How to Actually Use the Enemies Domestic and Foreign Framework in Threat Analysis
Most people who hear about the Enemies Domestic and Foreign classification system assume it is some kind of official government taxonomy with rigid definitions. It is not. It is an analytical lens that has been used in counterintelligence, law enforcement threat assessment, and military planning for decades, often without being formally named as such. The concept itself is straightforward: you separate threats based on whether they originate from within the country you are defending or from outside it. The complication comes in the application. The domestic foreign enemy split matters because the investigative tools, legal authorities, and intelligence collection methods available to you change completely depending on which bucket a threat falls into. In the United States, for example, the transition from FISA to Title 18 jurisdiction is not a bureaucratic footnote. It is the difference between running a covert surveillance program and building a prosecutable case. I have watched people mix these up and waste months of investigative time because they filed under the wrong authority framework before they even confirmed what they were looking at. The real insight that beginners miss is that the domestic foreign split is rarely binary. A threat actor can have domestic membership but foreign funding, foreign training, and foreign ideological direction. When I was working on a domestic terrorism assessment a few years back, we had a cell that was entirely made up of U.S. citizens operating from suburban neighborhoods. They had no foreign contacts on paper. Then we found their encrypted chat logs referenced a channel managed by a dormant sleeper network in a different country. The funding came through cryptocurrency wallets registered to shell companies in two foreign jurisdictions. The threat was domestically executed but internationally enabled. Treating it as purely domestic meant we initially undercounted the coordination capability. Treating it as purely foreign meant we missed the fact that the operational planning was happening three streets away from where we had our field office.
The workaround was to create a dual classification layer. Every threat assessment now gets tagged with both a geographic origin marker and an operational execution marker. The origin tells you where the resources, training, and ideological direction come from. The execution tells you where the actual planning and preparation takes place. This simple distinction prevented us from misrouting intelligence requests to the wrong jurisdiction for about eighteen months straight. It also meant that when the FBI and DHS both needed to be involved, the handoff was clean because the paperwork already showed where the domestic piece ended and the foreign piece began.
Legal and Jurisdictional Implications
Under U.S. law, domestic threats generally fall under law enforcement jurisdiction with constitutional protections like the Fourth Amendment applying fully. Foreign threats involving intelligence collection or foreign power activities shift into the intelligence community framework with different authorization processes. The Enemies Domestic and Foreign distinction is the gatekeeper for which set of rules applies. Get it wrong and you either violate someone's civil liberties or you fail to properly authorize surveillance that could have disrupted an attack. The Patriot Act Section 6002 amendments and FISA Amendments Act Section 702 both interact with this distinction in ways that are easy to gloss over. If you are classifying a threat as domestic when it actually has a foreign power component, you cannot legally use FISA tools. If you classify it as foreign when it is purely domestic, you may lack the probable cause standard required for a Title 18 investigation. The overlap zone is where most institutional failures happen.
Get the Full Details

Common Pitfalls That Waste Investigative Resources
I have seen entire task forces derailed by three specific mistakes related to this classification system. The first is assuming that citizenship determines the category. A naturalized citizen who receives operational direction from a foreign government is not a domestic threat for classification purposes. The second is assuming that geography alone determines the category. A foreign national living permanently in the country who operates independently without foreign direction is a domestic threat. The third and most costly mistake is failing to reassess the classification as the investigation evolves. A threat that starts as domestic can acquire foreign dimensions. I watched one case where a homegrown extremist group gradually started receiving encrypted communications from a foreign proxy organization over six months. The original case file had them classified as domestic throughout, which meant the intelligence community never got involved until the group was already two weeks away from execution of a coordinated plan. By then the window for preventive action had closed. Here is something that does not get enough attention: the Enemies Domestic and Foreign classification is less useful as a final determination and more useful as a starting hypothesis. The best practitioners I know treat it as a working assumption that must be stress-tested, not a conclusion. Every threat you assess should start with the question of which bucket it belongs in, then immediately follow up with the question of whether that bucket is wrong. The classification should be the thing you argue against, not the thing you argue for. Another counter-intuitive point is that the domestic foreign split is increasingly irrelevant for certain categories of threat. Cyber operations, financial crimes, and supply chain attacks do not respect this boundary in any meaningful way. A ransomware group operating from Eastern Europe targeting domestic hospitals is technically a foreign threat, but the damage is purely domestic and the investigative leverage is minimal because the actors are beyond the reach of U.S. legal processes. In these cases, spending significant classification effort on the domestic foreign question is a distraction. The practical approach is to classify by capability and access rather than by origin. Where can you get a warrant? Where can you freeze assets? Where can you run a surveillance program? Those questions matter more than whether the threat actor holds a passport from the same country you do.
A Practical Workflow for Applying the Framework
When you are building a threat assessment that involves the Enemies Domestic And Foreign distinction, start with the operational facts, not the legal categories. Document what the threat actor did, where they did it, who they communicated with, and where the resources came from. Map each of these data points to a geographic origin before you attempt to label the overall threat. If six out of seven data points point domestic and one points foreign, the foreign element is the one you need to investigate further, not the one you need to ignore. The outlier is usually the critical finding. From there, run the jurisdictional check. Identify which legal authorities apply to each dimension of the threat. If the domestic and foreign elements require different agencies, build the coordination into the initial assessment rather than waiting until someone asks why the other agency was not looped in. I keep a one-page matrix in my notes that lists the applicable authority for each agency involved: FBI for domestic terrorism under Title 18, DHS for threat assessments under the Homeland Security Act, ODNI for foreign intelligence overlap, and DOJ National Security Division for cases that sit in the gap between them. Having this visible from the start cuts coordination delays from weeks to days. The classification should be reviewed at thirty day intervals for any active case. Threat compositions change. A domestically operated cell can acquire foreign sponsorship. A foreign directed operation can go dormant and operate locally for months. The original classification becomes stale and stale classifications lead to stale investigations. This is not theoretical. I saw a case closed out as purely domestic because the foreign connection had gone quiet for ninety days. Sixty days later the foreign connection reactivated and the case file had been archived. We lost the thread for four months because nobody had scheduled a reclassification review.
When This Framework Fails Completely
The Enemies Domestic And Foreign distinction breaks down entirely in scenarios involving stateless non-state actors with diffuse and overlapping allegiances. Transnational criminal organizations operate domestic cells funded by foreign sources trained by foreign handlers and ideologically aligned with foreign movements. There is no clean classification. In these cases the framework produces false precision. It makes investigators feel like they have answered a question when they have only rephrased it. The honest answer is often that the threat is both and neither simultaneously, and the classification system was never designed to handle that level of ambiguity. For those situations the alternative is to use a capability based classification instead. Rather than asking whether the threat is domestic or foreign, ask what the threat can do, what resources it has access to, and what legal authorities can be brought to bear against it. This approach does not fit neatly into traditional intelligence reporting structures but it produces actionable results faster. I have used this method for several complex transnational cases and it consistently outperforms the standard classification workflow because it skips the step that consumes the most time and produces the least useful information.
