Skip to main content

Threat infrastructure intelligence

IP blocklists go stale in days. Operators don’t.

ClusterHawk resolves your IOC lists into the operation behind them: infrastructure tiers, durable fingerprints, and hunting queries that keep tracking the operator after every IP rotates.

What ClusterHawk provides

One dataset in. The whole operation out.

An accelerated analysis pipeline that profiles, clusters, labels, and explains infrastructure — every step auditable and reproducible.

Weighted ensemble clustering

Groups IPs by how their infrastructure actually behaves — TLS stacks, certificates, service fingerprints, open ports — not by subnet or geography. Multi-dimensional similarity analysis across 15+ parameters produces operator signatures invisible to manual review. This is the core every other stage builds on.

core · gpu

Infrastructure fingerprinting

JARM, JA3S and HASSH signatures that persist across IP churn.

Actor & cluster labeling

Custom rules turn clusters into named attribution with confidence, extending detection to previously unknown IPs.

Structural Anomaly Detection

Topological outliers surfaced with no training data required — catches infrastructure built to evade pattern-based detection.

Model training & prediction

Train on your own labels, then score new infrastructure with a confidence value per prediction.

Neighborhood analysis

Track how IPs move between clusters over time, with stability scores that flag the durable core of an operation.

Noise intelligence mining

Adaptive re-clustering pulls signal out of the points other tools discard as noise.

Explainable by default

SHAP and LIME show why each call was made — deterministic and auditable, not a black box.

Statistical intelligence

Geographic spread, CVE/EPSS exposure, and malware indicators layered onto every cluster.

Automated threat reports, mapped to MITRE ATT&CK

Every run produces a findings-first report — clusters, attribution, anomalies, and hunting queries — with technique mappings your analysts already speak.

The pipeline

Eight stages, one deterministic run.

Submit a dataset and the same sequence runs every time — so results are reproducible and every finding traces back to its evidence.

01

Ingest & profile

Parse IP metadata — TLS, certs, ports, service stacks — into a feature space.

02

Evaluate & label

Score cluster quality and apply your rules to name actors and tiers.

03

Train or predict

Fit models on your labels and score new infrastructure with confidence.

04

Analyze neighborhoods

Measure movement and stability to find the durable core of an operation.

05

Mine the noise

Adaptively re-cluster discarded points to recover missed signal.

06

Detect anomalies

Surface topological outliers with Structural Anomaly Detection.

07

Explain

Attach SHAP/LIME evidence to every cluster and prediction.

08

Report & export

Ship a MITRE-mapped report plus STIX 2.1, MISP, and SIEM queries.

Team workflows

How Teams Use ClusterHawk

Select your team to see how ClusterHawk fits into your workflow
Challenge

Alert fatigue: hundreds of IPs from SIEM alerts with no time to investigate each manually. Need to separate noise from real threats.

Workflow
1

Upload suspicious IPs from SIEM alerts or threat feeds

2

ClusterHawk groups them by infrastructure characteristics

3

Review cluster quality, features, and anomaly indicators

4

Prioritize and label clusters (e.g., "Suspicious C2")

Reduce triage time from hours to minutes. Scattered IPs become actionable clusters with quality scores and labels that track investigation context.

Fits your stack

Interoperable by design.

Everything ClusterHawk produces leaves in a format your existing tooling already understands.

Export

STIX 2.1

Structured threat intel your platforms ingest natively.

Share

MISP

Push clusters and attribution into your MISP instance.

Automate

Prediction API

Score infrastructure programmatically from your own tools.

Detect

SIEM rules

Fingerprint-based detections that survive IP rotation.

Published casework

50 addresses in. A 1,900-node fleet out.

OVERCAST started as 50 validated IPs. ClusterHawk profiled them, and the fingerprint it extracted, a certificate naming convention, two JARM signatures, three JA3S values, pivoted out to roughly 1,900 matching assets across 15 countries, resolved into 40 clusters with six signatures that matched nothing else on the internet at the time.

0

flagged by reputation feeds

Every asset scored clean across all major providers at analysis time. The fingerprints found them anyway.

~800

IPs rotated every two weeks

Static blocklists expire within days against this fleet. The infrastructure fingerprint does not.

38x

expansion from the seed set

Fifty starting addresses resolved into roughly 1,900 assets, organised into two OS tiers and 40 clusters.

The report is equally explicit about what the evidence does not support: the fleet is assessed as command-and-control-provider infrastructure with stated confidence levels, not attributed to a single actor. Fingerprints identify infrastructure; they do not name the operator behind it.

Start with your own data

See the operation behind your indicators.

Bring a real IOC list to a pilot investigation, or explore a finished analysis first.