Skip to main content

Platform Documentation

Learn how to use ClusterHawk for IP clustering and threat detection

Search Documentation

1
Submit IPs

Upload your IP addresses of interest through our secure interface. Our platform handles datasets up to 5000 addresses.

2
Analysis

Our deterministic ensemble pipeline analyzes patterns, identifies relationships, and generates threat intelligence automatically — same input, same clusters, same reasoning, every run.

3
Receive reports

Get comprehensive threat intelligence reports with IOCs, YARA rules, and hunting queries.

4
Execute hunting queries

Use our automated hunting query execution service to validate findings and monitor for new threats.

User Guide

Available Tabs


Available Analysis Tabs

Depending on your job type and permission level, you'll see different analysis tabs:

  • Clustering: The primary analysis tab showing cluster distributions, quality metrics, and IP assignments
  • Neighborhood Analysis: Visualizes how IP relationships and cluster assignments change over time
  • Noise Intelligence: Re-analyzes noise clusters to surface rare patterns and emerging threats that primary clustering passes over
  • Cluster Labeling: Shows potential threat actor attributions based on cluster characteristics
  • Model: Displays detailed model information for training jobs
  • Hunting Queries: Presents query results and patterns identified in the analysis
  • Job Config: For Basic and Training jobs, shows the processing options and clustering weights actually used to produce this job's results
  • Model Information: For prediction jobs, shows details about the model used for predictions
  • Predictions: For prediction jobs, displays prediction results with confidence metrics