Skip to main content

Platform Documentation

Learn how to use ClusterHawk for IP clustering and threat detection

Search Documentation

1
Submit IPs

Upload your IP addresses of interest through our secure interface. Our platform handles datasets up to 5000 addresses.

2
Analysis

Our deterministic ensemble pipeline analyzes patterns, identifies relationships, and generates threat intelligence automatically — same input, same clusters, same reasoning, every run.

3
Receive reports

Get comprehensive threat intelligence reports with IOCs, YARA rules, and hunting queries.

4
Execute hunting queries

Use our automated hunting query execution service to validate findings and monitor for new threats.

User Guide

Available Models


Available Pre-Built Models

The following pre-built models are currently available for immediate use. Each model is designed for specific threat detection scenarios and includes detailed performance metrics. Each model includes a CTI platform writeup that documents the initial infrastructure analysis, while the actor itself is continuously tracked and model is retrained as the actor and infrastructure evolves. Model features and infrastructure may change during retraining cycles, and the article is no longer updated after the initial analysis.

Storm-0940 Brute-Force

CHAWKR_STORM_0940_BRUTEFORCE

Detects infrastructure associated with Storm-0940 state-sponsored brute-force attacks targeting Microsoft 365 and federated authentication endpoints. Trained on confirmed attack IPs and grouped into infrastructure clusters spanning APAC residential telecom, IoT/MQTT relays, embedded SSH stacks, and SOHO routers. The model answers infrastructure-similarity questions for IPs the analyst has already decided to investigate — it returns which previously-observed attacker pattern a new IP most resembles, not whether the IP is malicious.

Key Features:
  • Distributed password-spray infrastructure targeting Microsoft 365 federated authentication endpoints
  • Compromised SOHO routers, MikroTik / TP-Link / ZyXEL / Ubiquiti / Synology appliances, and IoT nodes acting as anonymizing proxies
  • Multi-service SSH/Web nodes (22/80/443) used as staging and pivot infrastructure
  • IoT botnet relay clusters built on Mosquitto MQTT brokers (with $SYS/broker/uptime topic disclosure), Busybox telnetd, and net-snmp management exposure on ports 161 / 1701 / 1883
  • TLS-fronted IoT management surfaces — Busybox telnetd + net-snmp exposed behind self-signed TLSv1.2 on port 443, identified via JA3 / JARM fingerprints (Bharti Telenet New Delhi cluster)
  • Global residential / SOHO telecom presence — Bharti Airtel (India), CHINANET (China), Korea Telecom, TELEFÔNICA BRASIL, Comcast (US), Bredband2 (Sweden), Movitel (Mozambique)
  • Versioned OpenSSH / Dropbear populations separated by ISP, city, and CVE exposure
  • Cert-anchored TLS-fronted clusters identified via JA3 / JARM fingerprints and certificate issuer patterns
Metrics:

Training Data: Storm-0940 campaign infrastructure
Reference: CTI Platform Article

OVERCAST

CHAWKR_OVERCAST

Detects infrastructure associated with the OVERCAST tracking effort — a multi-service fleet of approximately 1,900 assets operating across Cloudzy's Command-and-Control Provider (C2P) ecosystem. The fleet spans Windows RDP nodes, Home Assistant instances, nginx / Apache / Nextcloud web services, and cloud-hosted duckdns endpoints. This model decomposes the fleet into deployment profiles using behavioral clustering across certificate configurations, TLS negotiation, JARM / JA3 fingerprints, and geographic provisioning patterns.

Key Features:
  • Two-tier Windows RDP fleet on RouterHosting / Cloudzy: Windows 8.1 / Server 2012 R2 (build 6.3.9600, TLSv1.2) and Windows 11 (build 10.0.26100, TLSv1.3)
  • Certificate-based detection via windows-{City} NetBIOS naming and SSL Cert Issuer CN patterns (e.g. windows-Dallas0) anchored to cloudzy.com domain
  • RouterHosting LLC / Cloudzy (AS14956) C2P attribution — every RDP cluster shows Org: RouterHosting + Domain: cloudzy.com
  • Cloud-hosted nginx + duckdns dynamic-DNS fleet on Amazon, Oracle Cloud, and DigitalOcean Ubuntu nodes — high-prevalence KEV exposure (CVE-2023-44487 HTTP/2 Rapid Reset, CVE-2025-23419) with Avg EPSS ~0.94
  • IoT / smart-home pivot tier: Home Assistant on 443 + Apache/Nextcloud collaboration nodes, all sharing the duckdns.org domain footprint
  • Six distinct JARM signatures separating service tiers — RDP TLSv1.2 (26d26d16…), RDP TLSv1.3 (14d14d00…), nginx-cloud (27d40d40…), Home Assistant variants (28d28d28…, 2ad2ad00…), and Apache/Nextcloud (40d40d40…)
  • Geographic anomaly: Telecom Italia / Rome — Home Assistant nodes on residential ISP outside the RouterHosting footprint, suggesting operator pivot to non-C2P infrastructure
Metrics:

Training Data: OVERCAST C2P ecosystem infrastructure (validated nation-state seed data)
Reference: CTI Platform Article


Model Specifications
ModelConfidence ThresholdStatus

Storm-0940 Brute-Force

CHAWKR_STORM_0940_BRUTEFORCE
80%+Available

OVERCAST

CHAWKR_OVERCAST
70%+Available