Skip to main content

Platform Documentation

Learn how to use ClusterHawk for IP clustering and threat detection

Search Documentation

1
Submit IPs

Upload your IP addresses of interest through our secure interface. Our platform handles datasets up to 5000 addresses.

2
Analysis

Our deterministic ensemble pipeline analyzes patterns, identifies relationships, and generates threat intelligence automatically — same input, same clusters, same reasoning, every run.

3
Receive reports

Get comprehensive threat intelligence reports with IOCs, YARA rules, and hunting queries.

4
Execute hunting queries

Use our automated hunting query execution service to validate findings and monitor for new threats.

User Guide

Noise Intelligence Mining


Noise Intelligence Mining

Noise Intelligence Mining is a feature that uncovers hidden threat patterns within noise data that traditional analysis might overlook.

How It Works

When a noise cluster exceeds a minimum size threshold, the system automatically triggers a specialized analysis workflow:

  • Adaptive Re-analysis: The system isolates IPs marked as noise and applies a proprietary secondary analysis specifically optimized for detecting subtle patterns among outliers.
  • Rare Pattern Recognition: The system identifies common anomalous characteristics that might be rare in the overall dataset but shared among subsets of noise IPs
  • Similarity Analysis: Similarity scoring techniques identify relationships invisible to primary clustering.
  • Anomaly Detection: A specialized algorithm identifies truly anomalous IPs within the noise for prioritized investigation. It distinguishes between:
    • Genuine statistical outliers with no meaningful patterns
    • Potential emerging threats with subtle shared characteristics
    • Sophisticated adversary infrastructure designed to evade pattern detection
Benefits of Noise Intelligence Mining
  • Emerging Threat Identification: Discover new threat patterns in their early stages before they become widely recognized or documented
  • Evasion Technique Detection: Identify adversaries who deliberately design infrastructure to evade pattern recognition
  • Greater Intelligence Value: Extract actionable insights from data traditionally discarded as noise, which increases the value of your analysis
  • Proactive Defense: Recognize subtle indicators of new attack methodologies before they become widely deployed. Early recognition gives your security team a time advantage