Threat infrastructure intelligence
IP blocklists go stale in days. Operators don’t.
ClusterHawk resolves your IOC lists into the operation behind them: infrastructure tiers, durable fingerprints, and hunting queries that keep tracking the operator after every IP rotates.
What ClusterHawk provides
One dataset in. The whole operation out.
An accelerated analysis pipeline that profiles, clusters, labels, and explains infrastructure — every step auditable and reproducible.
Weighted ensemble clustering
Groups IPs by how their infrastructure actually behaves — TLS stacks, certificates, service fingerprints, open ports — not by subnet or geography. Multi-dimensional similarity analysis across 15+ parameters produces operator signatures invisible to manual review. This is the core every other stage builds on.
core · gpu
Infrastructure fingerprinting
JARM, JA3S and HASSH signatures that persist across IP churn.
Actor & cluster labeling
Custom rules turn clusters into named attribution with confidence, extending detection to previously unknown IPs.
Structural Anomaly Detection
Topological outliers surfaced with no training data required — catches infrastructure built to evade pattern-based detection.
Model training & prediction
Train on your own labels, then score new infrastructure with a confidence value per prediction.
Neighborhood analysis
Track how IPs move between clusters over time, with stability scores that flag the durable core of an operation.
Noise intelligence mining
Adaptive re-clustering pulls signal out of the points other tools discard as noise.
Explainable by default
SHAP and LIME show why each call was made — deterministic and auditable, not a black box.
Statistical intelligence
Geographic spread, CVE/EPSS exposure, and malware indicators layered onto every cluster.
Automated threat reports, mapped to MITRE ATT&CK
Every run produces a findings-first report — clusters, attribution, anomalies, and hunting queries — with technique mappings your analysts already speak.
The pipeline
Eight stages, one deterministic run.
Submit a dataset and the same sequence runs every time — so results are reproducible and every finding traces back to its evidence.
01
Ingest & profile
Parse IP metadata — TLS, certs, ports, service stacks — into a feature space.
02
Evaluate & label
Score cluster quality and apply your rules to name actors and tiers.
03
Train or predict
Fit models on your labels and score new infrastructure with confidence.
04
Analyze neighborhoods
Measure movement and stability to find the durable core of an operation.
05
Mine the noise
Adaptively re-cluster discarded points to recover missed signal.
06
Detect anomalies
Surface topological outliers with Structural Anomaly Detection.
07
Explain
Attach SHAP/LIME evidence to every cluster and prediction.
08
Report & export
Ship a MITRE-mapped report plus STIX 2.1, MISP, and SIEM queries.
Team workflows
How Teams Use ClusterHawk
Select your team to see how ClusterHawk fits into your workflow
Challenge
Alert fatigue: hundreds of IPs from SIEM alerts with no time to investigate each manually. Need to separate noise from real threats.
Workflow
Upload suspicious IPs from SIEM alerts or threat feeds
ClusterHawk groups them by infrastructure characteristics
Review cluster quality, features, and anomaly indicators
Prioritize and label clusters (e.g., "Suspicious C2")
Reduce triage time from hours to minutes. Scattered IPs become actionable clusters with quality scores and labels that track investigation context.
Fits your stack
Interoperable by design.
Everything ClusterHawk produces leaves in a format your existing tooling already understands.
Export
STIX 2.1Structured threat intel your platforms ingest natively.
Share
MISPPush clusters and attribution into your MISP instance.
Automate
Prediction APIScore infrastructure programmatically from your own tools.
Detect
SIEM rulesFingerprint-based detections that survive IP rotation.
Published casework
50 addresses in. A 1,900-node fleet out.
OVERCAST started as 50 validated IPs. ClusterHawk profiled them, and the fingerprint it extracted, a certificate naming convention, two JARM signatures, three JA3S values, pivoted out to roughly 1,900 matching assets across 15 countries, resolved into 40 clusters with six signatures that matched nothing else on the internet at the time.
0
flagged by reputation feedsEvery asset scored clean across all major providers at analysis time. The fingerprints found them anyway.
~800
IPs rotated every two weeksStatic blocklists expire within days against this fleet. The infrastructure fingerprint does not.
38x
expansion from the seed setFifty starting addresses resolved into roughly 1,900 assets, organised into two OS tiers and 40 clusters.
The report is equally explicit about what the evidence does not support: the fleet is assessed as command-and-control-provider infrastructure with stated confidence levels, not attributed to a single actor. Fingerprints identify infrastructure; they do not name the operator behind it.
Start with your own data
See the operation behind your indicators.
Bring a real IOC list to a pilot investigation, or explore a finished analysis first.