from a domain rating of 0. An overall score of 0 reflects the arithmetic relationship between numerically rated risk enhancers and protective factors; it does not negate the presence of an individual risk-enhancing domain rated 2. Nor should protective factors be interpreted as directly "canceling out" a specific risk enhancer. 

 

More importantly, the presence of three unknown domains means this calculation cannot be treated as a complete priority rating. Depending upon whether the known information is sufficient to establish a reasonable temporary operational priority, SHIELD permits either a Provisional designation or Information Development Required when the unknowns prevent meaningful prioritization:

 

  • The operationally important finding is therefore not simply: Score = 0

  • It is the configuration: S = U | H = U | I = U | E = 2 | L = 1 | D = 1

 

That configuration tells the team something highly actionable. There is clear evidence of behavioral escalation and engagement, partial evidence of available leverage and deterrence, and insufficient information regarding three consequential risk-enhancing domains. The appropriate response is therefore structured information development.

 

From Triage to Targeted Information Development

The clear presence of E = 2 provides a behavioral basis for determining what to explore next rather than merely requesting "more information."

 

For Stability, information development should examine current stressors and losses, changes from baseline, coping and self-regulation, functional deterioration, and the possible significance of shame, humiliation, rejection, or meaningful setbacks.

 

For Harm Potential, inquiry should focus on practical feasibility: means, access, opportunity, proximity, capability, resources, and other pathways through which serious harm could realistically be carried out.

 

For Isolation, the team should seek information about meaningful relationships, changes in social connection, structured routines, peer engagement, interpersonal losses, increasing withdrawal, natural visibility, and, perhaps most importantly, who would notice meaningful change.

 

This illustrates one of the central advantages of structured triage. The protocol does not require the team to already possess a complete case picture before taking meaningful action. Instead, what is known helps organize inquiry into what remains unknown. The question becomes: What does the information we have require us to do next?

 

Potential Preventive Value

This retrospective application cannot establish that SHIELD, or any other triage protocol, would have prevented the Moscow homicides. It can, however, illustrate how structured recognition of the behavioral pattern might have changed the information environment and intervention opportunities preceding the attack. Had the recurrent boundary intrusions, unwanted proximity, following, and approach-like behaviors been consolidated as an E = 2 pattern, several proportionate actions could reasonably have followed:

 

Earlier consolidation of the behavioral pattern. Centralizing reports into a shared case record could have transformed apparently discrete incidents into a visible pattern of frequency, persistence, corroboration, and trajectory. The significance lies not simply in accumulating reports, but in recognizing what emerges when those observations are viewed together.


  • Targeted information development. The three U ratings would have generated specific questions regarding Stability, Harm Potential, and Isolation rather than allowing missing information to be mistaken for absence. This could have included collateral information, records review, inquiry into functional change and relationships, and examination of practical access, opportunity, or capability relevant to emerging concerns.

  • Activation and testing of existing leverage. An L = 1 identifies intervention opportunities already present but incompletely developed. Structured engagement, supervisory involvement, support resources, role clarification, or other institutional interventions could test whether those leverage points were capable of influencing behavior.

  • Strengthening deterrence and behavioral boundaries. A D = 1 similarly identifies existing but potentially underdeveloped controls. Clear behavioral expectations, restrictions on unwanted contact or following, documentation requirements, role or access limitations, and defined consequences could strengthen accountability while providing additional behavioral information.

  • Behavioral testing through intervention. Management itself generates information. Compliance with reasonable boundaries may be stabilizing and informative. Conversely, resistance, circumvention, retaliation, increased persistence, or migration to more covert behavior may alter the case picture and warrant reassessment.

  • Possible identification of higher-specificity information. Structured follow-up may have surfaced information bearing on capability, fixation, surveillance, access, grievance, deterioration, or other factors not apparent in the initial reports. Importantly, the claim is not that such information necessarily existed; rather, the structured triage configuration would have provided a defensible reason to look for it.

  • Increased protective awareness. Where warranted, individuals reporting repeated boundary violations could have received guidance regarding documentation, escalation reporting, safety planning, and changes requiring immediate notification.

 

These interventions might not have prevented the Moscow homicides, particularly given the limits of institutional control over conduct occurring away from campus. Their preventive value lies elsewhere: reducing system lag, connecting fragmented information, developing consequential unknowns, strengthening available leverage and deterrence, and creating opportunities to detect meaningful change.

 

Foreseeability and Duty of Care

In broad U.S. negligence principles, liability typically turns less on whether an institution could predict a specific crime and more on whether harms were reasonably foreseeable and whether the institution took reasonable steps under the circumstances. Negligence is generally framed as a failure to act with the level of care a reasonable person or entity would exercise in similar circumstances, and duty arises where the law recognizes an obligation to act. 

 

When the underlying harm is caused by a third party, many jurisdictions start from a general rule that there is no duty to control another person’s conduct, unless a special relationship, control, or specific circumstances create one. In practice, foreseeability is often evaluated using facts like notice of prior concerning behavior, pattern and escalation, and whether the entity had reasonable, practical control levers to reduce risk. This is exactly where centralized information sharing and structured BTAM protocols strengthen an organization’s duty-of-care posture as they create a consistent mechanism to recognize patterns, document notice, and deploy proportionate risk controls before the harm occurs.

 

When institutions lack a shared repository and reports remain siloed, it becomes much easier for a foreseeable risk pattern to look, on paper, like a series of unrelated minor issues. A BTAM framework, paired with strong information-sharing infrastructure, is designed to prevent that fragmentation and to convert early “subjective” concerns into defensible, behavior-based risk management decisions.

 

Summary

The Idaho student homicides underscore a reality that BTAM practitioners confront routinely: prevention is rarely about predicting a specific act with certainty. It is about recognizing when available information creates a reasonable basis for structured attention, further inquiry, and proportionate action before a trajectory becomes more clearly defined. Cases like this are often framed through the wrong lens in public conversation, a search for a single missed clue that should have made the eventual outcome obvious. BTAM instead asks whether observable behaviors, viewed in context and across time, created a credible basis to consider plausible feared outcomes and implement reasonable risk-reduction measures, even without evidence that a mass killing was imminent.

 

When the pre-incident information is examined behaviorally, the most instructive theme is not a subjective label such as “creepy,” but the cluster of reported boundary intrusions and coercive positioning behaviors described by multiple observers across settings. In isolation, any one report might be interpreted as awkwardness, misunderstanding, or interpersonal conflict. In aggregation, repeated allegations of intimidation dynamics, persistence despite disengagement cues, fixation-like attention, unwanted proximity, and third-party concern reflected in peers buffering for one another begin to form a meaningful behavioral pattern. BTAM treats such a pattern as actionable not because it establishes violent intent, but because persistent boundary unreliability and approach-like behavior warrant explanation, structured review, and proportionate intervention.

 

The SHIELD Rapid Triage™ framework further illustrates why what is unknown can be as operationally important as what is known. In this retrospective application, Escalation & Engagement is clearly present, while Stability, Harm Potential, and Isolation remain unknown because the available information is insufficient to establish either presence or absence. A U is not a zero and should not be interpreted as reassuring. It identifies a specific information gap requiring purposeful development and reassessment. Likewise, partial ratings for Leverage and Deterrence indicate that institutional intervention opportunities and accountability mechanisms existed to some degree, creating practical footholds that could potentially have been strengthened, activated, or tested. 

 

A BTAM-informed response does not require a crystal ball. It requires infrastructure and discipline. Structured triage consolidates reports into a shared case picture, distinguishes supported findings from unknowns, and directs information development toward the domains most relevant to understanding the case. Behavioral formulation then helps teams explore plausible drivers and trajectory without diagnosing or assigning motive. Management strategies can address access, supervision, role suitability, behavioral boundaries, supportive engagement, and interim controls tied directly to observable behavior, with reassessment as circumstances change. These steps are not punitive by default, nor are they predictions of homicide. They are the operational core of prevention: organizing uncertainty, reducing opportunities for harm, constraining concerning behavior, protecting those affected, and documenting decisions in a manner that is consistent, proportionate, and defensible.

 

This is also where the foreseeability conversation becomes most relevant. Foreseeability is not the claim that someone “knew” a quadruple homicide would occur. It is the recognition that a sufficiently established pattern of concerning behavior may create a reasonable basis for protective action within an organization's sphere of responsibility even when the ultimate outcome remains unknowable. Whether legal liability attaches in any particular case depends on jurisdiction, duty, control, notice, causation, and the specific facts. The BTAM lesson is narrower and more operational: prevention depends less on perfect prediction than on whether organizations recognize meaningful behavioral patterns, identify consequential unknowns, use a consistent decision process, and implement proportionate measures based on the information reasonably available at the time.

 

Ultimately, the preventive value of this case study lies not in hindsight certainty but in systems thinking. Risk-relevant information often exists in the spaces between departments, reports, and people who each possess only a fragment of the picture. When information remains siloed, patterns may remain invisible and opportunities for intervention can be delayed. When information is centralized and evaluated through a structured BTAM process, subjective concerns can be translated into observable behavior, knowns can expose important unknowns, and information development can become targeted rather than indiscriminate.

 

The central lesson is therefore not that a low score means low concern, nor that an unknown means absence. It is that structured triage tells us what the information supports, what it does not yet establish, and what we need to do next. BTAM does not promise that every tragedy can be prevented. It does provide a defensible pathway toward earlier recognition, better information development, coordinated management, and a greater opportunity to disrupt concerning trajectories before they culminate in serious harm.


About the Author

Dr. Matt Talbot, PhD, LCSW, CFMHE, CCFC, CTM, is a subject matter expert in behavioral threat assessment, violence risk assessment, forensic mental health, and workplace violence prevention. He has helped develop violence prevention programs for Fortune 50 corporations, major healthcare institutions, and K–12 schools and created the first collegiate certificate in behavioral threat assessment and engagement at Alliant International University. Dr. Talbot previously served as President of the South Central Chapter of the Association of Threat Assessment Professionals and is a renowned public and keynote speaker. He holds a PhD in Forensic Psychology, is a clinically licensed social worker in several states, and is a Certified Threat Manager, Certified Forensic Mental Health Evaluator, and Clinically Certified Forensic Counselor.

 

References
  1. Boone, R. (2025, August 20). Kohberger’s sexist, creepy behavior alarmed university faculty and students before Idaho murders. ABC30. https://abc30.com/post/bryan-kohbergers-sexist-creepy-behavior-alarmed-university-faculty-students-before-idaho-college-murders/17594574/

  2. Calhoun, F. & Weston, S. (2003). Contemporary Threat Management: A Practical Guide for Identifying, Assessing, and Managing Individuals of Violent Intent. Specialized Training Services.

  3. Cornell Law School. (2021). Foreseeability. Legal Information Institute. https://www.law.cornell.edu/wex/foreseeability

  4. Dias, B. & Talbot, M. (in press). SHIELD Rapid Triage. Key Operational Insights.

  5. Gainor, D. (2025, August 19). Bryan Kohberger described as creepy, domineering by college peers in months before Idaho killings, newly released files show. CNN. https://www.cnn.com/2025/08/19/us/kohberger-washington-state-university-peers-police-interviews-hnk

  6. Johnston, J. E. (2025, July 15). A psychological autopsy of Bryan Kohberger: The evidence, the psychology, the plea. Substack. https://joniejohnstonpsyd.substack.com/p/a-psychological-autopsy-of-bryan

  7. Meloy, J.R., Hoffmann, J., Guldimann, A., & James, D. (2012). The role of warning behaviors in threat assessment: an exploration and suggested typology. Behavioral sciences & the law30(3), 256–279. https://doi.org/10.1002/bsl.999

  8. Occupational Safety and Health Administration. (n.d.). Field Operations Manual, Chapter 4: Violations. https://www.osha.gov/fom/chapter-4

  9. Ruiz, M. (2025, February 10). Prosecutors get Bryan Kohberger’s mental health records as he fights death penalty. FOX 13 Seattle. https://www.fox13seattle.com/news/bryan-kohberger-mental-health-records-prosecutors

  10. Ruiz, M., & Rumpf-Whitten, S. (2025, July 24). Newly released documents reveal Bryan Kohberger’s disturbing behavior before Idaho murders. FOX 5 Atlanta. https://www.fox5atlanta.com/news/bryan-kohberger-new-documents-disturbing-behavior

  11. Spargo, C. (2025, September 3). Bryan Kohberger diagnosed with 4 “mental health disorders,” he reveals in handwritten guilty plea. People. https://people.com/bryan-kohberger-mental-health-disorders-autism-11803100

  12. State of Idaho v. Kohberger, B. C. (2024). Defendant’s response to state’s motion in limine re: neuropsychological and psychiatric evidence (Case No. CR01-24-31665). District Court of the Fourth Judicial District of the State of Idaho, County of Ada.

  13. Talbot, M. & Dias, B. (2025). Predators, Posers & Pained Personalities: Defensible and Effective Strategies to Prevent Targeted Violence and Manage Malevolent Behaviors. Key Operational Insights, LLC.

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page