Capabilities-versus-Intent Threat Calculus
Separate what something can do from evidence of what it intends
- Difficulty
- Easy
- Time to result
- ~days to results
- Steps
- 5
- Confidence
- 99%
Elizondo distinguishes a national-security issue from a confirmed threat by separating two questions: what the actor can do and what it intends to do. Demonstrated access or performance establishes capability; hostile purpose requires separate evidence. If intent is unknown, the disciplined conclusion is concern and investigation rather than either panic or dismissal. His muddy-boot analogy makes the mechanism concrete: unexplained entry into a locked home does not prove an attack, but it exposes a security failure worth investigating. Applied elsewhere, the framework produces a calibrated label, identifies the vulnerability revealed by the event, and supports proportionate precautions while more evidence is gathered. It is a decision rule for uncertainty, not a formula that calculates probability or severity.
Origin
Luis Elizondo used this threat-assessment distinction during a discussion of UAP and national security on The Diary of a CEO.
Core principles
- 01Capability and hostile intent are different variables
- 02Uncertainty about intent prevents a definitive threat conclusion
- 03Unknown access can justify concern without proving hostility
- 04Precaution should target the vulnerability revealed by the evidence
How to run it
- 1
Document capability
List only access, performance, or effects that the evidence supports. Keep reported and independently confirmed capabilities visibly separate.
Pro tip Use verbs describing observed behavior rather than labels describing identity.
Watch out A claimed capability is not automatically a demonstrated one.
- 2
Investigate intent
Look for behavior, communication, targeting, or patterns that indicate purpose. Record when the evidence cannot distinguish benign, neutral, or hostile motives.
Watch out Do not infer intent simply from unfamiliarity or superior capability.
- 3
Choose the calibrated label
Call the situation an issue or concern when capability matters but intent remains unknown. Reserve threat language for cases with evidence supporting harmful intent.
Pro tip State the missing evidence that would change the classification.
Watch out Lack of known hostile intent is not proof of safety.
- 4
Locate the vulnerability
Identify what the observed capability bypassed, reached, or disrupted. Focus immediate work on understanding and reducing that exposure.
Pro tip Ask how the muddy footprints got into the locked house.
- 5
Respond proportionately
Gather more evidence and apply precautions matched to the supported risk. Update the classification when new capability or intent evidence appears.
Watch out Concern should not become certainty through repetition.
In the wild
Elizondo asks the host to imagine finding large muddy footprints in a living room after locking the doors, windows, and alarm. Nobody is hurt and nothing is missing, so harmful intent is unproven; nevertheless, the unexplained access demonstrates a vulnerability.
→ The homeowner investigates the entry path without claiming that a confirmed attack occurred.
Common mistakes
Equating capability with hostility
The ability to cause harm does not by itself establish an intention to do so.
Treating unknown intent as safety
Uncertainty still warrants investigation when meaningful access or capability has been demonstrated.
Is it for you?
Best for
Security and risk decisions involving an actor with observable access or capability but uncertain motives.
Not ideal for
Situations where hostile action is already underway and immediate protective action is required.
From the transcript
“It's capabilities versus intent.”
“We have seen some of the capabilities. We have no idea the intent.”
From the episode
Ex-Pentagon Official: The U.S Isn't Telling The Truth! Top-Secret UFO Encounters Finally Uncovered! They're Trying To Silence Us!