Skip to main content

Platform Documentation

Learn how to use ClusterHawk for IP clustering and threat detection

Search Documentation

1
Submit IPs

Upload your IP addresses of interest through our secure interface. Our platform handles datasets up to 5000 addresses.

2
Analysis

Our deterministic ensemble pipeline analyzes patterns, identifies relationships, and generates threat intelligence automatically — same input, same clusters, same reasoning, every run.

3
Receive reports

Get comprehensive threat intelligence reports with IOCs, YARA rules, and hunting queries.

4
Execute hunting queries

Use our automated hunting query execution service to validate findings and monitor for new threats.

User Guide

Clustering Basics


Understanding IP Clusters

IP clustering is a technique for grouping IP addresses based on their behavior patterns, infrastructure characteristics, service attributes, and other features. This helps identify patterns that might indicate related infrastructure or potentially malicious activity.

Clustering Feature Types

The system uses a rich set of features to identify meaningful IP clusters:

  • Behavioral Features: How IPs interact with services, access patterns, and frequency of connections
  • Infrastructure Features: Hosting providers, ASNs, network ranges, and deployment patterns
  • Service Attributes: Open ports, service types, software versions, and response patterns
  • TLS Characteristics: Certificate attributes, cipher suites, and cryptographic fingerprints
  • Geographic Indicators: Physical locations, regional patterns, and geospatial relationships
  • Vulnerability Profiles: Shared vulnerabilities, common CVEs, and similar security postures
  • and more
Benefits of IP Clustering
  • Pattern Identification: Discover groups of IPs behaving similarly without prior knowledge of their nature
  • Anomaly Detection: Identify outliers that don't fit into clusters, which may indicate unusual behavior
  • Scalable Analysis: Process large volumes of IP data to find patterns that would be impossible to detect manually
  • Proactive Security: Identify potential threats before they cause harm by recognizing suspicious behavior patterns
  • Infrastructure Mapping: Understand relationships between different infrastructure components and how they might be connected
  • Attribution Support: Help identify and group infrastructure potentially associated with specific threat actors