Skip to main content

Platform Documentation

Learn how to use ClusterHawk for IP clustering and threat detection

Search Documentation

1
Submit IPs

Upload your IP addresses of interest through our secure interface. Our platform handles datasets up to 5000 addresses.

2
Analysis

Our deterministic ensemble pipeline analyzes patterns, identifies relationships, and generates threat intelligence automatically — same input, same clusters, same reasoning, every run.

3
Receive reports

Get comprehensive threat intelligence reports with IOCs, YARA rules, and hunting queries.

4
Execute hunting queries

Use our automated hunting query execution service to validate findings and monitor for new threats.

User Guide

Decision Making


Making Decisions Based on Results

To effectively use analysis results for security decision-making:

  • Focus on high-quality clusters: Prioritize clusters with "Good" or "Very Good" evaluation scores and high confidence metrics. These represent the most reliable patterns in your data.
  • Investigate unusual clusters: Clusters with unusual feature patterns may represent emerging threats or unique infrastructure even if they have moderate evaluation scores.
  • Read the kind field first: confident_match rows are the actionable subset; ambiguous_diffuse and ambiguous_split rows require reviewing the candidate set as a unit; out_of_distribution rows should be investigated via behavioral evidence rather than the cluster attribution. Confidence and the candidate distribution together gauge reliability. A high-confidence confident_match with a wide top1 − top2 gap is the most trustworthy prediction.
  • Track neighborhood changes: Use neighborhood analysis to monitor how IP relationships evolve over time. Significant changes in cluster membership may indicate infrastructure shifts or emerging threats.
  • Analyze noise intelligence: For large noise clusters, examine the Noise Intelligence Mining results to identify emerging threat patterns that traditional clustering might miss. Pay special attention to secondary clusters with high confidence scores and anomalous IPs with unusual feature combinations.
  • Use actor labeling: Actor labels automatically identify potential threat types based on known patterns. Use these as starting points for more focused investigations.
  • Cross-reference tabs: Compare findings across different tabs to build an understanding. For example, correlate infrastructure relationships with cluster assignments and actor labels.
  • Use Cluster Comparison: Apply the Cluster Statistical Comparison tool for side-by-side analysis of clusters. Use Features Comparison Mode to understand how SHAP/LIME-based feature importance differs between clusters, and Statistics Comparison Mode to compare organizational profiles, vulnerability patterns, and other statistical dimensions for a complete cluster profile.
  • Compare Noise Intelligence Groups: Use the Group Comparison Framework in Noise Intelligence Analysis to identify relationships between similarity groups, reverse similarity groups, and noise clusters. Analyze overlaps to discover connections and use anomaly statistics to prioritize investigation of unusual patterns.
  • Execute hunting queries: Use the Queries tab to execute real-time searches that help you identify current infrastructure matching your cluster patterns.
  • Analyze vulnerability data: In the Infrastructure tab, examine vulnerability information to prioritize response to potentially vulnerable systems.
  • Use visualization options: Experiment with different visualization layouts in the Network Graph to uncover relationships that might not be immediately apparent in the default view.