NVE Dictionary in Threat Assessment: Avoiding the Online “Decoder Trap”
- Brian Van Brunt, EdD

- 2 days ago
- 6 min read

Threat assessment and BIT/CARE teams increasingly encounter reports that arrive with a screenshot and a question: “Does this mean something?” A student has “764” in a username. Someone references a “lorebook.” A disturbing image contains blood, knives, skulls, or unfamiliar symbols. A parent discovers an online account filled with violent memes. The instinct to decode these signs is understandable, but it can also pull teams in the wrong direction.
The newly released Nihilistic Violence Extremism (NVE) Dictionary, Version 1.0, developed by H. N. Landress, DHS, PhD, offers a useful alternative. The open-access resource contains 153 entries drawn from 29 official, scholarly, law-enforcement, and established research sources addressing NVE, The Com, 764, and adjacent online harm environments. More importantly, the dictionary repeatedly cautions users that it is not a decoder, profile, risk score, or method of determining affiliation. Its governing principle could also serve as a mantra for behavioral threat assessment: start with conduct, not vocabulary.
The problem with “What does this symbol mean?”
BIT/CARE and threat assessment teams are particularly vulnerable to what we might call the decoder trap. A concerning report comes in, team members search an unfamiliar term, discover that it has appeared in an extremist or exploitative community, and the terminology itself begins to drive the assessment.
The NVE Dictionary pushes against that approach. Every entry includes not only a definition and documented context, but two especially important fields: “Does not prove” and “Concern context.” The first identifies conclusions that cannot responsibly be drawn from the term alone. The second directs attention back toward observable conduct. The dictionary explicitly describes those two fields as safeguards against misuse. That distinction maps beautifully onto good threat assessment practice. A symbol can be a lead without becoming a finding.
Consider the number 764. The dictionary identifies 764 as a decentralized online predatory network associated in public sources with grooming, sextortion, coerced self-harm, child sexual abuse material, gore, animal cruelty, status competition, and violence glorification. Yet the same entry immediately notes that “764” appears innocently in addresses, dates, usernames, scores, and countless other settings. Concern rises when the number occurs alongside behaviors such as group invitations, victim files, coerced injury, blood writing, threats, self-harm demands, or praise of attacks.
Imagine, for example, that a faculty member reports that a student's online username contains “764.” That fact by itself should contribute very little to a threat assessment. The team might document it and seek reasonable context, but it should not leap to conclusions about extremism or dangerousness. Now change the facts. The same account contains invitations to restricted online groups, messages directing another person to injure themselves, threats to expose private material unless demands are followed, and photographs apparently being collected as “proof.” The number has not become more dangerous. The behavior surrounding it has changed the case. That is precisely the kind of distinction behavioral threat assessment is designed to make.
A “lorebook” may be fantasy world-building, or something very different
The same caution applies to unfamiliar vocabulary. The dictionary defines a lorebook in this particular harm environment as a compiled digital collection of coerced or exploited victim material that can contain identifying information, sexual content, self-harm, humiliation, gore, or threats. Public sources describe such collections being archived, traded, used as leverage, or treated as status material. Yet “lore” and “lorebook” are also perfectly ordinary terms in gaming, fiction, fandom, and world-building.
For a BIT/CARE team, that difference is enormous. A student talking about the “lorebook” for a fantasy role-playing campaign is not displaying a threat indicator. A student possessing a password-protected collection of materials concerning actual victims, discussing trading those materials, threatening disclosure, or using the files to control another person presents an entirely different behavioral picture. The team’s question should therefore shift from “Does the student use this word?” to “What is the person actually doing?”
Disturbing imagery requires the same discipline
Some of the most difficult reports involve visual material because the images produce an immediate emotional reaction. A cut sign, for example, is defined in the dictionary as a word, name, number, or symbol carved into someone's skin at another person's direction as proof, branding, submission, or status content. Critically, the entry distinguishes that practice from self-injury occurring without another person's direction, tattoos, ordinary writing on skin, or unrelated scars. Concern becomes urgent when injury has been demanded, photographed or livestreamed, linked to an alias, or accompanied by threats, exploitation, blackmail, or escalating instructions.
