Skip to main content

Release notes

Changelog

Track the evolution of ClusterHawk with our latest updates, improvements, and fixes.
Version 3.2.0
June 17, 2026

Added

The 3D view now supports the questions analysts actually ask of it: where is this IP, what is in this cluster, and how do I take the answer with me.

  • Find Any IP

    Search for an IP address and the camera flies straight to it, with its details pinned on screen.

  • Click to Pin IP Details

    Clicking a point pins its details (cluster, labels, and scores) with one-click copy, so findings survive the next mouse movement.

  • CSV Export of Selections

    Export the IPs of highlighted clusters (or the entire view) as a CSV, ready for enrichment, blocking lists, or reporting.

  • True-Distance Cluster Links

    Optional links between clusters show which groups are genuinely similar in the full feature space, not just close in the 3D projection. This directly counters the distortion every projection introduces.

  • Per-Cluster Visibility & Selection Stats

    Hide individual clusters from the legend to focus the view, and see live statistics (IP count, mean confidence, top detected labels) for whatever you have highlighted.

Neighborhood Analysis gains a new Evolution view that follows your clusters across recent jobs as living objects: surviving, splitting, merging, appearing, or dissolving from one run to the next.

  • Cluster Flow Diagram

    A flow chart anchored on the job you open, with one column per related job that shares IPs with it, shows how cluster membership moves over time: band thickness reflects how many IPs traveled together, and color shows what happened to them. Flows are drawn between any two jobs that share IPs, even across an intervening job, and jobs that share no IPs are simply left unconnected rather than pretending continuity.

  • Split, Merge, Birth & Death Events

    Every cluster is labeled with its fate (survived, split, merged, newly formed, or dissolved) based on actual shared membership, never on cluster numbering (which can change arbitrarily between runs). Verdicts are only issued when enough shared IPs exist to support them; thin evidence is clearly marked as such.

  • Co-Moving Cohorts

    Groups of IPs that break away and travel together are surfaced as first-class findings. Each cohort card shows its path through your jobs, whether the group stayed together, and exactly how its destination differs from its origin (ports, certificates, vulnerabilities, and shifted model explanations), with the full member list one click away. A group of addresses retooling in lockstep is one of the strongest signals this data can produce.

  • Always Available

    The Evolution view draws on your job history, so it works even when the currently selected job has no transitions of its own.

Explore the similarity structure of your noise at any depth, with risk visible at a glance.

  • Risk-Aware Nodes

    Node coloring now reflects each IP's anomaly standing, consensus flags are marked directly on the graph, and IPs not covered by pairwise analysis are visually distinguished so absence of connections is never mistaken for evidence.

  • Group Collapse & Pivoting

    Collapse groups into single nodes for an uncluttered overview and expand them on click. From any IP, jump straight to its data-table row or pivot to external enrichment sources in one click.

Individual IPv6 addresses are now fully supported across the analysis path: submission, clustering, labeling, anomaly detection, and results display. Dual-stack datasets (mixed IPv4 and IPv6) can be submitted in a single job.

  • Dual-Stack Job Submission

    The Workspace accepts individual IPv6 addresses (e.g., 2001:db8::1) alongside IPv4 addresses and IPv4 CIDR blocks. IPv6 CIDR notation is not supported; enter individual IPv6 addresses instead.

Two new controls on the Neighborhood network graph keep attention on movement instead of mass.

  • Changes-Only Preset

    One click hides the unchanged structure (maintained links and plain membership), leaving only added, removed, and migrating connections on screen. One more click brings everything back.

  • Collapse Stable IPs

    Large neighborhoods of completely stable IPs can be folded into a single compact marker that carries their count, so the IPs that actually changed stand out instead of drowning in a stable crowd. Anything touched by a change always stays individually visible.

A set of new capabilities that turn unattributed noise from a static report into an investigation starting point. It surfaces what to look at first, why it was flagged, and where it almost belongs.

  • High-Priority Shortlist

    The Noise Intelligence overview now opens with the IPs that matter most: those that are both highly anomalous and pattern-correlated with other noise. The "investigate first" list is computed for you instead of being assembled by hand across tabs.

  • Nearest Cluster Match

    Every noise IP is now measured against your existing clusters and reports the closest match with a confidence rating. Borderline IPs that nearly belong to a known cluster become attribution leads instead of dead ends.

