Getting started

IntelMCP gives your Claude access to messages collected continuously from public Telegram channels about threat actors, ransomware, hacktivism, data leaks, vulnerabilities and IT/OT security, with extracted indicators. All analysis runs in your own Claude, on your own Claude plan.

Choose one way to connect: claude.ai, Claude Code with the connector, or the Claude Code plugin. Using more than one in the same app gives you duplicate tools and two sign-ins.

Add IntelMCP to claude.ai

  1. Open claude.ai, then Settings → Connectors → Add custom connector.
  2. Name: IntelMCP. URL: https://mcp.intelmcp.io/mcp. Click Add, then Connect.
  3. Sign in with Google, or with a one-time code sent to your email. Use the email address you subscribed with: an email that is not subscribed is refused.
  4. Approve the access request. IntelMCP now appears in your connectors.

On Team or Enterprise plans, an organization owner may need to add the connector first.

Add IntelMCP to Claude Code

claude mcp add --scope user --transport http intelmcp https://mcp.intelmcp.io/mcp

Then run /mcp in Claude Code and choose IntelMCP to sign in.

Using Claude Code or Cowork

Install the IntelMCP plugin. It adds the connector and two commands. Use either the plugin or the claude mcp add command above, not both.

/plugin marketplace add intelmcpops-creator/intelmcp-plugin
/plugin install intelmcp@intelmcp

In claude.ai, ask "Show my IntelMCP dashboard", or pick the IntelMCP prompts from the connector menu.

First things to ask

Start with "Set up my IntelMCP monitoring." Claude interviews you about what you need to watch (your organization, country, sector, threat groups, products), shows you real examples, tests alert rules against recent history, and saves your setup once you approve it. Not sure where to start? Say so, and Claude suggests common starting points.

After that, try:

How monitoring works

If something goes wrong