Resources · Claude connector

Claude Defense.com Threat Analysis connectorWhat Claude can do in your Defense.com Threat Analysis account.

The Claude Defense.com Threat Analysis connector exposes 16 tools. 13 read your portal, 0 are documented as writing, and 3 training tools are described without saying whether they change anything. Here: what Claude can pull, what it needs, and its real limits.

Verified Trustpilot reviews · AI, automation & growth agency

Overview

Why a security lead would plug Defense.com into Claude

You stop clicking through portal filters to answer the morning question: what should we fix first? You ask Claude in plain English, it calls the Defense.com tools on its own, and you get a ranked answer with remediation guidance instead of a raw export. The data stays your Defense.com data; Claude just reads it for you.

Start the day with a priority list. Ask for your biggest risks and get_biggest_risks returns critical and high severity threats, ordered by risk score and number of affected assets. get_threat_to_remediate_first narrows it to the single most urgent open item.

Slice threats the way people talk. "Show me open phishing threats from the last 30 days" goes to get_threats_by_source, which understands 200+ friendly aliases such as pentest, phishing or social engineering. get_workload_analysis then shows who is carrying what across the team.

Turn a live threat into a lesson. get_training_for_threat and get_security_awareness_brief build training content and a briefing from what is actually hitting you right now.

What it will not do: the directory sheet documents no tool that closes, assigns or edits a threat in the portal. The extension runs only in Claude Desktop and needs an API token from your Defense.com account. And nothing fires on its own: no tool wakes up when a new detection lands. For alerts pushed into a channel the moment something happens, you need an automation tool, a different job; our Integrations hub covers that side.

Vocabulary

Five words before you start

The vocabulary you will run into while setting up Defense.com in Claude.

Connector
The link you set up once between Claude and an account you already have, so Claude can work in it while it answers you.
Tool
One named action a connector opens to Claude. Claude picks the ones it needs by itself; the directory lists them by name.
Authorization
The step where you hand Claude the access it will use on the service. Given once per person, and you can take it back later.
Approval
The confirmation Claude waits for before finishing something that changes your account, shown in the chat when it matters.
MCP
The shared standard behind connectors: it is what lets an assistant like Claude talk to an outside service such as Defense.com.
Connect

Plug Defense.com into Claude in three steps

  1. 01

    Find Defense.com in Claude

    In Claude's settings, open Customize, then Connectors, and look for Defense.com Threat Analysis. On a Team or Enterprise workspace, an Owner or Primary Owner has to enable the connector before each member can sign in to it.

  2. 02

    Start the connection

    Click Connect on its row and give the access Defense.com asks for. If the link breaks later, Disconnect and plug it back in; access can also be withdrawn from your Defense.com account.

  3. 03

    Check what the access covers

    Read the access screen before you confirm. It belongs to the service, not to Claude, and it is what sets the scope. A service can announce broader permissions there than Claude actually uses day to day.

Tools

The 16 tools, grouped by what they do

Defense.com Threat Analysis gives Claude 16 tools: 13 that read your account, 0 that change something in it, and 3 no official source describes.

Thirteen read, three training tools stay unclassified. Names stay exactly as Claude shows them, in English.

  • 13 read
  • 3 not documented

What Claude reads (13)

13 tools

Thirteen tools that pull threats, workload and training content from your portal without changing it.

get_biggest_risks

Returns your critical and high severity threats, ranked by risk score and by how many assets they affect, with remediation guidance attached.

When it helps
the Monday stand-up starts in ten minutes and you want the three items that deserve the team's attention this week.

Sourcegithub.com · October 1, 2026 ↗

get_new_threats

Lists the threats that appeared over the last N days, a window you choose in your question, so recent arrivals do not drown in the backlog.

When it helps
you come back from a week off and need to know what landed while you were away.

Sourcegithub.com · October 1, 2026 ↗

get_threat_to_remediate_first

Picks out the single unremediated threat with the highest priority, rather than a whole list to sort through yourself.

