ThreatCluster
Live threat intelligence: incident clusters, actor and malware profiles, exploited CVEs, ransomware leak-site victims.
- Category
- Security
- Primary Subcategory
- Threat Detection & SIEM/XDR Monitoring
Integration details
Description
ThreatCluster reads every public security report, clusters them into one deduplicated story per incident, scores each story, extracts the entities involved (threat actors, malware, tools, vendors, CVEs, countries, industries) and tracks ransomware leak sites. This connector gives Claude that corpus through ten read-only tools: search incident clusters, search everything, newest threats, get a full threat record with its sources and validated indicators, leak-site victims with a tally by group, sector and country, look up an entity, get a vulnerability with KEV, EPSS and exploit status, exploited vulnerabilities in a window, trending entities, and your API budget so Claude can pace itself. Every result carries citation URLs back to the original reporting. Sign in with your ThreatCluster account; the free tier includes 100 credits a day and no card is needed.
- Integration type
- Connector
- Verification status
Community connector- Platform
- Claude
- Primary Subcategory
- Threat Detection & SIEM/XDR Monitoring
- Secondary Subcategories
- None listed
- Brand
- ThreatCluster
- Access
- Account required
- First tracked
- 2026-09-28
- Tool count
- 10
- Geography
- US
The Primary Subcategory used for this profile’s headline score.
Other Subcategories where the Integration is listed.
Claude Discoverability Score
Claude Connector discovery is coming soon
Community Connectors only appear in Claude’s registry.Once verified, organic discovery begins and we can calculate your score.Read more about Community Connector verification.
No spam. Unsubscribe any time.
No spam. Unsubscribe any time.
What discovery looks like

Claude can surface verified Connectors when they match a user’s Prompt.
How Claude Connector discovery works
Your Connector will compete to appear for users’ Prompts once Claude verifies it
Competing in Claude Threat Detection & SIEM/XDR Monitoring
View Category10 tools agents can invoke
How do I improve a Community connector's discoverability?
The levers are the listing surface agents actually read: names, descriptions, keywords, tool metadata, and registry health. Which lever matters depends on where discovery breaks, which is what continuous measurement shows.
What are ThreatCluster alternatives on Claude?
As of 2026-09-29, ThreatCluster competes with Anvilogic, Brandefense MCP, Exaforce, Fingerprint, LimaCharlie, SEON, Spectra Intelligence MCP, WhisperGraph in Claude Threat Detection & SIEM/XDR Monitoring, ranked by public Discoverability Score.
Where is this profile measured?
This profile uses the geography attached to the latest public registry snapshot: US. Locale tags are intentionally omitted.