Skip to main content

Platform Documentation

Learn how to use ClusterHawk for IP clustering and threat detection

Search Documentation

1
Submit IPs

Upload your IP addresses of interest through our secure interface. Our platform handles datasets up to 5000 addresses.

2
Analysis

Our deterministic ensemble pipeline analyzes patterns, identifies relationships, and generates threat intelligence automatically — same input, same clusters, same reasoning, every run.

3
Receive reports

Get comprehensive threat intelligence reports with IOCs, YARA rules, and hunting queries.

4
Execute hunting queries

Use our automated hunting query execution service to validate findings and monitor for new threats.

User Guide

Clustering Tab


Clustering Tab

The CLUSTERING tab provides multiple views to help you analyze clusters:

  • Cluster Distribution: Bar chart showing the number of IPs in each cluster and noise. Larger clusters might represent common infrastructure patterns, while smaller ones may indicate specialized or unusual activity.
  • Cluster Stability Metrics: Metrics showing how stable clusters are between analysis runs. Higher stability suggests more reliable patterns that persist across different methods.
  • IP Distribution: Detailed view of IP address distribution across clusters. Use this to examine the composition of each cluster and identify representative IPs.
  • Cluster Table: Information about each cluster, including size, evaluation metrics, and representative IPs. This provides a quick overview of all identified patterns.
  • Cluster Features: For users with enhanced permissions, this view shows the key characteristics that define each cluster, helping you understand what makes each group unique and what attributes contribute most to cluster formation.
  • User-Defined Cluster Labels: Assign custom labels to clusters for easier identification and organization:
    • In the IP Distribution tab, click the edit icon on any cluster card header to add or modify a custom label
    • User labels are displayed alongside auto-detected labels in tooltips across all analysis views
    • Labels persist across sessions and are included in prediction results when using the trained model
    • User labels are distinguished from detection-based labels and can be removed by clearing the label field
  • Cluster Statistical Comparison: Dual-mode comparison system for conducting comparative assessments across cluster dimensions:
    • Features Comparison Mode: Side-by-side feature importance comparison showing SHAP/LIME values, representative values, frequency analysis, and cluster-specific interpretations. Identifies shared features, unique features, and importance differentials for precise cluster differentiation.
    • Statistics Comparison Mode: Statistical comparison across organizational profiles, vulnerability analysis, product analysis, certificate analysis, service analysis, naming patterns, and malware indicators for complete cluster profiling.
    • The framework is flexible, letting analysts compare clusters across all these dimensions.