Skip to main content

Platform Documentation

Learn how to use ClusterHawk for IP clustering and threat detection

Search Documentation

1
Submit IPs

Upload your IP addresses of interest through our secure interface. Our platform handles datasets up to 5000 addresses.

2
Analysis

Our deterministic ensemble pipeline analyzes patterns, identifies relationships, and generates threat intelligence automatically — same input, same clusters, same reasoning, every run.

3
Receive reports

Get comprehensive threat intelligence reports with IOCs, YARA rules, and hunting queries.

4
Execute hunting queries

Use our automated hunting query execution service to validate findings and monitor for new threats.

User Guide

Queries Tab


Queries Analysis Tab

The QUERIES tab presents insights from the query analysis component:

  • Query Patterns: Identifies common patterns in the queries used in your analysis.
  • Cluster Queries: Shows the specific Shodan queries that define each cluster, helping you understand what characteristics group IPs together.
  • Real-World Counts: For users with enhanced visualization permissions, displays how many IPs in the current Shodan dataset match each query.
  • Hunting Queries: For users with hunting query permissions, allows direct execution of queries to see current matches, with real-time IP address lists.
  • Temporal Comparison: Shows how query results have changed between the original analysis time and current execution, helping identify emerging or declining infrastructure patterns.