Skip to main content

Platform Documentation

Learn how to use ClusterHawk for IP clustering and threat detection

Search Documentation

1
Submit IPs

Upload your IP addresses of interest through our secure interface. Our platform handles datasets up to 5000 addresses.

2
Analysis

Our deterministic ensemble pipeline analyzes patterns, identifies relationships, and generates threat intelligence automatically — same input, same clusters, same reasoning, every run.

3
Receive reports

Get comprehensive threat intelligence reports with IOCs, YARA rules, and hunting queries.

4
Execute hunting queries

Use our automated hunting query execution service to validate findings and monitor for new threats.

User Guide

Noise Intelligence Mining


Noise Intelligence Mining Results
  • Noise Re-Clustering View:
    • Secondary clusters identified within the noise data
    • Confidence metrics for these secondary clusters
    • Distribution charts showing the breakdown of formerly noisy IPs into meaningful groups
    • Quality metrics for the re-clustering analysis
  • Similarity Network: Interactive visualization showing relationships between IPs:
    • Color-coded connections indicating similarity strength
    • Adjustable threshold controls to focus on stronger relationships
  • Anomaly Detection Results: Prioritized list of the most anomalous IPs:
    • Anomaly scores indicating how unusual each IP is compared to the overall dataset
    • Feature contribution breakdown showing which characteristics make each IP anomalous
    • Grouping of anomalies with similar characteristics
    • Contextual information to help analysts understand the significance of each anomaly
  • Intelligence Extraction: Actionable insights derived from the noise analysis:
    • Potential new threat actor TTPs (Tactics, Techniques, and Procedures)
    • Emerging infrastructure patterns not yet widely recognized
    • Connection points between seemingly unrelated clusters
    • Indicators that might represent early warning signs of new campaign types
  • Group Features Explorer: Dedicated interface for exploring all features within similarity and reverse similarity groups:
    • Tabular display of feature names, representative values, and importance scores
    • Systematic pattern analysis across all group types
    • Feature value display showing actual representative values alongside feature names
    • Enables concrete pattern identification by understanding which features matter and their specific values within each group
  • Group Comparison Framework: Side-by-side analysis system for comparing noise intelligence groups:
    • Compare similarity groups, reverse similarity groups, and noise clusters
    • Overlap analysis showing common IPs between groups
    • Unique IP identification for each group
    • Anomaly statistics comparison across groups
    • Similarity score evaluation for group relationship assessment
Interpreting Noise Intelligence Results

To use Noise Intelligence Mining results effectively:

  • Focus on high-confidence secondary clusters: These represent the most reliable patterns discovered within the noise and may indicate emerging threat groups or infrastructure types not previously recognized.
  • Examine rare pattern intersections: Pay special attention to IPs that share multiple unusual characteristics, as these combinations often indicate sophisticated infrastructure designed to evade detection.
  • Investigate high anomaly scores: IPs with the highest anomaly scores warrant individual investigation, as they represent the most unusual cases that don't fit established patterns.
  • Connect with primary clusters: Look for relationship indicators between noise-derived patterns and primary clusters, which may reveal connections between different threat infrastructures.
  • Use Group Features Explorer: Examine feature values and importance scores within similarity and reverse similarity groups to understand the specific characteristics that bind IPs together. This systematic analysis helps identify concrete patterns that may not be immediately apparent from cluster assignments alone.
  • Use Group Comparison: Compare similarity groups, reverse similarity groups, and noise clusters side-by-side to identify relationships, overlaps, and unique characteristics. Use overlap analysis to discover connections between different group types and anomaly statistics to prioritize investigation efforts.