Getting started
Add IntelMCP to claude.ai
- Open claude.ai, then Settings → Connectors → Add custom connector.
- Name:
IntelMCP. URL:https://mcp.intelmcp.io/mcp. Click Add, then Connect. - Sign in with Google, or with a one-time code sent to your email. Use the email address you subscribed with.
- Approve the access request. IntelMCP now appears in your connectors.
Add IntelMCP to Claude Code
claude mcp add --scope user --transport http intelmcp https://mcp.intelmcp.io/mcp
Then run /mcp in Claude Code and choose IntelMCP to sign in.
First things to ask
Start with "Set up my IntelMCP monitoring." Claude interviews you about what you need to watch (your organization, country, sector, threat groups, products), shows you real examples, tests alert rules against recent history, and saves your setup once you approve it. Not sure where to start? Say so, and Claude suggests common starting points.
After that, try:
- "Watch for breach claims that mention our company." Then later: "Any new matches?"
- "Show today's matches and tell me which ones matter."
- "Search for CVE-2024-3400 and trace where the first claim came from."
If something goes wrong
- "No active IntelMCP subscription": you signed in with an email that is not subscribed. Disconnect IntelMCP in your connector settings and sign in again with the email you subscribed with.
- Anything else: email intelmcp.ops@gmail.com.