  • Anomaly Explanations

    Flagged IPs now show exactly which characteristics drive their anomaly, as an expandable breakdown in the data table and graph. Analysts get a concrete pivot point instead of a bare score.

  • Recurring Signatures

    A new Signatures view mines the noise set for exact recurring combinations of characteristics: shared fingerprints, services, and configurations that overall similarity can miss. These tool-fingerprint-shaped patterns are among the most actionable artifacts in unattributed data.

Changed

Noise Intelligence has been rebuilt around a simple question: how much should you trust each finding? Every grouping now reports how reliable it is, every anomaly is cross-checked and explains itself.

  • Group Reliability Scores

    Every similarity group now carries a stability score showing how consistently the group re-forms when the data is resampled. Strong groups can be trusted as findings; fragile ones are clearly marked so analysts treat them as hints rather than conclusions.

  • Self-Tuning Grouping

    Grouping thresholds now adapt to each dataset's actual similarity landscape rather than using fixed cutoffs. Very uniform data no longer collapses into one giant group, and diverse data no longer produces empty results. The threshold used is always visible alongside each group.

  • Anomaly Consensus

    Anomalies are now cross-checked by multiple independent detection perspectives, with a clear agreement indicator on every IP. A glance tells you whether a flag is a strong consensus worth acting on or a single detector's opinion worth a second look.

Version 3.1.0
May 11, 2026

Changed

Prediction outputs are now richer and more transparent, giving analysts a clearer picture of how confident the model is for every IP, not just a single best-guess label. Each prediction now reflects the full shape of the model's reasoning, making it easier to decide what to act on, what to investigate further, and what to set aside.

  • Top Candidate Matches per IP

    Instead of returning only the single best match, every prediction now includes a ranked shortlist of the most likely clusters for that IP, each with its own confidence score. This surfaces meaningful alternatives when more than one cluster is plausible, so analysts can review the full set of contenders rather than trusting one label blindly.

  • Out-of-Distribution Detection

    Predictions that don't convincingly match anything the model knows are now explicitly flagged as out-of-distribution rather than being assigned a low-confidence label that could mislead downstream tooling. This eliminates a common source of false positives when integrating prediction results into SIEMs, TIPs, and automated workflows.

  • Prediction Quality Indicator

    Every prediction is tagged with a clear quality category so analysts can triage results at a glance without inspecting raw scores: a confident match (one cluster clearly stands out), a close call (two or more clusters are genuinely competing for the same IP), a weak signal (no single cluster dominates and the model spreads its attention thinly across many), or no match at all (the IP doesn't resemble anything the model has learned).

  • Uncertainty Signals

    Each prediction carries additional signals that describe how decisive the model was: how far ahead the top match was over the runner-up, and how spread out the model's attention was across all known clusters. These help distinguish a clean, dominant match from one that only narrowly won.

  • Safer Downstream Integrations

    Low-confidence and out-of-distribution predictions no longer populate the primary match field, preventing weak guesses from silently propagating into joins, exports, and detection rules. Consumers that want the underlying detail can still access the full candidate shortlist.

Version 3.0.8
April 9, 2026

Added

Cluster statistics now break out industrial control systems and database exposure into dedicated sections. This makes the composition of each cluster easier to see at a glance.

Noise analysis now produces more accurate scores and pattern detection for outlier data points.

Changed

Introduced a statistical data enrichment layer before clustering. Your data is now enriched with domain-aware features for deeper context, so each pipeline suits its use case rather than being defined only by its complexity tier.

Version 3.0.7
February 27, 2026

Added

Improved network graph for Neighborhood Analysis with historical job filtering, stability-based filtering, and interactive node inspection.

  • Historical Job Filter

    Filter connections by historical comparison job to explore temporal changes.

  • Stability Range Filter

    Filter nodes by stability range to isolate stable or volatile nodes.

  • Node Details Panel

    Click any node to view stability scores, neighbor changes, and connection details.

  • Label Visibility Toggle

    Toggle node labels on or off for cleaner views of dense graphs.

Improved network graph for Noise Intelligence with better performance, new filtering controls, and interactive node inspection.

  • Anomaly Score Range Filter

    Filter nodes by anomaly score range to isolate specific anomaly bands.

  • Per-Cluster Visibility

    Show or hide individual clusters to focus on specific groups.

  • Node Details Panel

    Click any node to view detailed information including anomaly scores, similarity groups, and cluster features.

  • Multi-Node Selection

    Select multiple nodes to highlight their connections simultaneously.

Force-directed graph visualizations for exploring relationships between clusters, their statistical profiles, and distinguishing features. Shared data points across clusters are visually connected, so cross-cluster patterns are immediately apparent.

  • Cluster Profile Graph

    Hierarchical graph in the Cluster Profiles tab showing clusters connected to their categories, fields, and individual data values. Shared values like common products, vulnerabilities, or certificates link clusters together.

  • Feature Importance Graph

    Hierarchical graph in the Cluster Features tab displaying clusters connected to their distinguishing features and individual values. Node color and size reflect normalized importance scores, and shared values across clusters link them together.

  • Interactive Exploration

    Click any node to highlight its connections across the hierarchy. Hover for detailed tooltips showing values, importance scores, frequency percentages, and interpretations. Filter by importance threshold or shared-only features.

Version 3.0.6
January 12, 2026

Added

Assign custom labels to clusters in completed jobs for easier identification and organization. Labels persist across sessions and are automatically included in prediction results when using trained models.

  • Inline Label Editing

    In the IP Distribution tab, click the edit icon on any cluster card header to add or modify a custom label

  • Label Persistence

    User-defined labels are stored with the job results and preserved when the model is used for predictions.

  • Label Display

    Labels are displayed via a tooltip pattern across analysis components, showing both user-defined and auto-detected labels.

  • Prediction Label Enrichment

    When running predictions with a trained model, cluster labels from the training job are automatically applied to prediction results.

Version 3.0.5
January 9, 2026

Added

Interactive 3D visualization of IP cluster analysis results, with multiple visualization modes and dimensionality reduction techniques for exploring cluster relationships and patterns.

  • Multiple Dimensionality Reduction Methods

    Support for PCA, t-SNE, and UMAP dimensionality reduction methods, so different projection techniques can be compared for the clearest cluster visualization.

  • Convex Hull Rendering

    Semi-transparent convex hull meshes around each cluster in Point Cloud mode with adjustable opacity and wireframe toggle for clear cluster boundary visualization.

  • Orbital IP Positioning

    Golden ratio spiral positioning algorithm in Cluster Spheres mode that positions IPs based on confidence score, with high confidence points near center and low confidence points near sphere surface.

  • Outlier Detection Visualization

    Visual highlighting of outlier IPs in Cluster Spheres mode that are spatially outside their cluster sphere boundary. This helps identify points that may be misclassified or represent edge cases.

Export clustering analysis results as MISP JSON events for direct import into MISP instances with full relationship support. The MISP-native format preserves cluster relationships and supports threat hunting by cluster membership.

  • Annotation Cluster Objects

    Each cluster is exported as an annotation MISP object with proper display name in Event Graph, containing IP addresses as ip-dst attributes with cluster metadata in the object comment.

  • Deduplicated Malware Objects with IP Linking

    Creates single MISP malware object per unique malware family (not per cluster), linked to all relevant clusters via Object References (cluster→malware: related-to, malware→cluster: controls) and specific IPs (malware→IP: communicates-with) for full graph navigation.

  • Malware Tags

    IP attributes with malware labels are tagged with the malware family name (e.g., malware:cobalt-strike) without confidence percentage, supporting multiple tags for IPs with multiple labels.

  • IDS Flag Assignment

    Automatic to_ids flag assignment for IPs in malware-associated clusters and anomalous IPs, enabling direct use in detection systems.

  • Anomaly Comments

    Anomalous IPs include severity level, anomaly score, and percentile in the attribute comment for analyst context.

  • Cluster Display Names

    Each cluster object includes a descriptive name attribute (e.g., "Cluster 0", "Noise") for clear identification in MISP object lists instead of showing UUIDs or IP addresses.

  • IP Label Comments

    IP addresses with detected labels include the label and confidence in the attribute comment (e.g., "Cobalt Strike: 90%") for quick analyst identification.

Version 3.0.4
January 3, 2026

Added

Export clustering analysis results as STIX 2.1 bundles for integration with threat intelligence platforms like MISP and OpenCTI. This enables automated sharing of infrastructure profiling data in an industry-standard format with rich relationships for automated correlation and detection.

  • Infrastructure SDO Modeling

    Each cluster is exported as a STIX Infrastructure object with associated IP Address observables (ipv4-addr or ipv6-addr), preserving cluster groupings and relationships.

