Skip to main content

Platform Documentation

Learn how to use ClusterHawk for IP clustering and threat detection

Search Documentation

1
Submit IPs

Upload your IP addresses of interest through our secure interface. Our platform handles datasets up to 5000 addresses.

2
Analysis

Our deterministic ensemble pipeline analyzes patterns, identifies relationships, and generates threat intelligence automatically — same input, same clusters, same reasoning, every run.

3
Receive reports

Get comprehensive threat intelligence reports with IOCs, YARA rules, and hunting queries.

4
Execute hunting queries

Use our automated hunting query execution service to validate findings and monitor for new threats.

User Guide

Storm-0940 Model Interpretation


Classification Interpretation

The Storm-0940 Brute-Force model analyzed confirmed attack IPs and grouped them into distinct infrastructure clusters. All IPs were actively conducting brute-force activity at the time of analysis. Infrastructure characteristics were gathered using SHODAN metadata with timely retrieval. When this model predicts a cluster assignment for a new IP, the prediction indicates the IP matches characteristics of infrastructure the threat actor has used, which falls into a "possibly going to be malicious" category. The model does not answer "is this IP malicious" (that question is answered by the analyst's pre-curation upstream); it answers which previously-observed attacker-infrastructure pattern this IP most resembles, and how strongly.

The recommended workflow is to read the prediction's kind field first: it is the trust gate. confident_match rows are the actionable subset (the model is confident in the cluster attribution). ambiguous_diffuse and ambiguous_split rows mean the model is hedging across multiple plausible attributions; investigate the candidate set as a unit. out_of_distribution rows do not match any trained pattern. Investigate via behavioral evidence and do not rely on the cluster attribution.

Cluster Quick Reference: