Skip to main content

Platform Documentation

Learn how to use ClusterHawk for IP clustering and threat detection

Search Documentation

1
Submit IPs

Upload your IP addresses of interest through our secure interface. Our platform handles datasets up to 5000 addresses.

2
Analysis

Our deterministic ensemble pipeline analyzes patterns, identifies relationships, and generates threat intelligence automatically — same input, same clusters, same reasoning, every run.

3
Receive reports

Get comprehensive threat intelligence reports with IOCs, YARA rules, and hunting queries.

4
Execute hunting queries

Use our automated hunting query execution service to validate findings and monitor for new threats.

User Guide

Model Updates


Model Updates and Maintenance

Pre-built models are regularly updated to incorporate the latest threat intelligence and improve detection capabilities.

Update Schedule

Pre-built models follow a structured update schedule:

  • Monthly Updates: Minor improvements and new threat intelligence integration
  • Quarterly Updates: Major model retraining with expanded datasets
  • Emergency Updates: Rapid updates in response to emerging threats or critical vulnerabilities
Update Process

Each model update goes through a rigorous validation process:

  1. Data Collection: Gather new threat intelligence and attack patterns from multiple sources
  2. Model Retraining: Retrain models with expanded datasets while maintaining performance standards
  3. Validation Testing: Test updated models against known threat datasets and real-world scenarios
  4. Performance Verification: Ensure updated models meet or exceed previous performance metrics
  5. Deployment: Roll out updated models with backward compatibility for ongoing jobs
Version Compatibility

ClusterHawk maintains backward compatibility for model updates:

  • API Compatibility: Existing API calls continue to work with updated models
  • Result Format: Result structure remains consistent across model versions
  • Performance Improvements: Updates typically improve performance without changing core functionality