  • Infrastructure Type Inference

    Automatically infers STIX infrastructure_types (command-and-control, botnet, exfiltration, anonymization, staging, hosting-malware) based on detected malware labels, products, and cluster features.

  • Malware SDO Generation

    Creates STIX Malware objects for each detected malware family per cluster, with cluster-specific confidence scores and proper malware_types classification (remote-access-trojan, trojan, bot, ransomware, spyware, dropper, backdoor).

  • Indicator SDOs for Anomalies

    Anomalous IPs are exported as STIX Indicator objects in standard STIX format, enabling direct use in TIP detection workflows.

  • Relationship Graph

    Complete STIX relationship mapping: Infrastructure→IP Address (consists-of), Malware→Infrastructure (controls), Malware→IP Address (communicates-with), and Indicator→IP Address (based-on) for full TIP graph navigation.

  • Cluster Descriptions

    Infrastructure objects include cluster quality metrics, top distinguishing features, identified products/CPEs, and malware labels for comprehensive threat context.

  • Grouping SDO

    Grouping SDO that is the root container referencing all analysis objects (Infrastructure, Malware, IP Address Observables, Indicators, Relationships), enabling navigation of related objects in TIP interfaces.

  • IP Observable Context

    IP Address observables (ipv4-addr / ipv6-addr) now include an optional x_clusterhawk_context custom property containing actor labels (e.g., "Cobalt Strike: 90%"), anomaly information (e.g., "HIGH anomaly: score=15.50, percentile=99.5%"), or combined context when both apply.

Version 3.0.3
November 24, 2025

Added

Automatically consolidates clearly equivalent subclusters into a single cluster when they represent the same infrastructure. This reduces duplicate groupings, improves clarity, and makes results easier to investigate.

  • Automatic Consolidation

    When multiple clusters describe the same underlying activity or infrastructure, they are combined into one unified group.

  • Cleaner Cluster Landscape

    Removes unnecessary fragmentation caused by minor variations, resulting in fewer, stronger, and more meaningful clusters.

  • Improved Investigation Flow

    Unified clusters provide clearer context and reduce analyst workload by grouping related infrastructure together.

Version 3.0.2
November 22, 2025

Changed

New Cluster Comparison component with dual comparison capabilities: feature-level and statistical-level analysis. Security analysts can compare clusters across all dimensions in one place.

  • Comparison Framework

    Flexible comparison system with two distinct modes: Features Comparison for SHAP/LIME-based feature importance analysis, and Statistics Comparison for profiling.

  • Features Comparison Mode

    Side-by-side feature importance comparison showing SHAP/LIME values, representative values, frequency analysis, and cluster-specific interpretations. Identifies shared features, unique features, and importance differentials for precise cluster differentiation.

  • Statistics Comparison Mode

    Statistical comparison across organizational profiles, vulnerability analysis, product analysis, certificate analysis, service analysis, naming patterns, and malware indicators for complete cluster profiling.

Adds group feature exploration and group comparison to the Noise Intelligence Analysis component. Analysts can now explore similarity patterns in depth and compare noise intelligence groups directly.

  • Group Features Explorer

    New dedicated interface for exploring all features within similarity and reverse similarity groups. Displays feature names, representative values and importance scores in a tabular format for systematic pattern analysis.

  • Group Comparison Framework

    Comparison system enabling side-by-side analysis of similarity groups, reverse similarity groups, and noise clusters. Provides overlap analysis, unique IP identification, anomaly statistics comparison, and similarity score evaluation for group relationship assessment.

  • Feature Value Display

    Feature display showing actual representative values alongside feature names across all group types. Analysts can see which features matter and what specific values they have within each group.

Version 3.0.1
October 11, 2025

Added

Expanded the default labeling rules library with 50+ new threat actor rules, and added new detection patterns to existing rules. Coverage now includes modern malware families, C2 frameworks, and other threat actors, improving automated threat classification.

  • New Malware Family Rules

    Added detection rules for Misha Stealer, XMRig Monero Cryptominer, Bandit Stealer2, Atlandida Stealer, SpiceRAT, Mystic Stealer, Collector Stealer, and numerous other modern malware families with specific behavioral and technical indicators.

  • Enhanced C2 Framework Detection

    Expanded CobaltStrike, Metasploit, Sliver C2, RedGuard, and other C2 framework rules with additional detection patterns, including specific HTTP headers, certificate patterns, and behavioral indicators for improved accuracy.

  • Stealer Family Coverage

    Added extensive coverage of stealer malware families including Gotham, Lumma, Meduza, Bandit, Atomic, Serpent, Axile, Vector, Mint, Z3us, Rastro, DarkEye, Agniane, and Epsilon stealers with unique identification patterns.

  • RAT and Trojan Detection Rules

    Enhanced detection for Remote Access Trojans (RATs) and trojans including XtremeRAT, Gh0st RAT, NanoCore RAT, DarkComet, Poison Ivy, Remcos, njRAT, and various other trojan families with specific technical fingerprints.

  • Botnet and Cryptocurrency Mining Rules

    Added detection patterns for botnets (Scarab, Echida, Doxerina, Mozi) and cryptocurrency mining malware (XMRig) with specific behavioral and technical indicators for automated threat classification.

  • Security Tool and Framework Detection

    Included detection rules for security tools and frameworks (BurpSuite, Hachcat, MobSF, Empire, CalderaC2).

User rules are now automatically compared with the latest default rules and shows new, updated, or deleted rules. Users can add new rules, update existing ones, or restore deleted rules.

  • Rule Comparison

    Automatically detects differences between user rules and default rules.

  • Rule Management Interface

    Interface to add, update, or restore rules individually.

  • Rule Status Display

    Shows which rules are new, updated, or deleted with rule details.

  • Actions

    Add, update, or restore rules.

Version 2.5.5
October 2, 2025

Added

New analysis component that displays the user-defined job configuration parameters used during clustering and infrastructure analysis, so analysts can see exactly which settings drove the results.

  • Clustering Weights Visualization

    Displays all 14 clustering weight parameters (vulnerability, certificate, JA3/JARM fingerprints, hash, hostname, domain, algorithms, product, HTML, redirects, tags, chain, and data) which were used for that specific job.

Version 2.4.4
September 2, 2025

Added

ClusterHawk now ships and shares prebuilt detection models directly from our team. This expands the platform beyond custom training, giving all users instant access to high-fidelity threat intelligence models.

  • Storm-0940

    First released prebuilt model covering Chinese threat actor Storm-0940. Provides automated attribution of attacker infrastructure and compromised assets, backed by our weighted-ensemble clustering engine.

  • Model Sharing Capability

    Introduced the ability for ClusterHawk to publish and share new pre-trained models. The library will continue to expand to include both state-sponsored and criminal threat actors.

  • Future Coverage

    Roadmap includes APT29, Lazarus Group, ransomware affiliates, and additional intrusion sets, with updates published directly into the expanding model catalogue.

Version 2.4.3
August 26, 2025

Added

New external API for automated threat intelligence integration and bulk IP analysis. Provides secure API key authentication and access to trained clustering models.

  • Job Management

    Create, track, and retrieve jobs with progress updates, estimated completion times, and detailed error handling.

  • SIEM Integration

    Connects with existing SIEM platforms to support threat detection, actor identification, and predictive analysis.

  • Real-Time Threat Evaluation

    Run instant checks against known threat actor patterns for rapid response to new threats and infrastructure changes.

  • Bulk Processing

    Submit large datasets for full-scale threat mapping, with queuing and progress monitoring.

  • Custom Threat Models

    Use pre-trained models or configure your own detection parameters for environment-specific analysis.

Version 2.4.2
August 23, 2025

Changed

Preprocessing pipeline with feature engineering, adaptive parameter optimization, and improved data validation, for better clustering performance

  • Adaptive Feature Processing

    Dynamic feature engineering based on data characteristics, job requirements, and pipeline type with automatic feature selection and optimization

  • Intelligent Feature Selection

    Automatic feature importance calculation and selection for better clustering performance, with real-time feature weight adjustment

  • Real-time Feature Optimization

    Dynamic adjustment of feature weights and parameters during processing based on data quality, cluster stability, and performance metrics

  • Enhanced Data Validation

    Improved input sanitization and data quality assessment with error handling and data integrity verification

  • Performance Optimization

    Faster preprocessing pipeline with better memory management, optimized data structures, and reduced computational overhead

Job queue management system with resource allocation, automatic recovery, and tier-based prioritization for reliable job processing

  • Unified Priority Queue System

    Tier-based job prioritization with enterprise, professional, team, and analyst priority levels for fair resource allocation based on subscription tiers

  • Job Recovery & Persistence

    Queue state persistence with automatic recovery after service restarts, preventing job loss during maintenance or crashes with state tracking

  • Exponential Backoff Retry System

    Retry mechanism with configurable attempts and exponential backoff delays for handling temporary resource unavailability

  • Orphaned Job Detection

    Automatic detection and recovery of stuck PENDING jobs with periodic health checks and re-queuing based on job age and status

Version 2.4.1
August 19, 2025

Added

Executive summary report extracted from the Full Report. It gives decision-makers, security teams, and stakeholders a multi-perspective threat intelligence overview for rapid assessment with actionable intelligence

  • Bottom Line Up Front (BLUF) Summary

    Executive-ready threat characterization with immediate action requirements and critical defensive needs for rapid decision-making

  • Multi-Perspective Threat Assessment

    Analysis addressing operational, defensive, and intelligence perspectives with role-specific action matrices for Security Operations, Threat Intelligence, and Strategic Decision Makers

  • Strategic Risk Assessment Framework

    Quantified risk assessment with business impact analysis, resource allocation recommendations, and strategic considerations for long-term threat management

  • Campaign Assessment Metrics

    Threat actor operational assessment including infrastructure sophistication, operational security maturity, and campaign sustainability projections with defensive posture evaluation

  • Attribution Likelihood Matrix

    Structured attribution assessment with confidence percentages, supporting indicators, and disconfirming evidence for threat actor identification and intelligence collection priorities

  • Infrastructure Profile Summarization

    Consolidated infrastructure profiles including cluster, tier, and threat actor classifications with operational roles, hosting distribution patterns, and distinguishing technical features

Version 2.4.0
July 20, 2025

Added

Anomaly detection system that analyzes the topological structure of clustering results using mathematical concepts including structural tensor analysis, topological charges, and pulsation energies to identify anomalous patterns without requiring training data

  • Detection Engine

    Identifies anomalies without the need for training data by analyzing the intrinsic structural properties of clustering results using topological charge theory and structural integrity assessment

  • Multi-Scale Structural Analysis

    Detects anomalies across multiple temporal and spatial scales using ensemble clustering stability metrics, co-association embeddings, and multi-dimensional structural decomposition

  • Structural Tensor Analysis

    Employs inverse problem solving to extract structural paths and tensor decomposition, revealing hidden anomalous patterns in cluster formation dynamics through mathematical topology

  • Adaptive Weight Optimization

    Dynamically optimizes detection weights based on clear sample identification and structural characteristics, maximizing detection accuracy for specific data patterns and topological configurations

  • Topological Anomaly Detection

    Calculates topological charges, stability measures, and structural winding numbers to identify anomalies that manifest as distortions in the underlying mathematical structure

  • Multi-Pattern Detection Framework

    Identifies diverse anomaly patterns including pulse anomalies, phase jumps, periodic disruptions, topological bifurcations, and structural discontinuities with pattern-specific scoring

  • Kernel Space Analysis

    Uses multiple kernel methods (RBF, polynomial, Laplacian) to capture non-linear anomalous structures in high-dimensional feature spaces with kernel-specific anomaly scoring

  • Explainable Anomaly Intelligence

    Provides detailed explanations for each anomaly score including cluster stability metrics, membership entropy, structural decomposition analysis, and topological charge contributions

Version 2.3.2
July 9, 2025

Changed

Configuration management system that lets users back up, share, and restore their analysis configurations across all major system components, with validation and workflow integration for the full configuration lifecycle

  • Labeling Rules Management

    Export and import functionality for custom labeling rules with validation, supporting structured formats with automatic rule structure verification

  • Clustering Weights Configuration Control

    Full configuration management for clustering weight parameters across all 14 feature dimensions (vulnerability, certificate, JA3/JARM fingerprints, hash, hostname, domain, algorithms, product, HTML, redirects, tags, chain, and data).

