IntelMCP
Claude connectorCommunityThreat intelligence from public Telegram channels, searchable and monitored inside Claude.
- Tools
- 23
exposed by this connector
Movement
From our daily snapshots over the last 30 days.
Rank by popularity
Rank by trending score
Popularity score
Trending score
Movement is measured against our own daily snapshots, and there isn’t an earlier one to compare with yet.
In its category
How this connector compares with others in the same category. Positions are counted within the category, not across the whole directory.
Othernot ranked by popularity · not ranked by trending score
This connector isn’t ranked by popularity, so the category’s top connectors are shown instead.
| # | Connector | Popularity | Trending | 7d |
|---|---|---|---|---|
| 1 | 20,503 | 1places up | ||
| 2 | 18,983 | 1places up | ||
| 3 | 17,279 | 3places down | ||
| 4 | 16,850 | 7places up | ||
| 5 | 14,699 | 24places up | ||
| 6 | 14,539 | 15places up | ||
| 7 | 14,434 | 14places up |
IntelMCP gives Claude access to messages collected continuously from curated public Telegram channels about threat actors, ransomware, hacktivism, data leaks, vulnerabilities and IT/OT security, with edits, forwards and extracted indicators (IP addresses, domains, URLs, file hashes, CVE identifiers and countries). Coverage is deepest for the Middle East and the Gulf, Iran–Israel, Russia–Ukraine hacktivism, and leak, ransomware and CVE trackers.
Security analysts use it to:
- search the last 90 days of collected messages in their original languages, including Arabic, Persian, Russian and Hebrew;
- look up an indicator and see every post that mentions it;
- trace a claim to its earliest copy in the collection through forwards and copies;
- set up alert rules (words, patterns or indicators) that match new messages as they arrive, tested against history before saving;
- review matches with reposts of one event grouped into a single incident, record verdicts, and send matches to a signed webhook.
A built-in setup prompt asks the analyst two questions (what to watch for, and which regions), drafts starter rules and tests them against recent history, then shows one summary with each rule's expected alerts per day. On one approval it creates the rules and watch profile, matches the last 7 days of history, and shows the newest matches with an offer to judge them. Run again when monitoring exists, it tunes the existing rules and profile instead of creating new ones. A triage prompt judges unreviewed matches a page at a time against the watch profile and summarizes the relevant ones by severity. A dashboard prompt gives a visual overview of the monitoring, and an investigate prompt researches a question across the collection with every point cited.
All analysis runs in the user's own Claude; IntelMCP only stores and searches the collection and the user's own settings.
Tools
- ack_matches
- add_rule
- delete_rule
- find_entity
- get_context
- get_message
- get_watch_profile
- list_matches
- list_rules
- list_topics
- match_feed
- preview_rule
- record_verdict
- request_channel
- save_watch_profile
- search_messages
- set_delivery
- set_rule_enabled
Show all 23Show fewer
- stats
- timeline
- top_entities
- trace_forwards
- update_rule
- Categories
- Sign-in
- Required
- Connector URL
- https://mcp.intelmcp.io/mcp
- Transport
- Streamable HTTP
- Works with
- Claude, Claude API, Claude Code, Claude Desktop
- Added
- October 3, 2026
- More info