Skip to main content

Platform Documentation

Learn how to use ClusterHawk for IP clustering and threat detection

Search Documentation

1
Submit IPs

Upload your IP addresses of interest through our secure interface. Our platform handles datasets up to 5000 addresses.

2
Analysis

Our deterministic ensemble pipeline analyzes patterns, identifies relationships, and generates threat intelligence automatically — same input, same clusters, same reasoning, every run.

3
Receive reports

Get comprehensive threat intelligence reports with IOCs, YARA rules, and hunting queries.

4
Execute hunting queries

Use our automated hunting query execution service to validate findings and monitor for new threats.

User Guide

Neighborhood Tab


Neighborhood Analysis Tab

The NEIGHBORHOOD ANALYSIS tab shows IP relationships, cluster stability, and temporal evolution patterns, with filtering, anomaly detection, and visualization tools:

  • High-Performance Network Graph Visualization: Interactive visualization with multiple layout algorithms and performance optimization:
    • Standard Network layout: Shows direct connections between IPs based on neighbor relationships
    • Temporal Cluster View: Positions clusters in outer rings with IPs in inner rings, clearly distinguishing primary vs neighbor IPs
    • Force-Directed layout: Optimized physics simulation for large graphs integration
    • Interactive node selection with detailed information panels and job correlation data
  • Multi-Dimensional Filtering Framework: Filtering system with real-time results:
    • Quick filter presets: High Impact, Stable Networks, Cluster Migrations, Volatile IPs
    • Dynamic neighbor count ranges based on actual data
    • Stability score filtering with adjustable ranges
    • Temporal trend filtering (stable, declining, improving, volatile IPs)
    • Cluster ID selection and IP search patterns
  • Enhanced Stability Metrics: Composite stability scoring with detailed breakdown:
    • Neighborhood stability (40% weight): Consistency of IP neighbors across jobs
    • Cluster size stability (20% weight): Stability of cluster membership counts
    • Change magnitude analysis (20% weight): Magnitude of relationship changes
    • Cluster transition penalties (20% weight): Impact of moving between clusters
    • Visual progress indicators and detailed metric explanations
  • Temporal Trend Analysis Integration: Pattern recognition across time series:
    • Stable IPs: Consistently high stability across multiple jobs
    • Declining IPs: Decreasing stability over time indicating potential infrastructure changes
    • Improving IPs: Increasing stability suggesting infrastructure maturation
    • Volatile IPs: Highly variable patterns requiring investigation
  • Anomaly Detection and Alerting: Automated identification of unusual patterns:
    • Statistical outliers: IPs with abnormal stability scores or deviations
    • Temporal disruptions: Sudden changes in stability patterns
    • Cluster anomalies: Unusual migration patterns or fragmentation
    • Network anomalies: Isolated IPs or hub degradation patterns
    • Severity classification (critical, high, medium, low) with actionable recommendations
  • Enhanced Job Comparison Engine: Integrated differential analysis:
    • Comparison data with stability improvements and declines
    • Cluster migration tracking across job boundaries
    • Detailed IP transition analysis with job correlation
    • Interactive comparison dialogs with improving/declining IP categorization
  • How to interpret neighborhood analysis
    • High stability = IPs keep the same neighbors across jobs. This usually means mature, well-maintained infrastructure.
    • Sudden drops = many neighbors changed at once. Treat these as infrastructure churn, rehosting, or potential take-downs/migrations.
    • Mass migrations = many IPs move from one cluster to another between jobs. This can indicate coordinated updates or campaign shifts.
    • Isolated IPs = few or no neighbors. These are outliers, often newly discovered, decommissioned, or purposely obfuscated hosts.
    • Hubs losing neighbors = central nodes that suddenly drop connections. Investigate for key infrastructure changes or disruptions.
    • What to act on first: low-stability IPs, large added/removed neighbor counts, and any cluster transitions for high-value targets.