Skip to main content

Platform Documentation

Learn how to use ClusterHawk for IP clustering and threat detection

Search Documentation

1
Submit IPs

Upload your IP addresses of interest through our secure interface. Our platform handles datasets up to 5000 addresses.

2
Analysis

Our deterministic ensemble pipeline analyzes patterns, identifies relationships, and generates threat intelligence automatically — same input, same clusters, same reasoning, every run.

3
Receive reports

Get comprehensive threat intelligence reports with IOCs, YARA rules, and hunting queries.

4
Execute hunting queries

Use our automated hunting query execution service to validate findings and monitor for new threats.

User Guide

Proprietary Frameworks


Understanding Proprietary Frameworks

ClusterHawk uses a proprietary evaluation framework to assess clustering quality and algorithm performance. To protect its intellectual property while maintaining transparency, it uses codenames for different metrics and methods.

Important Note: The metrics and clustering methods referenced by these codenames are modified versions of publicly available techniques. ClusterHawk's proprietary implementations add improvements and customizations built specifically for IP clustering and threat detection scenarios. These modifications are not available in standard implementations and are part of ClusterHawk's core intellectual property.

Metrics Framework Overview

ClusterHawk's evaluation framework assesses clustering quality across multiple dimensions:

  • Quartz: Cluster stability and formation quality assessment
  • Obsidian: Cluster separation measurement
  • Topaz: Cluster density and distribution pattern evaluation
  • Onyx: Inter-cluster distance and relationship assessment
  • Sapphire: Intra-cluster similarity and cohesion measurement
  • Emerald: Alternative separation assessment method
  • Jade: Alternative density evaluation approach
  • Amethyst: Cluster internal cohesion and structure measurement
  • Amber: Feature importance scoring for cluster differentiation
  • Ruby: Noise analysis encoded similarity measurement
  • Opal: Noise analysis categorical feature matching
Clustering Method Codenames

The ensemble clustering system uses multiple algorithms, each dynamically evaluated and weighted based on your specific dataset:

  • Orion: Clustering approach with dynamic parameter optimization
  • Lyra: Alternative clustering methodology with adaptive settings
  • Cygnus: Specialized clustering technique with dataset-specific tuning
  • Draco: Clustering approach with dynamic optimization
  • Phoenix: Specialized clustering method with adaptive parameters
  • Hydra: Alternative clustering technique with dynamic evaluation
  • Vela: Noise anomaly detection method for identifying outliers
  • Pyxis: Secondary grouping method that relates outliers by characteristics normally overlooked in clustering
Framework Component Codenames

Core framework components also use codenames for consistency:

  • Aether: Cluster confidence assessment system
  • Ignis: Ensemble cluster assignment
  • Aqua: Cluster labeling system
Dynamic Evaluation System

All metrics and methods in the framework are dynamically calculated and evaluated based on your specific dataset:

  • No Fixed Hierarchies: All metrics are equally important and calculated based on data characteristics
  • Dataset-Driven: Method performance and metric values adapt to your specific IP clustering data
  • Dynamic Weighting: Algorithm weights are automatically adjusted based on dataset patterns
  • Contextual Evaluation: Each metric provides insights relevant to your specific analysis
Interpreting Metric Values

Understanding how to interpret these metrics helps you assess clustering quality:

  • High Values (0.7-1.0): Excellent performance in that metric dimension
  • Medium Values (0.4-0.7): Good performance with room for improvement
  • Low Values (0.0-0.4): Poor performance indicating potential issues
  • Negative Values: May indicate instability or poor clustering formation
Using Metrics for Decision Making

These metrics help you make informed decisions about your clustering results:

  • Cluster Quality Assessment: Use Quartz to identify well-formed vs. problematic clusters
  • Separation Analysis: Obsidian and Emerald help identify overlapping or poorly defined clusters
  • Density Evaluation: Topaz and Jade reveal whether clusters are appropriately sized and distributed
  • Overall Confidence: Combined metrics provide overall confidence in clustering results
Framework Benefits

ClusterHawk's proprietary framework provides several advantages:

  • Evaluation: Multiple dimensions ensure thorough quality assessment
  • Consistent Standards: Standardized metrics enable comparison across different analyses
  • Actionable Insights: Clear metrics help identify areas for improvement
  • Quality Assurance: Systematic evaluation reduces false positives and improves reliability

Understanding these codenames helps you interpret clustering results, make informed decisions about your analysis, and keep ClusterHawk's proprietary algorithms secure.