  • Validation Framework

    Validation system that checks imported configurations against all structural and range requirements, with error reporting and automatic compatibility checking

  • Enhanced User Experience

    Export/import workflow with clear success/error notifications, backward compatibility support, and automatic configuration preservation during imports

Version 2.3.1
July 4, 2025

Changed

Network visualization platform with multiple layout algorithms, interaction capabilities, and rendering techniques designed for large-scale network analysis and exploration

  • Multi-Algorithm Layout Engine

    Layout system supporting Standard Network visualization, Temporal Cluster View with cluster-centric positioning, and Force-Directed algorithms optimized for large graphs with automatic algorithm selection and layout optimization

  • Interactive Node Selection and Analysis

    Node interaction system with detailed information panels, connection analysis, job correlation data, relationship strength visualization, and contextual information display with expandable detail views

  • Responsive Design and Grid Integration

    Adaptive layout system with responsive grid integration, collapsible detail panels, sticky navigation controls, mobile-optimized interactions, and full integration with the overall analysis interface

Adds filtering, temporal analysis, and anomaly detection to the neighborhood analysis engine, with performance optimization and interactive visualization capabilities

  • Multi-Dimensional Filtering Framework

    Filtering system with quick presets (High Impact, Stable Networks, Cluster Migrations, Volatile IPs), dynamic neighbor count ranges, stability score filtering, temporal trend analysis, and cluster ID selection with real-time filter summary statistics

  • Temporal Trend Analysis Integration

    Temporal pattern recognition with categorization of IPs into stable, declining, improving, and volatile categories, complete with trend statistics, visual indicators, and filtering capabilities for temporal-based analysis

  • Stability Metrics Visualization

    Stability scoring with composite metrics including neighborhood stability, cluster size stability, change magnitude analysis, and cluster transition penalties with detailed explanations and visual progress indicators

Version 2.3.0
June 28, 2025

Changed

Adds certificate analysis and feature differentiation to cluster descriptive statistics, for deeper infrastructure profiling and more detailed insight into cluster composition and characteristics

  • Certificate and TLS Intelligence

    Deep certificate analysis including JA3/JARM fingerprinting, cipher suite profiling, certificate chain analysis, and TLS configuration assessment for cryptographic infrastructure mapping

  • Enhanced Product and CPE Analysis

    Common Platform Enumeration (CPE) analysis with vendor/product/version profiling, application categorization, and technology stack identification for complete software asset inventory

  • Intelligent Positive and Negative Differentiators

    Feature differentiation engine that identifies both positive (overrepresented) and negative (underrepresented) characteristics with lift scoring and prevalence analysis for precise cluster distinction

  • Malware Indicator Profiling

    Malware intelligence analysis including malware type detection, possible beacon identification, watermark analysis, and process injection technique profiling with host-level indicator tracking

  • Enhanced Service and Protocol Analytics

    Detailed service composition analysis with port profiling, protocol categorization, and service stack identification for complete network service intelligence

  • Names and Domain Intelligence

    Hostname, domain, and FQDN analysis with coverage statistics, naming pattern detection, and infrastructure naming convention profiling

Version 2.2.0
June 21, 2025

Added

Converts clustering artifacts into structured job reports, built for cyber threat intelligence teams. Turns data and metrics into actionable intelligence without manual work

  • Full-Spectrum Cluster Intelligence Analysis

    Analysis including SHAP/LIME-ranked features, label consensus, and MITRE technique mappings for complete threat understanding

  • Multi-Perspective Intelligence Framework

    Tailored insights for Infrastructure Owners (exposure and asset analysis), Defenders (detection logic and escalation paths), and Intel Analysts (attribution hints and tooling patterns)

  • Hypothesis Engine

    Competing narrative generation (botnet, APT, broker) backed by structured evidence analysis and disconfirming clues for threat assessment

  • Operational Recommendations Matrix

    Role-specific action matrices with safe-to-deploy detections and targeted mitigations for immediate operational implementation

  • Infrastructure-Tier Analysis

    Detailed cluster portraits with cross-cluster correlation analysis and confidence scoring for stronger threat attribution

  • Anomaly and Mis-Cluster Detection

    Automated identification of potential classification errors and anomalous patterns with detailed explanations for quality assurance

  • Bottom Line Up Front (BLUF) Summaries

    Executive-ready summaries with key findings and immediate action items for rapid decision-making and threat response

  • Ground-Truth Evaluation Integration

    Automatic incorporation of evaluation metrics and confidence assessments to provide reliability context for all analytical conclusions

Version 2.1.0
June 19, 2025

Added

Statistical analysis and profiling system that gives deep insight into both regular clusters and noise intelligence patterns, showing the composition and characteristics of threat infrastructure in detail

  • Overall Cluster Statistical Analysis

    Statistical profiling of regular clusters including organizational profiles, geographic distribution, and infrastructure characteristics

  • Noise Intelligence Statistical Intelligence

    Extended statistical analysis specifically designed for noise clusters, revealing hidden patterns in previously uncategorized threat infrastructure

