Skip to main content

Platform Documentation

Learn how to use ClusterHawk for IP clustering and threat detection

Search Documentation

1
Submit IPs

Upload your IP addresses of interest through our secure interface. Our platform handles datasets up to 5000 addresses.

2
Analysis

Our deterministic ensemble pipeline analyzes patterns, identifies relationships, and generates threat intelligence automatically — same input, same clusters, same reasoning, every run.

3
Receive reports

Get comprehensive threat intelligence reports with IOCs, YARA rules, and hunting queries.

4
Execute hunting queries

Use our automated hunting query execution service to validate findings and monitor for new threats.

User Guide

Cluster Labeling Tab


Cluster Labeling Tab

The CLUSTER LABELING tab provides insights into potential threat actors associated with your IP clusters:

  • Label Distribution: Shows the distribution of potential actors or other labels across your dataset with pie charts.
  • Label Rules: Displays the rule conditions used to identify different actors or patterns, including both AND and OR rule types.
  • Labeled IPs: Shows which IPs are associated with which potential actors, allowing you to investigate specific infrastructure.
  • Overview Statistics: Provides summary metrics including total IPs, total matches, and unique actors identified in your dataset.