Skip to main content

Platform Documentation

Learn how to use ClusterHawk for IP clustering and threat detection

Search Documentation

1
Submit IPs

Upload your IP addresses of interest through our secure interface. Our platform handles datasets up to 5000 addresses.

2
Analysis

Our deterministic ensemble pipeline analyzes patterns, identifies relationships, and generates threat intelligence automatically — same input, same clusters, same reasoning, every run.

3
Receive reports

Get comprehensive threat intelligence reports with IOCs, YARA rules, and hunting queries.

4
Execute hunting queries

Use our automated hunting query execution service to validate findings and monitor for new threats.

User Guide

Prebuilt Configurations


Prebuilt Configurations

ClusterHawk includes several prebuilt configurations optimized for different use cases. These configurations provide a starting point for your analysis and can be customized further based on your specific needs.

Security-Focused Configuration

Best for: Detecting security threats and attack patterns, identifying malicious infrastructure

  • Emphasis: TLS certificates, JA3/JARM fingerprints, vulnerability data, and certificate chains
  • Clustering Weights: High weights on security-related features (JA3: 3.5, JARM: 3.5, Cert: 3.0, Vuln: 2.5)
  • Use Cases: Threat hunting, incident response, malware infrastructure detection, C2 server identification
Threat Hunting Configuration

Best for: Advanced threat hunting with maximum sensitivity for detecting attack infrastructure

  • Emphasis: Maximum sensitivity on behavioral patterns, TLS fingerprints, and attack indicators
  • Clustering Weights: Highest weights on security features (JA3: 4.0, JARM: 4.0, Hash: 3.5, Chain: 3.5)
  • Use Cases: Advanced persistent threat (APT) detection, sophisticated attack infrastructure analysis, zero-day threat hunting
Performance-Optimized Configuration

Best for: Processing large datasets quickly with reduced computational complexity

  • Emphasis: Balanced approach with reduced complexity for faster processing
  • Clustering Weights: Moderate weights with focus on hostname/domain (1.5) and reduced security features
  • Use Cases: Large-scale network monitoring, routine infrastructure analysis, performance-critical environments
Enterprise Scale Configuration

Best for: Large enterprise environments with thousands of assets and complex infrastructure

  • Emphasis: Balanced security and performance for enterprise-scale analysis
  • Clustering Weights: Moderate security focus (JA3: 2.5, JARM: 2.5, Cert: 2.0) with infrastructure emphasis
  • Use Cases: Enterprise security monitoring, compliance analysis, large-scale threat detection
Research Mode Configuration

Best for: Maximum sensitivity for research, analysis, and pattern detection

  • Emphasis: Maximum sensitivity across all features for thorough analysis
  • Clustering Weights: Highest weights on all security features (JA3: 4.5, JARM: 4.5, Vuln: 4.0, Chain: 4.0)
  • Use Cases: Security research, academic analysis, in-depth threat intelligence, detailed infrastructure mapping
Choosing the Right Configuration

Select a prebuilt configuration based on your primary use case:

  • Security Teams: Start with Security-Focused for general threat detection, upgrade to Threat Hunting for advanced analysis
  • Large Organizations: Use Enterprise Scale for balanced performance and security across large infrastructures
  • High-Volume Environments: Choose Performance-Optimized for fast processing of large datasets
  • Research & Analysis: Use Research Mode for maximum sensitivity and thorough pattern detection

You can always customize any prebuilt configuration by adjusting the weights to better match your specific requirements.

Using Prebuilt Configurations

To use a prebuilt configuration:

  1. Navigate to the Configurations tab in your Workspace
  2. Select the prebuilt configuration that best matches your use case
  3. Review and adjust the settings if needed to fine-tune for your specific requirements
  4. Save the configuration to apply it to all future jobs

Prebuilt configurations are a starting point, and you can always modify them to better suit your specific analysis needs and data characteristics.