AI Marketplaces Leaderboard

Have I Been Squatted

Claude connectorCommunity

Find and investigate domains impersonating your organization: typosquat scans, live domain analysis, certificate transparency search and tr…

View in Claude directory
Tools
9

exposed by this connector

Movement

From our daily snapshots over the last 30 days.

Rank by popularity

#3224of 3,757176places up24h—7d
#3,207#3,260#3,313#3,366Sep 3Sep 9Sep 15Sep 21Sep 27Oct 2

Rank by trending score

—not ranked—24h—7d
—

Popularity score

3,000+2,00024h—7d
8001,4002,0002,6003,200Sep 3Sep 9Sep 15Sep 21Sep 27Oct 2

Trending score

——24h—7d
—

In its categories

How this connector compares with others in the same category. Positions are counted within the category, not across the whole directory.

Developer tools570th of 662 by popularity · not ranked by trending score
Order by

All 686 Developer tools connectors

Other245th of 282 by popularity · not ranked by trending score
Order by

All 291 Other connectors

Productivity1,713th of 2,019 by popularity · not ranked by trending score
Order by

All 2,090 Productivity connectors

Have I Been Squatted catches attacker infrastructure as it is being built and shuts it down across every control our customers run. Lookalike domains, mail servers, staging hosts and their certificates often appear before a phishing campaign launches. We find them, collect the evidence and drive the response through the controls you already operate.

This connector brings that intelligence into Claude.

Enrich and hunt, for any domain:

  • Analyze a domain from an alert, email or ticket: DNS and IPs, mail records, registration, hosting, ASN and location, HTTP response, technologies, open ports, known vulnerabilities, classification and a verdict. Seconds for a cached verdict, up to a few minutes for a full live pass.
  • Search certificate transparency: match new certificate names against a pattern such as "examp[l1]e", often before the host serves anything.
  • Hunt typosquats: generate permutations of a domain and find which are registered or live. Typically 5–10 minutes.

Work your organization's detections:

  • Query infrastructure found for your monitored domains, email and websites. Enrich mail records, registration, hosting, open ports, redirect chains, and what a page asks visitors for, such as passwords, one-time codes or wallet recovery phrases.
  • Triage: manage your results, such as tagging detections as owned or malicious. The tag persists when the domain resurfaces.
  • Find unregistered lookalikes an attacker could still register, so you can take them first. Paid plans.

Long lookups run in the background; Claude tells you one has started and checks back for results.

Try asking:

  • "Enrich every domain in this phishing report and rank them by risk."
  • "Which lookalikes found this week already have mail servers set up?"
  • "Can you help me analyze this domain"
  • "Has Have I Been Squatted seen this domain before?"

Requires a Have I Been Squatted account with an organization; every call is limited to the organization you connect. Detections require a paid plan.

Tools

  • analyze
  • annotate_result
  • ct_search
  • describe_catalog
  • discover
  • get_job
  • query
  • squat
  • whoami
Categories
Made by
Have I Been Squatted Inc. · Website
Sign-in
Required
Connector URL
https://mcp.haveibeensquatted.com/mcp?cache-bust
Transport
Streamable HTTP
Works with
Claude, Claude API, Claude Code, Claude Desktop
Added
September 29, 2026
More info