Skip to main content

Platform Documentation

Learn how to use ClusterHawk for IP clustering and threat detection

Search Documentation

1
Submit IPs

Upload your IP addresses of interest through our secure interface. Our platform handles datasets up to 5000 addresses.

2
Analysis

Our deterministic ensemble pipeline analyzes patterns, identifies relationships, and generates threat intelligence automatically — same input, same clusters, same reasoning, every run.

3
Receive reports

Get comprehensive threat intelligence reports with IOCs, YARA rules, and hunting queries.

4
Execute hunting queries

Use our automated hunting query execution service to validate findings and monitor for new threats.

User Guide

Platform Features


Platform Features

ClusterHawk offers an extensive set of features for IP address analysis, clustering, and threat detection, enabling security professionals to identify and respond to potential threats.

Analysis Capabilities
  • IP Clustering Engine: Process and analyze IP metadata using sophisticated algorithms, handling datasets from 100 to 5000+ addresses with precision
  • Pattern Recognition & Labeling: Apply custom labeling rules to identify malicious clusters based on known patterns, extending threat detection to previously unknown IP addresses
  • Infrastructure Relationship Mapping: Uncover hidden connections between IP addresses through pattern detection and relationship mapping, revealing potential threat infrastructure
  • Model Training & Prediction: Create and train custom models based on your specific attack patterns and infrastructure behaviors for future threat prediction
  • Neighborhood Analysis: Track how IP addresses move between clusters across different clustering jobs, providing insights into changing infrastructure patterns