Getting started
IntelMCP gives your Claude access to messages collected continuously from public Telegram channels about threat actors, ransomware, hacktivism, data leaks, vulnerabilities and IT/OT security, with extracted indicators. All analysis runs in your own Claude, on your own Claude plan.
Choose one way to connect: claude.ai, Claude Code with the connector, or the Claude Code plugin. Using more than one in the same app gives you duplicate tools and two sign-ins.
Add IntelMCP to claude.ai
- Open claude.ai, then Settings → Connectors → Add custom connector.
- Name:
IntelMCP. URL:https://mcp.intelmcp.io/mcp. Click Add, then Connect. - Sign in with Google, or with a one-time code sent to your email. Use the email address you subscribed with: an email that is not subscribed is refused.
- Approve the access request. IntelMCP now appears in your connectors.
On Team or Enterprise plans, an organization owner may need to add the connector first.
Add IntelMCP to Claude Code
claude mcp add --scope user --transport http intelmcp https://mcp.intelmcp.io/mcp
Then run /mcp in Claude Code and choose IntelMCP to sign in.
Using Claude Code or Cowork
Install the IntelMCP plugin. It adds the connector and two commands. Use either the plugin or the claude mcp add command above, not both.
/plugin marketplace add intelmcpops-creator/intelmcp-plugin
/plugin install intelmcp@intelmcp
/intelmcp:setup: the setup interview./intelmcp:dashboard: a visual overview of your monitoring.
In claude.ai, ask "Show my IntelMCP dashboard", or pick the IntelMCP prompts from the connector menu.
First things to ask
Start with "Set up my IntelMCP monitoring." Claude interviews you about what you need to watch (your organization, country, sector, threat groups, products), shows you real examples, tests alert rules against recent history, and saves your setup once you approve it. Not sure where to start? Say so, and Claude suggests common starting points.
After that, try:
- "Watch for breach claims that mention our company." Then later: "Any new matches?"
- "Show today's matches and tell me which ones matter."
- "Search for CVE-2024-3400 and find its earliest appearance in the collection."
How monitoring works
- Rules match new messages on words, patterns and indicators. A match is a candidate, not a finding.
- Your own Claude judges each match against your watch profile and records a verdict. That uses your Claude plan.
- Matches wait in IntelMCP until you ask Claude about them, or can be pushed as they arrive to Slack or your own webhook.
- Message text is third-party content from Telegram: treat it as data to check, never as instructions.
If something goes wrong
- "No active IntelMCP subscription": you signed in with an email that is not subscribed. Disconnect IntelMCP in your connector settings and sign in again with the email you subscribed with.
- Anything else: email intelmcp.ops@gmail.com.