Threat infrastructure intelligence
IP blocklists go stale in days. Operators don’t.
ClusterHawk resolves your IOC lists into the operation behind them: infrastructure tiers, durable fingerprints, and hunting queries that keep tracking the operator after every IP rotates.
What ClusterHawk provides
One dataset in. The whole operation out.
An accelerated analysis pipeline that profiles, clusters, labels, and explains infrastructure — every step auditable and reproducible.
Weighted ensemble clustering
Groups IPs by how their infrastructure actually behaves — TLS stacks, certificates, service fingerprints, open ports — not by subnet or geography. Multi-dimensional similarity analysis across 15+ parameters produces operator signatures invisible to manual review. This is the core every other stage builds on.
core · gpu
Infrastructure fingerprinting
JARM, JA3S and HASSH signatures that persist across IP churn.
Actor & cluster labeling
Custom rules turn clusters into named attribution with confidence, extending detection to previously unknown IPs.
Structural Anomaly Detection
Topological outliers surfaced with no training data required — catches infrastructure built to evade pattern-based detection.
Model training & prediction
Train on your own labels, then score new infrastructure with a confidence value per prediction.
Neighborhood analysis
Track how IPs move between clusters over time, with stability scores that flag the durable core of an operation.
Noise intelligence mining
Adaptive re-clustering pulls signal out of the points other tools discard as noise.
Explainable by default
SHAP and LIME show why each call was made — deterministic and auditable, not a black box.
Statistical intelligence
Geographic spread, CVE/EPSS exposure, and malware indicators layered onto every cluster.
Automated threat reports, mapped to MITRE ATT&CK
Every run produces a findings-first report — clusters, attribution, anomalies, and hunting queries — with technique mappings your analysts already speak.
The pipeline
Eight stages, one deterministic run.
Submit a dataset and the same sequence runs every time — so results are reproducible and every finding traces back to its evidence.
01
Ingest & profile
Parse IP metadata — TLS, certs, ports, service stacks — into a feature space.
02
Evaluate & label
Score cluster quality and apply your rules to name actors and tiers.
03
Train or predict
Fit models on your labels and score new infrastructure with confidence.
04
Analyze neighborhoods
Measure movement and stability to find the durable core of an operation.
05
Mine the noise
Adaptively re-cluster discarded points to recover missed signal.
06
Detect anomalies
Surface topological outliers with Structural Anomaly Detection.
07
Explain
Attach SHAP/LIME evidence to every cluster and prediction.
08
Report & export
Ship a MITRE-mapped report plus STIX 2.1, MISP, and SIEM queries.
Team workflows
How Teams Use ClusterHawk
Select your team to see how ClusterHawk fits into your workflow
Challenge
Alert fatigue: hundreds of IPs from SIEM alerts with no time to investigate each manually. Need to separate noise from real threats.
Workflow
Upload suspicious IPs from SIEM alerts or threat feeds
ClusterHawk groups them by infrastructure characteristics
Review cluster quality, features, and anomaly indicators
Prioritize and label clusters (e.g., "Suspicious C2")
Reduce triage time from hours to minutes. Scattered IPs become actionable clusters with quality scores and labels that track investigation context.
Fits your stack
Interoperable by design.
Everything ClusterHawk produces leaves in a format your existing tooling already understands.
Export
STIX 2.1Structured threat intel your platforms ingest natively.
Share
MISPPush clusters and attribution into your MISP instance.
Automate
Prediction APIScore infrastructure programmatically from your own tools.
Detect
SIEM rulesFingerprint-based detections that survive IP rotation.
Published casework
Read our research
See how ClusterHawk profiles real-world threat infrastructure, including nation-state campaigns and compromised router networks.
Threat intelligence publicationsStart with your own data
See the operation behind your indicators.
Bring a real IOC list to a pilot investigation, or explore a finished analysis first.