When it helps
one engineer just freed up an afternoon and you want to hand over the one item that matters most.

Sourcegithub.com · October 1, 2026 ↗

search_threats_by_keyword

Searches your threats for a word or phrase you supply, which is the quickest route when you remember a name but not where it was filed.

When it helps
a vendor bulletin mentions a product your company uses and you want every related finding.

Sourcegithub.com · October 1, 2026 ↗

get_latest_detections

Brings back the most recent detection events recorded in your Defense.com portal: the latest detections, in the publisher's own wording for this tool.

When it helps
someone reports a strange login and you want to see what the platform picked up in the last few hours.

Sourcegithub.com · October 1, 2026 ↗

get_threats_by_assignee

Shows the threats assigned to one named person, so you can review a colleague's queue without rebuilding the filter in the portal.

When it helps
a teammate is leaving on holiday and you need to see what has to be handed over to someone else.

Sourcegithub.com · October 1, 2026 ↗

get_threats_by_source

Filters threats by where they came from, and accepts everyday names: Defense.com maps 200+ aliases such as pentest, phish, email phishing or social engineering to the right source.

When it helps
the board asks what the last penetration test found that is still open.

Sourcegithub.com · October 1, 2026 ↗

get_threat_details_with_context

Opens one threat in full, together with the assets and users it touches, so Claude can explain the context and not only the title.

When it helps
you have a threat ID from a ticket and need to brief the asset owner before the call.

Sourcegithub.com · October 1, 2026 ↗

get_workload_analysis

Gives a dashboard-style view of the threat workload across your team, in line with the publisher's promise of a view on workload and assignments.

When it helps
you suspect two analysts carry most of the queue and want numbers before rebalancing assignments.

Sourcegithub.com · October 1, 2026 ↗

get_training_for_threat

Pulls training content tied to one specific threat, so the lesson matches a risk your company actually faces rather than a generic scenario.

When it helps
a phishing finding keeps recurring and you want material for the department that keeps clicking.

Sourcegithub.com · October 1, 2026 ↗

get_security_awareness_brief

Builds a security briefing from the threats currently open in your portal, which is how Defense.com describes it: a briefing drawn from current threats.

When it helps
you owe leadership a short security note and want it grounded in this month's real findings, not generic advice.

Sourcegithub.com · October 1, 2026 ↗

get_training_hint

Gives a hint for the quiz question currently on screen in an interactive training session run from the chat.

When it helps
a new hire is stuck on a ransomware question and you would rather they learn than guess, especially during onboarding week.

Sourcegithub.com · October 1, 2026 ↗

get_training_session_status

Checks how far a training session has gone, so you know where the learner stands before continuing.

When it helps
you paused a quiz yesterday and want to pick it up at the right question instead of starting from scratch.

Sourcegithub.com · October 1, 2026 ↗

Described, not classified (3)

3 tools

Defense.com gives each of these a one-line description, but no source says whether they read or record anything in your portal.

generate_training_questions

Defense.com's README gives it a single line about security training questions. No source documents whether it stores anything in your portal, so this page leaves it unclassified rather than guessing at its effect. The general approval rule further down covers it like any other tool.

start_training_session

Described by the publisher as the way to begin an interactive training, with quiz questions in the chat. Whether it records anything on the Defense.com side is not documented, which is why it sits in this group. The default approval rule applies to it.

submit_training_answer

The README's single line for this one: submit an answer, get the next question. No source states what happens to that answer in your portal, so its read or write status stays open here. Treat it under the general approval rule below.

Approvals

What Claude asks you before it acts

By default, Claude stops and asks for your go-ahead before each action it takes on an account for you. The request appears in the conversation, right when it matters.

On Team and Enterprise, workspace owners decide whether a member can let some actions through without being asked again. They can also cap what a connector may do for the whole organization, keeping reads open and closing writes, and nobody bypasses that from their own account. Claude works with your rights and nothing more: what your API token cannot see, Claude cannot see. The official per-tool label (read-only versus write and delete) only shows in a connected account's settings.

