Skip to main content

Platform Documentation

Learn how to use ClusterHawk for IP clustering and threat detection

Search Documentation

1
Submit IPs

Upload your IP addresses of interest through our secure interface. Our platform handles datasets up to 5000 addresses.

2
Analysis

Our deterministic ensemble pipeline analyzes patterns, identifies relationships, and generates threat intelligence automatically — same input, same clusters, same reasoning, every run.

3
Receive reports

Get comprehensive threat intelligence reports with IOCs, YARA rules, and hunting queries.

4
Execute hunting queries

Use our automated hunting query execution service to validate findings and monitor for new threats.

User Guide

Model Training Benefits


Model Training Benefits

All profiling tiers use a proprietary framework that offers significant advantages:

  • Fully Automated Optimization: All parameters, weights, and model selections are dynamically adjusted based on your specific dataset characteristics, eliminating the need for manual tuning
  • Intelligent Feature Engineering: Automatic feature selection and dimensionality reduction techniques ensure that only the most relevant data points influence the analysis
  • Method Diversity: The system evaluates multiple analytical approaches using the proprietary evaluation methodology, automatically selecting and weighting techniques for your specific data. This ensures optimal results without manual configuration.
  • Cluster Quality Assurance: Each generated cluster undergoes thorough evaluation, ensuring that prediction confidence scores can be combined with quality metrics for reliable threat assessment
  • Trustworthy Predictions: When you run prediction jobs with these models, the confidence metrics can be combined with quality evaluations from training to provide actionable intelligence you can trust