Skip to main content

Platform Documentation

Learn how to use ClusterHawk for IP clustering and threat detection

Search Documentation

1
Submit IPs

Upload your IP addresses of interest through our secure interface. Our platform handles datasets up to 5000 addresses.

2
Analysis

Our deterministic ensemble pipeline analyzes patterns, identifies relationships, and generates threat intelligence automatically — same input, same clusters, same reasoning, every run.

3
Receive reports

Get comprehensive threat intelligence reports with IOCs, YARA rules, and hunting queries.

4
Execute hunting queries

Use our automated hunting query execution service to validate findings and monitor for new threats.

User Guide

OVERCAST Model Interpretation


Classification Interpretation

The OVERCAST model was built from 50 validated nation-state IPs that were expanded to approximately 1,900 assets through profile matching across internet scanning data. The RDP tier of the fleet operates predominantly through RouterHosting LLC / Cloudzy (AS14956), a documented Command-and-Control Provider (C2P), and is anchored to the cloudzy.com domain. The non-RDP tier (nginx, Apache / Nextcloud, Home Assistant, OpenSSH) runs on cloud providers (Amazon, Oracle Cloud, DigitalOcean) and is anchored to the duckdns.org dynamic-DNS service. Behavioral clustering decomposed the fleet into deployment profiles based on certificate configurations, TLS negotiation behavior, JARM / JA3 / JA3S fingerprints, encryption stack composition, screenshot states, and geographic provisioning patterns.

When this model predicts a cluster assignment for a new IP, it indicates the IP matches characteristics of infrastructure associated with the OVERCAST fleet, including windows-{City} NetBIOS / certificate naming on the RDP tier,duckdns.org domain footprint on the web / IoT tier, JARM / JA3S fingerprints clustering by service type, and hosting-provider signatures consistent with the tracked C2P ecosystem.

Cluster Quick Reference: