Skip to main content

Threat infrastructure intelligence

IP blocklists go stale in days. Operators don’t.

ClusterHawk resolves your IOC lists into the operation behind them: infrastructure tiers, durable fingerprints, and hunting queries that keep tracking the operator after every IP rotates.

What ClusterHawk provides

One dataset in. The whole operation out.

An accelerated analysis pipeline that profiles, clusters, labels, and explains infrastructure — every step auditable and reproducible.

Weighted ensemble clustering

Groups IPs by how their infrastructure actually behaves — TLS stacks, certificates, service fingerprints, open ports — not by subnet or geography. Multi-dimensional similarity analysis across 15+ parameters produces operator signatures invisible to manual review. This is the core every other stage builds on.

core · gpu

Infrastructure fingerprinting

JARM, JA3S and HASSH signatures that persist across IP churn.

Actor & cluster labeling

Custom rules turn clusters into named attribution with confidence, extending detection to previously unknown IPs.

Structural Anomaly Detection

Topological outliers surfaced with no training data required — catches infrastructure built to evade pattern-based detection.

Model training & prediction

Train on your own labels, then score new infrastructure with a confidence value per prediction.

Neighborhood analysis

Track how IPs move between clusters over time, with stability scores that flag the durable core of an operation.

Noise intelligence mining

Adaptive re-clustering pulls signal out of the points other tools discard as noise.

Explainable by default

SHAP and LIME show why each call was made — deterministic and auditable, not a black box.

Statistical intelligence

Geographic spread, CVE/EPSS exposure, and malware indicators layered onto every cluster.

Automated threat reports, mapped to MITRE ATT&CK

Every run produces a findings-first report — clusters, attribution, anomalies, and hunting queries — with technique mappings your analysts already speak.

The pipeline

Eight stages, one deterministic run.

Submit a dataset and the same sequence runs every time — so results are reproducible and every finding traces back to its evidence.

01

Ingest & profile

Parse IP metadata — TLS, certs, ports, service stacks — into a feature space.

02

Evaluate & label

Score cluster quality and apply your rules to name actors and tiers.

03

Train or predict

Fit models on your labels and score new infrastructure with confidence.

04

Analyze neighborhoods

Measure movement and stability to find the durable core of an operation.

05

Mine the noise

Adaptively re-cluster discarded points to recover missed signal.

06

Detect anomalies

Surface topological outliers with Structural Anomaly Detection.

07

Explain

Attach SHAP/LIME evidence to every cluster and prediction.

08

Report & export

Ship a MITRE-mapped report plus STIX 2.1, MISP, and SIEM queries.

Team workflows

How Teams Use ClusterHawk

Select your team to see how ClusterHawk fits into your workflow
Challenge

Alert fatigue: hundreds of IPs from SIEM alerts with no time to investigate each manually. Need to separate noise from real threats.

Workflow
1

Upload suspicious IPs from SIEM alerts or threat feeds

2

ClusterHawk groups them by infrastructure characteristics

3

Review cluster quality, features, and anomaly indicators

4

Prioritize and label clusters (e.g., "Suspicious C2")

Reduce triage time from hours to minutes. Scattered IPs become actionable clusters with quality scores and labels that track investigation context.

Fits your stack

Interoperable by design.

Everything ClusterHawk produces leaves in a format your existing tooling already understands.

Export

STIX 2.1

Structured threat intel your platforms ingest natively.

Share

MISP

Push clusters and attribution into your MISP instance.

Automate

Prediction API

Score infrastructure programmatically from your own tools.

Detect

SIEM rules

Fingerprint-based detections that survive IP rotation.

Published casework

Read our research

See how ClusterHawk profiles real-world threat infrastructure, including nation-state campaigns and compromised router networks.

Threat intelligence publications

Start with your own data

See the operation behind your indicators.

Bring a real IOC list to a pilot investigation, or explore a finished analysis first.