  • Organizational Profile Analysis

    Detailed breakdown of countries, cities, ISPs, organizations, ASNs, and cloud providers within each cluster for geographic and infrastructure intelligence

  • Differentiating Feature Analytics

    Lift score analysis identifying key features that distinguish each cluster, with cluster prevalence vs. overall prevalence comparisons

  • Integrated Vulnerability Intelligence

    Vulnerability analysis including CVE details, EPSS scores, Known Exploited Vulnerabilities (KEV), and high-risk host identification

  • Names Profile Intelligence

    Hostname, domain, and subdomain analysis providing insights into naming conventions and infrastructure patterns used by threat actors

  • Malware Indicators Profiling

    Malware family classification, threat categorization, and IOC type analysis for each cluster with detailed indicator breakdowns

  • Interactive Statistical Visualization

    Rich, interactive interface for exploring cluster statistics with expandable sections, detailed tables, and data presentation

Version 2.0.0
May 6, 2025

Added

All processing and computation pipelines have been optimized to use GPU acceleration, significantly improving analysis speed and efficiency across all clustering methods

  • Parallel Feature Extraction

    Feature extraction processes now run concurrently on GPU for dramatically reduced preprocessing time

  • Accelerated Neural Network Processing

    All neural network operations now use GPU tensor operations for faster training and inference

  • Real-time Visualization Processing

    Visualization generation now uses GPU compute capabilities for a smoother, more responsive user interface

  • Enhanced Batch Processing

    Optimized memory management for large dataset processing with automatic GPU resource allocation

Version 1.3.0
April 24, 2025

Added

Methodology that transforms traditional "noise" into actionable intelligence. It uncovers sophisticated threats designed to evade detection and gives early warning of emerging attack methodologies

  • Adaptive Re-clustering Engine

    Automatic detection and re-analysis of large noise clusters (>20 IPs) to uncover hidden threat patterns that traditional analysis misses

  • Similarity Analysis Framework

    Similarity scoring to detect subtle relationships

  • Anomaly Detection

    Implementation of an algorithm to identify truly anomalous IPs from noise clusters for prioritized investigation

  • Interactive Noise Intelligence Visualization

    Specialized visualization tools including similarity networks, pattern analysis cards, and secondary cluster distribution charts for analysis of noise data

  • Emerging Threat Discovery

    Proactive identification of new threat methodologies and sophisticated adversary infrastructure designed to evade traditional pattern detection

Version 1.2.0
April 11, 2025

Added

Vulnerability-aware clustering for threat actor analysis

  • Vulnerability Intelligence

    Visualization of vulnerability exploitation patterns, so remediation can be prioritized based on actual attacker behavior

  • Enhanced Clustering Intelligence

    Vulnerability-enriched clustering improves detection accuracy and provides more meaningful threat groupings

Controls for managing user quotas across different subscription levels

  • On-demand quota reset functionality for all subscription tiers

    Users can now reset their quotas at any time without waiting for the billing cycle

  • One-time payment option through Stripe for immediate quota replenishment

    Flexible payment options for users who need to increase their quota immediately

Cluster explainability with detailed feature analysis, available to all subscribers

  • Cluster Feature Analysis

    SHAP and LIME-based identification of top features that define each cluster, with instance-level explanations for representative IPs. This shows what characteristics make each threat cluster unique

  • Interactive Feature Visualization

    Radar charts showing the relative importance of different features within each cluster

  • Detailed Feature Importance Ranking

    Precise importance scores for all defining features to prioritize threat intelligence analysis

  • Noise Cluster Analysis

    Extends analysis to noise clusters to surface potential emerging threats that don't yet fit established patterns

Version 1.1.0
April 9, 2025

Added

Neural network capabilities for processing large IP datasets

  • Ability to detect subtle patterns in datasets of 4,000+ IP addresses

    Pattern detection at scale for enterprise environments

  • Deep pattern recognition using neural encoding

    Complex feature relationship mapping using multi-dimensional encoding techniques

  • Adaptive neural networks that scale with data volume

    Dynamically adjusting network architecture based on input data size and complexity

  • Self-attention mechanism for improved feature learning in high-dimensional data

    Better feature extraction through contextual awareness in the neural model

  • Temperature scaling for better confidence calibration in threat predictions

    More accurate probability estimates for threat assessment

  • Dynamic layer sizing based on input dimensions for optimal model architecture

    Automatically optimized model structures based on input characteristics