Skip to main content

Upcoming Innovations

Explore the roadmap of features coming to ClusterHawk: from pre-trained threat models to collaborative workspaces.

Collaborative Shared Workspaces


Give your enterprise security teams secure, organisation-wide workspaces for collaboration. Share clustering jobs, models, and threat intelligence across your entire security organization.

Shared Workspaces eliminate analysis silos by creating a central repository for all team jobs, models, and configurations. That speeds up incident response and enables collective threat hunting.

Key Capabilities

Team Job Repository: All jobs submitted by workspace members are automatically visible to the team. That enables cross-dataset comparison, search, and reuse of analysis findings.

Role-Based Permissions: Granular controls (Admin, Analyst, Viewer) regulate who can create jobs, edit configurations, or annotate results. That protects sensitive investigations while still allowing collaboration.

Cross-Job Analytics: Workspace dashboards aggregate metrics across all team jobs. That reveals organisation-wide threat trends, recurring infrastructure, and actor movement between clusters.

Secure Isolation: Each enterprise workspace is isolated with dedicated storage and API tokens. That ensures data sovereignty and compliance while permitting safe intra-team collaboration.

Inline Annotations & Comments: Analysts can leave contextual comments on clusters, IPs, or model results directly inside analysis dashboards. That supports real-time knowledge sharing and peer review without leaving the platform.

Cross-Workspace Job Comparison: Compare clustering results between any two team jobs using the same comparison engine already used in individual analysis. This surfaces drift, cluster migrations, and stability trends across projects.

Audit Logs: Every action (from job creation to annotation edits) is immutably logged. That gives administrators full visibility for compliance, incident forensics, and team accountability.

Expected release: In the future

Intelligent Threat History Search


Instantly access the complete history of any IP address or threat actor across your entire analysis history. The contextual search system reveals the full evolution of threats throughout your environment: how they were categorized, when they first appeared, and how their characteristics changed over time.

Search Features:

Actor-Based Intelligence: Search by threat actor label to instantly locate all associated infrastructure across your entire analysis history. That reveals patterns of behavior unique to specific threat groups.

IP Evolution Tracking: Trace how specific IP addresses have moved between different clusters and classifications over time, with detailed explanations of why each transition occurred.

Cross-Job Correlation: Discover how the same IP or actor has been classified across different analysis jobs. That provides a view of threat correlation across your entire dataset.

First Appearance Insights: Instantly identify when a specific threat indicator first appeared in your environment and track its complete history through your security analysis workflow.

Contextual Threat Intelligence

Traditional search tools locate data points. ClusterHawk's search adds context: which analysis jobs contained the target, why it was classified in specific ways, and how its threat profile changed over time.

Expected release: In the near future

Real-Time Alerting & Notification Integrations


Receive critical insights the moment they happen. Our real-time alerting engine delivers instant notifications to Slack, Microsoft Teams, e-mail, or custom webhooks when jobs finish, anomalies spike, or new threat-actor labels emerge.

Key Capabilities

Multi-Channel Delivery: Slack, Teams, e-mail, and webhook endpoints are supported out-of-the-box.

Per-Workspace Routing: Fine-grained rules route alerts to the right team or channel based on workspace, job type, or severity.

Alert-Throttling Controls: Suppress noise with rate limits, quiet hours, and de-duplication of repeat events.

Expected release: In the near future