Telegram threat intelligence, inside Claude.

IntelMCP collects messages from public Telegram channels where threat actors, hacktivists and researchers post: breach claims, leaks, vulnerability chatter. You search and monitor them from Claude. Describe what you care about in plain language; Claude sets up the alert rules and does the reading.

Get started for $25 per month

How it works

  1. Subscribe. One subscription gives one analyst a sign-in.
  2. Connect it to Claude. Add https://mcp.intelmcp.io/mcp as a custom connector in claude.ai or Claude Code, and sign in with Google or a code sent to your email.
  3. Set alerts and ask questions. Tell Claude what matters to you (an organization, a country, a CVE, a threat group) and it creates rules and digs into the history. New matches wait in IntelMCP until you ask Claude to review them, or can be pushed as they arrive to Slack or your own webhook.

What you get

Pricing

$25 per month

Everything above, for one analyst. Billed monthly. Cancel any time.

Get started

Payments are processed by Lemon Squeezy, our merchant of record. You need a Claude account that can add custom connectors, or Claude Code. See the refund policy.

Questions

Which channels does IntelMCP collect from?
Only public Telegram channels and groups, the ones anyone can find and join. Never private chats or invite-only groups. Messages deleted at the source are removed from IntelMCP when the collector sees the deletion.
Is IntelMCP affiliated with Telegram?
No. IntelMCP is an independent service that uses Telegram's API. It is not affiliated with or endorsed by Telegram.
Do you train AI on the data?
No. IntelMCP does not train or fine-tune AI models, and does not run one. The analysis happens in your own Claude.
Is the content verified?
No. Messages are third-party posts as published, and claims in them can be false or exaggerated. Treat them as leads to check, not as facts.
What do I need?
A Claude account that can add custom connectors (or Claude Code) and an IntelMCP subscription.