Skip to main content

Platform Documentation

Learn how to use ClusterHawk for IP clustering and threat detection

Search Documentation

1
Submit IPs

Upload your IP addresses of interest through our secure interface. Our platform handles datasets up to 5000 addresses.

2
Analysis

Our deterministic ensemble pipeline analyzes patterns, identifies relationships, and generates threat intelligence automatically — same input, same clusters, same reasoning, every run.

3
Receive reports

Get comprehensive threat intelligence reports with IOCs, YARA rules, and hunting queries.

4
Execute hunting queries

Use our automated hunting query execution service to validate findings and monitor for new threats.

User Guide

Overview


Pre-Built Models Overview

ClusterHawk provides a collection of pre-trained models ready to use for immediate threat detection and IP analysis. These models are trained on extensive datasets and optimized for specific threat detection scenarios, so you can start advanced analysis without training your own models.

Benefits of Pre-Built Models
  • Immediate Deployment: Start using advanced threat detection without waiting for model training
  • Curated Training Data: Models trained on carefully selected datasets representing real-world threat scenarios
  • Regular Updates: Models are continuously updated with new threat intelligence and attack patterns
  • Proven Performance: Validated against known threat datasets and real-world attack scenarios
  • No Resource Requirements: Use without consuming your model storage quota
How to Use Pre-Built Models

Pre-built models can be used in two ways:

  1. Direct Analysis: Select a pre-built model when submitting a prediction job in the Workspace
  2. API Integration: Use pre-built models through the public API for automated threat detection workflows

All pre-built models include detailed documentation about their training data, performance metrics, and recommended use cases to help you choose the most appropriate model for your analysis needs.