Similarly, a blood wall refers to an inscription made with blood displaying an extorter's alias or group affiliation. Yet horror imagery, theatrical effects, art materials, and unrelated blood marks do not establish that something is a blood wall. The dictionary recommends urgent medical, suicide-risk, safeguarding, and law-enforcement pathways when the behavior is authentic, demanded, recorded, or connected with a harmful group.
This distinction matters in educational settings. A disturbing piece of student art may warrant a conversation. A photograph showing an actual student being coerced into injuring themselves warrants an entirely different response. The visual resemblance is less important than the behavioral circumstances surrounding its creation.
A practical BIT/CARE application
The dictionary can strengthen team practice in four particularly useful ways:
Use terminology as an investigative prompt, not a risk score. When an unfamiliar phrase or symbol appears, look it up to understand what questions might reasonably follow. Then return to behaviors, relationships, targets, coercion, victimization, preparation, access, timing, and escalation.
Document the surrounding context, not simply the code. The dictionary recommends preserving the smallest lawful context packet: the complete visible phrase or sequence, platform, date, surrounding message, sender, and what behavior followed.
Determine whether the person is a potential aggressor, victim, witness, researcher, or something else entirely. Exposure to harmful material does not establish participation. A student may be coerced, recruited, targeted, observing, researching, or trying to help someone else.
Bring the information back into multidisciplinary assessment. A concerning online artifact may simultaneously raise questions about victimization, suicide risk, sexual exploitation, criminal conduct, stalking, interpersonal violence, or targeted violence. The vocabulary should help the team identify the appropriate professionals and response pathways rather than prematurely attach a single ideological label.
This is also where the dictionary's concept of a “semiotic constellation” becomes useful. Rather than treating one symbol as determinative, the term describes a combination of language, visuals, profile features, relationships, behaviors, and surrounding circumstances whose joint meaning may be more informative than any individual item. Even then, the dictionary emphasizes that this is not a validated predictive score. Escalation should remain grounded in coercion, target specificity, preparation, injury, victimization, or credible threats.
Avoiding false positives is part of threat assessment
One of this resource's strongest features is what it deliberately excludes. The dictionary assigns an X tier to unsupported identification claims, including the idea that a single emoji, a dark aesthetic, a mental-health diagnosis, true-crime interest, or an isolated group name can identify someone as NVE-involved. For example, it specifically warns that skulls, knives, blood imagery, fire emojis, and similar symbols are widely used across gaming, music, humor, art, and ordinary online communication. No stable public one-to-one emoji decoder was identified in the research underlying the dictionary.
It makes an equally important point regarding mental health: a psychiatric or neurodevelopmental diagnosis does not establish extremist affiliation or predict targeted violence. Address clinical needs as clinical needs, while evaluating threatening or harmful behavior through the appropriate multidisciplinary process.
For BIT/CARE teams, these cautions are not merely academic. False positives have consequences. When teams overinterpret dark humor, unusual interests, mental-health conditions, memes, or online aesthetics, they can stigmatize students, damage trust, consume investigative resources, and bury genuinely concerning behavioral changes beneath mountains of noise. Good threat assessment is not only about finding danger. It is also about correctly recognizing when the evidence does not support a conclusion of danger.
Observe. Preserve. Refer.
Perhaps the most useful page in the entire dictionary is the last one. Its guidance is remarkably compatible with the work of BIT/CARE and threat assessment teams: Observe. Preserve. Refer.
Observe and document factual behavior. Preserve only the lawful context and metadata necessary to understand what occurred. Refer the matter through the appropriate safeguarding, suicide-response, threat-assessment, mandated-reporting, or law-enforcement pathway. Do not independently enter private groups, seek prohibited material, circulate graphic content, or label a person based upon vocabulary alone.
The value of the NVE Dictionary is therefore not that it gives teams a secret decoder ring for the darker corners of the internet. In many ways, it does exactly the opposite. It helps practitioners resist the seductive simplicity of decoding.
A number is a data point.
A meme is a data point.
A username is a data point.
A disturbing image is a data point.
Behavior tells the story. For threat assessment and BIT/CARE teams trying to navigate an online environment where language, symbols, identities, and communities mutate rapidly, that may be the resource's most important contribution.
