Skip to main content

Platform Documentation

Learn how to use ClusterHawk for IP clustering and threat detection

Search Documentation

1
Submit IPs

Upload your IP addresses of interest through our secure interface. Our platform handles datasets up to 5000 addresses.

2
Analysis

Our deterministic ensemble pipeline analyzes patterns, identifies relationships, and generates threat intelligence automatically — same input, same clusters, same reasoning, every run.

3
Receive reports

Get comprehensive threat intelligence reports with IOCs, YARA rules, and hunting queries.

4
Execute hunting queries

Use our automated hunting query execution service to validate findings and monitor for new threats.

User Guide

Noise Intelligence Mining


Noise Intelligence Mining Results
  • Overview: Summary of the noise analysis, including a ranked list of the most anomalous hosts found among the noise IPs.
  • IP Distribution: Secondary clusters identified within the noise data, shown as per-cluster IP cards with each noise IP's nearest main cluster and containment confidence.
  • Noise Cluster Statistics: Statistical profiles of the secondary noise clusters.
  • Relationship Graph: Interactive visualization showing relationships between IPs:
    • Connections color-coded by relationship type (similarity, reverse similarity, membership), with edge width showing similarity strength
    • Adjustable score threshold controls to focus on stronger relationships
  • Data Table: Per-IP table of the noise set, including anomaly score, percentile, and detector agreement columns, with expandable rows explaining the features driving each score.
  • Signatures: Recurring feature-value combinations shared by subsets of noise IPs, with support counts and scores — useful for spotting patterns that repeat across otherwise unclustered hosts.
  • Group Features: Dedicated interface for exploring the top features (up to 5) of each similarity and reverse similarity group:
    • Tabular display of feature names, representative values, and importance scores
    • Systematic pattern analysis across all group types
    • Feature value display showing actual representative values alongside feature names
    • Enables concrete pattern identification by understanding which features matter and their specific values within each group
  • Group Comparison Framework: Side-by-side analysis system for comparing noise intelligence groups:
    • Compare similarity groups, reverse similarity groups, and noise clusters
    • Overlap analysis showing common IPs between groups
    • Unique IP identification for each group
    • Anomaly statistics comparison across groups
    • Similarity score evaluation for group relationship assessment
Interpreting Noise Intelligence Results

To use Noise Intelligence Mining results effectively:

  • Focus on high-confidence secondary clusters: These represent the most reliable patterns discovered within the noise and may indicate emerging threat groups or infrastructure types not previously recognized.
  • Examine rare pattern intersections: Pay special attention to IPs that share multiple unusual characteristics, as these combinations often indicate sophisticated infrastructure designed to evade detection.
  • Investigate high anomaly scores: IPs with the highest anomaly scores warrant individual investigation, as they represent the most unusual cases that don't fit established patterns.
  • Connect with primary clusters: Look for relationship indicators between noise-derived patterns and primary clusters, which may reveal connections between different threat infrastructures.
  • Use Group Features Explorer: Examine feature values and importance scores within similarity and reverse similarity groups to understand the specific characteristics that bind IPs together. This systematic analysis helps identify concrete patterns that may not be immediately apparent from cluster assignments alone.
  • Use Group Comparison: Compare similarity groups, reverse similarity groups, and noise clusters side-by-side to identify relationships, overlaps, and unique characteristics. Use overlap analysis to discover connections between different group types and anomaly statistics to prioritize investigation efforts.