All apps & connectors
ThreatCluster logo

ThreatCluster

ClaudeCommunityby ThreatCluster

ThreatCluster reads every public security report, clusters them into one deduplicated story per incident, scores each story, extracts the entities involved (threat actors, malware, tools, vendors, CVEs, countries, industries) and tracks ransomware leak sites. This connector gives Claude that corpus through ten read-only tools: search incident clusters, search everything, newest threats, get a full threat record with its sources and validated indicators, leak-site victims with a tally by group, sector and country, look up an entity, get a vulnerability with KEV, EPSS and exploit status, exploited vulnerabilities in a window, trending entities, and your API budget so Claude can pace itself. Every result carries citation URLs back to the original reporting. Sign in with your ThreatCluster account; the free tier includes 100 credits a day and no card is needed.

Details

Data Analytics
Listed Sep 29, 2026
by ThreatCluster
MCP endpoint: https://threatcluster.io/mcp · streamable-http

Available tools (10)

api_budgetexploited_vulnerabilitiesget_threatget_vulnerabilityleak_site_victimslookup_entitynewest_threatssearch_everythingsearch_threatstrending_entities