Plans

Which plans it works on

Of the 819 sheets in the official directory, 0 shows plan availability. The connector-by-connector answer is not published anywhere: it is a real gap in the catalog.

The general rule is published. Remote connectors are open to all users on Claude, Cowork, Claude Desktop and mobile, while desktop extensions like this one install in Claude Desktop. On Team and Enterprise, an Owner or Primary Owner opens the connector for the organization before members can connect. For the current state, check this connector's sheet in the official directory.

Limits

Where this connector stops

A connector is not an automation. Claude calls these tools while it answers you: nothing starts when a detection arrives or a threat goes critical.

Only Defense.com documents this connector; no Claude help page covers it. The tool list shows reads plus three unclassified training tools, which is an observed floor, not a guarantee: an administrator can open actions no public sheet lists. The partner badge is not a security audit, and Anthropic says on every sheet that it does not choose the tools a publisher exposes or vouch for how they behave. Connect what comes from a publisher you trust. Each directory connector has its own page with us, such as the Claude affinity connector.

Need help

Need help connecting Defense.com Threat Analysis to Claude?

A person reads every message.

FAQ

Claude Defense.com Threat Analysis connector: common questions

01What can Claude do with the Defense.com Threat Analysis connector?
Claude can read your Defense.com portal and answer security questions in plain English. Its tools rank your biggest risks, pick the threat to fix first, list new threats and latest detections, filter by keyword, assignee or source, open a threat with its assets and users, and show team workload. On the training side, it pulls lessons tied to a threat, writes an awareness brief, and runs quiz sessions with hints and progress checks inside the chat.
02Can Claude close, assign or change threats in Defense.com?
Not with any tool the sources document. Thirteen tools read your portal, and none is described as editing, assigning or closing a threat. Three training tools are described without saying whether they record anything, so they stay unclassified. A read-only list is an observed floor rather than a promise, since an administrator can open actions that no public directory sheet shows. Remediation work itself still happens in the Defense.com portal.
03Does Claude ask before it uses these tools?
No source describes a confirmation specific to a Defense.com tool, so the general rule applies: by default Claude asks before each action it takes on an account for you. Defense.com adds that Claude Desktop lets you set permissions per tool to control when Claude may use each one. On Team and Enterprise, workspace owners can also restrict what the connector may do for the whole organization, and members cannot override that.
04Which Claude plans is it available on?
No official source publishes plan availability connector by connector, and none of the 819 directory sheets displays it. The general rule says remote connectors are open to all users on Claude, Cowork, Claude Desktop and mobile, and that desktop extensions like this one install in Claude Desktop. On Team and Enterprise, an Owner or Primary Owner enables a connector first. The connector's sheet in the directory shows its current state.
05Does Claude see everything in our Defense.com portal?
Claude sees what the API token you entered can see, and nothing beyond it. Defense.com asks for a token with read permissions on threat data, created in the portal under Account and API Keys. Claude works with those rights the way you would. On a Team or Enterprise workspace, an owner can further restrict what the connector is allowed to do, and a member cannot lift that restriction alone, whatever their role in Defense.com.
06Why does Claude say no Defense.com tools are available?
Start with Claude Desktop itself. Defense.com's troubleshooting advice is to make sure every tool is enabled in Claude Desktop's tools menu, then to try disabling and re-enabling the extension. If authentication fails instead, the API token may have expired; regenerate it from the Defense.com portal, and check it has read permissions on threat data. Keep in mind the extension only exists in Claude Desktop: the web and mobile apps never list these tools.
07Claude or an automation tool for Defense.com?
They answer different needs, so it depends on the job. Claude works inside a conversation: you ask, it reads your threats and explains them, and nothing else happens when you stop typing. It does not watch the portal or alert anyone when a critical threat appears. For a process that runs in the background on an event or a schedule, that is an automation tool's role. For on-demand triage and briefings, the connector fits.