- Home
- Resources
- Integrations
- Defense.com Threat Analysis
Claude Defense.com Threat Analysis connectorWhat Claude can do in your Defense.com Threat Analysis account.
The Claude Defense.com Threat Analysis connector exposes 16 tools. 13 read your portal, 0 are documented as writing, and 3 training tools are described without saying whether they change anything. Here: what Claude can pull, what it needs, and its real limits.
Verified Trustpilot reviews · AI, automation & growth agency
Why a security lead would plug Defense.com into Claude
You stop clicking through portal filters to answer the morning question: what should we fix first? You ask Claude in plain English, it calls the Defense.com tools on its own, and you get a ranked answer with remediation guidance instead of a raw export. The data stays your Defense.com data; Claude just reads it for you.
Start the day with a priority list. Ask for your biggest risks and get_biggest_risks returns critical and high severity threats, ordered by risk score and number of affected assets. get_threat_to_remediate_first narrows it to the single most urgent open item.
Slice threats the way people talk. "Show me open phishing threats from the last 30 days" goes to get_threats_by_source, which understands 200+ friendly aliases such as pentest, phishing or social engineering. get_workload_analysis then shows who is carrying what across the team.
Turn a live threat into a lesson. get_training_for_threat and get_security_awareness_brief build training content and a briefing from what is actually hitting you right now.
What it will not do: the directory sheet documents no tool that closes, assigns or edits a threat in the portal. The extension runs only in Claude Desktop and needs an API token from your Defense.com account. And nothing fires on its own: no tool wakes up when a new detection lands. For alerts pushed into a channel the moment something happens, you need an automation tool, a different job; our Integrations hub covers that side.
Five words before you start
The vocabulary you will run into while setting up Defense.com in Claude.
- Connector
- The link you set up once between Claude and an account you already have, so Claude can work in it while it answers you.
- Tool
- One named action a connector opens to Claude. Claude picks the ones it needs by itself; the directory lists them by name.
- Authorization
- The step where you hand Claude the access it will use on the service. Given once per person, and you can take it back later.
- Approval
- The confirmation Claude waits for before finishing something that changes your account, shown in the chat when it matters.
- MCP
- The shared standard behind connectors: it is what lets an assistant like Claude talk to an outside service such as Defense.com.
Plug Defense.com into Claude in three steps
- 01
Find Defense.com in Claude
In Claude's settings, open Customize, then Connectors, and look for Defense.com Threat Analysis. On a Team or Enterprise workspace, an Owner or Primary Owner has to enable the connector before each member can sign in to it.
- 02
Start the connection
Click Connect on its row and give the access Defense.com asks for. If the link breaks later, Disconnect and plug it back in; access can also be withdrawn from your Defense.com account.
- 03
Check what the access covers
Read the access screen before you confirm. It belongs to the service, not to Claude, and it is what sets the scope. A service can announce broader permissions there than Claude actually uses day to day.
The 16 tools, grouped by what they do
Defense.com Threat Analysis gives Claude 16 tools: 13 that read your account, 0 that change something in it, and 3 no official source describes.
Thirteen read, three training tools stay unclassified. Names stay exactly as Claude shows them, in English.
- 13 read
- 3 not documented
Tools index
What Claude reads (13)
13 toolsThirteen tools that pull threats, workload and training content from your portal without changing it.
get_biggest_risks
Returns your critical and high severity threats, ranked by risk score and by how many assets they affect, with remediation guidance attached.
get_new_threats
Lists the threats that appeared over the last N days, a window you choose in your question, so recent arrivals do not drown in the backlog.
get_threat_to_remediate_first
Picks out the single unremediated threat with the highest priority, rather than a whole list to sort through yourself.
search_threats_by_keyword
Searches your threats for a word or phrase you supply, which is the quickest route when you remember a name but not where it was filed.
get_latest_detections
Brings back the most recent detection events recorded in your Defense.com portal: the latest detections, in the publisher's own wording for this tool.
get_threats_by_assignee
Shows the threats assigned to one named person, so you can review a colleague's queue without rebuilding the filter in the portal.
get_threats_by_source
Filters threats by where they came from, and accepts everyday names: Defense.com maps 200+ aliases such as pentest, phish, email phishing or social engineering to the right source.
get_threat_details_with_context
Opens one threat in full, together with the assets and users it touches, so Claude can explain the context and not only the title.
get_workload_analysis
Gives a dashboard-style view of the threat workload across your team, in line with the publisher's promise of a view on workload and assignments.
get_training_for_threat
Pulls training content tied to one specific threat, so the lesson matches a risk your company actually faces rather than a generic scenario.
get_security_awareness_brief
Builds a security briefing from the threats currently open in your portal, which is how Defense.com describes it: a briefing drawn from current threats.
get_training_hint
Gives a hint for the quiz question currently on screen in an interactive training session run from the chat.
get_training_session_status
Checks how far a training session has gone, so you know where the learner stands before continuing.
Described, not classified (3)
3 toolsDefense.com gives each of these a one-line description, but no source says whether they read or record anything in your portal.
generate_training_questions
Defense.com's README gives it a single line about security training questions. No source documents whether it stores anything in your portal, so this page leaves it unclassified rather than guessing at its effect. The general approval rule further down covers it like any other tool.
start_training_session
Described by the publisher as the way to begin an interactive training, with quiz questions in the chat. Whether it records anything on the Defense.com side is not documented, which is why it sits in this group. The default approval rule applies to it.
submit_training_answer
The README's single line for this one: submit an answer, get the next question. No source states what happens to that answer in your portal, so its read or write status stays open here. Treat it under the general approval rule below.
What Claude asks you before it acts
By default, Claude stops and asks for your go-ahead before each action it takes on an account for you. The request appears in the conversation, right when it matters.
On Team and Enterprise, workspace owners decide whether a member can let some actions through without being asked again. They can also cap what a connector may do for the whole organization, keeping reads open and closing writes, and nobody bypasses that from their own account. Claude works with your rights and nothing more: what your API token cannot see, Claude cannot see. The official per-tool label (read-only versus write and delete) only shows in a connected account's settings.
Which plans it works on
Of the 819 sheets in the official directory, 0 shows plan availability. The connector-by-connector answer is not published anywhere: it is a real gap in the catalog.
The general rule is published. Remote connectors are open to all users on Claude, Cowork, Claude Desktop and mobile, while desktop extensions like this one install in Claude Desktop. On Team and Enterprise, an Owner or Primary Owner opens the connector for the organization before members can connect. For the current state, check this connector's sheet in the official directory.
Where this connector stops
A connector is not an automation. Claude calls these tools while it answers you: nothing starts when a detection arrives or a threat goes critical.
Only Defense.com documents this connector; no Claude help page covers it. The tool list shows reads plus three unclassified training tools, which is an observed floor, not a guarantee: an administrator can open actions no public sheet lists. The partner badge is not a security audit, and Anthropic says on every sheet that it does not choose the tools a publisher exposes or vouch for how they behave. Connect what comes from a publisher you trust. Each directory connector has its own page with us, such as the Claude affinity connector.
Need help connecting Defense.com Threat Analysis to Claude?
A person reads every message.