Follow these steps to get started with professional threat intelligence analysis
1
Submit IPs
Upload your IP addresses of interest through our secure interface. Our platform handles datasets up to 5000 addresses.
2
Analysis
Our deterministic ensemble pipeline analyzes patterns, identifies relationships, and generates threat intelligence automatically — same input, same clusters, same reasoning, every run.
3
Receive reports
Get comprehensive threat intelligence reports with IOCs, YARA rules, and hunting queries.
4
Execute hunting queries
Use our automated hunting query execution service to validate findings and monitor for new threats.
User Guide
Prebuilt Configurations
Prebuilt Configurations
ClusterHawk includes several prebuilt configurations optimized for different use cases. These configurations provide a starting point for your analysis and can be customized further based on your specific needs.
Security-Focused Configuration
Best for: Detecting security threats and attack patterns, identifying malicious infrastructure
Emphasis: TLS certificates, JA3/JARM fingerprints, vulnerability data, and certificate chains
Clustering Weights: High weights on security-related features (JA3: 3.5, JARM: 3.5, Cert: 3.0, Vuln: 2.5)
Use Cases: Threat hunting, incident response, malware infrastructure detection, C2 server identification
Threat Hunting Configuration
Best for: Advanced threat hunting with maximum sensitivity for detecting attack infrastructure
Emphasis: Maximum sensitivity on behavioral patterns, TLS fingerprints, and attack indicators
Clustering Weights: Highest weights on security features (JA3: 4.0, JARM: 4.0, Hash: 3.5, Chain: 3.5)
Select a prebuilt configuration based on your primary use case:
Security Teams: Start with Security-Focused for general threat detection, upgrade to Threat Hunting for advanced analysis
Large Organizations: Use Enterprise Scale for balanced performance and security across large infrastructures
High-Volume Environments: Choose Performance-Optimized for fast processing of large datasets
Research & Analysis: Use Research Mode for maximum sensitivity and thorough pattern detection
You can always customize any prebuilt configuration by adjusting the weights to better match your specific requirements.
Using Prebuilt Configurations
To use a prebuilt configuration:
Navigate to the Configurations tab in your Workspace
Select the prebuilt configuration that best matches your use case
Review and adjust the settings if needed to fine-tune for your specific requirements
Save the configuration to apply it to all future jobs
Prebuilt configurations are a starting point, and you can always modify them to better suit your specific analysis needs and data characteristics.
Cookie Notice
We use essential cookies to provide core functionality for authentication and payment processing. These cookies are necessary for the website to function properly and cannot be disabled. We do not use any non-essential cookies for analytics or tracking. For more information, please read our Privacy Policy.