Skip to main content

Platform Documentation

Learn how to use ClusterHawk for IP clustering and threat detection

Search Documentation

1
Submit IPs

Upload your IP addresses of interest through our secure interface. Our platform handles datasets up to 5000 addresses.

2
Analysis

Our deterministic ensemble pipeline analyzes patterns, identifies relationships, and generates threat intelligence automatically — same input, same clusters, same reasoning, every run.

3
Receive reports

Get comprehensive threat intelligence reports with IOCs, YARA rules, and hunting queries.

4
Execute hunting queries

Use our automated hunting query execution service to validate findings and monitor for new threats.

User Guide

Results Overview


Understanding Analysis Results

Once your analysis job is complete, ClusterHawk provides results through the Analysis Results page. This page offers a detailed view of your analysis output with various tabs and visualizations to help you interpret the data.

How ClusterHawk analyzes your data
  • Group similar IPs: ClusterHawk clusters IP addresses that behave alike (similar services, products, certificates, etc.).
  • Summarize what defines each group: It highlights the key characteristics that make a cluster unique.
  • Track change over time: It compares today's clusters with earlier jobs to see what stayed stable and what moved.
  • Surface unusual items: It flags outliers, sudden changes, and suspicious movement patterns.
Quick way to read the results
  • Start with Cluster Distribution: Big, consistent clusters usually represent stable infrastructure; tiny or fragmented clusters may be niche or newly emerging.
  • Open Cluster Features: Read the top features like you would a fingerprint: these explain what actually binds the IPs together.
  • Use Neighborhood Analysis: Look for what changed since previous jobs: new neighbors, lost neighbors, or mass movements between clusters.
  • Review Anomalies: Outliers, sudden drops in stability, or isolated IPs often point to interesting investigations.

The results section is divided into the following subsections for easier navigation:

  • Job Management: Tools for managing and filtering your analysis jobs
  • Analysis Tabs: Overview of the different analysis tabs available
  • Key Metrics: Understanding the metrics used to evaluate result quality
  • Clustering Tab: Details about the clustering analysis tab
  • Noise Intelligence Mining: Understanding analysis of noise clusters
  • Neighborhood Tab: Information about the neighborhood analysis tab
  • Cluster Labeling Tab: Understanding actor attribution analysis
  • Infrastructure Tab: Details about infrastructure analysis
  • Model Tab: Information about model training results
  • Queries Tab: Understanding query analysis results
  • Prediction Tabs: Details about prediction model information and results
  • STIX Export: Exporting results in STIX 2.1 format for OpenCTI and other TIPs
  • MISP Export: Exporting results in MISP-native format for direct MISP integration
  • Decision Making: How to make security decisions based on analysis results