Skip to main content

Platform Documentation

Learn how to use ClusterHawk for IP clustering and threat detection

Search Documentation

1
Submit IPs

Upload your IP addresses of interest through our secure interface. Our platform handles datasets up to 5000 addresses.

2
Analysis

Our deterministic ensemble pipeline analyzes patterns, identifies relationships, and generates threat intelligence automatically — same input, same clusters, same reasoning, every run.

3
Receive reports

Get comprehensive threat intelligence reports with IOCs, YARA rules, and hunting queries.

4
Execute hunting queries

Use our automated hunting query execution service to validate findings and monitor for new threats.

User Guide

Your First Analysis


Your First Analysis

Once you've set up your account, follow these steps to start using ClusterHawk for IP clustering and threat detection:

  1. Navigate to the Workspace: This is where you'll configure your settings and submit jobs for IP analysis and clustering
  2. Submit your first analysis job: Select a pipeline type and enter IP addresses for analysis. Not sure which pipeline? Start with Core / Basic clustering: it's the right choice for a first look at any dataset.
  3. Monitor job progress: Track your job in the Active Jobs tab
  4. View results: Once the job completes, go to the Analysis page to explore your results
  5. Check your Dashboard: Monitor your quota usage and recent activities

The following sections provide detailed instructions for each of these steps.