---
title: "Connect Intruder to Claude: Monitor Targets & Manage Security Issues"
slug: connect-intruder-to-claude-monitor-targets-manage-security-issues
date: 2026-10-07
author: Riya Sethi
categories: ["AI & Agents"]
excerpt: "A definitive technical guide to connecting Intruder to Claude via MCP. Learn how to expose vulnerability data, automate scans, and triage security issues."
tldr: "Connect Intruder to Claude using a managed MCP server. This guide covers overcoming Intruder's API quirks, generating an MCP server, securely exposing tools, and orchestrating vulnerability workflows."
canonical: https://truto.one/blog/connect-intruder-to-claude-monitor-targets-manage-security-issues/
---

# Connect Intruder to Claude: Monitor Targets & Manage Security Issues

**Intruder in Claude, in about a minute.** The best way to connect Intruder to Claude is Elaichi: connect Intruder to Elaichi once, then add Elaichi to Claude as a connector. Two steps, about a minute, with a 14-day free trial and no credit card required.

1. **Start your free trial.** Create your Elaichi account. 14 days free, no credit card required.
2. **Connect Intruder.** Connect Intruder once in Elaichi. Claude never gets more access than you have.
3. **Add Elaichi to Claude.** In Claude, open Customize, then Connectors, press Add and paste https://api.elaichi.ai/mcp. Sign in and approve.

[Start free on Elaichi, 14 days, no credit card required](https://app.elaichi.ai/signup?utm_source=truto.one&utm_medium=referral&utm_campaign=launchpad&utm_content=post_markdown&utm_term=intruder) · [Intruder on Elaichi](https://elaichi.ai/connectors/intruder/?utm_source=truto.one&utm_medium=referral&utm_campaign=launchpad&utm_content=post_markdown&utm_term=intruder)

*Building Intruder into your own product? The guide below is for you.*

---

If you need to connect Intruder to Claude to automate vulnerability scans, monitor attack surfaces, or triage new security issues, you need a [Model Context Protocol (MCP) server](https://truto.one/the-hands-on-guide-to-building-mcp-servers-for-ai-agents-2026/). This server acts as the translation layer between Claude's natural language tool calls and Intruder's REST API. You can either build, host, and maintain this infrastructure yourself, or use a managed integration platform like Truto to dynamically generate a secure, authenticated MCP server URL. If your team uses ChatGPT, check out our guide on [connecting Intruder to ChatGPT](https://truto.one/connect-intruder-to-chatgpt-automate-vulnerability-scans-audits/) or explore our broader architectural overview on [connecting Intruder to AI Agents](https://truto.one/connect-intruder-to-ai-agents-orchestrate-scans-issue-remediation/).

Giving a Large Language Model (LLM) read and write access to a vulnerability management platform like Intruder is an engineering challenge. You have to handle API token lifecycles, map complex vulnerability schemas to MCP tool definitions, and deal with Intruder's specific domain logic around targets and occurrences. Every time the underlying API changes, you have to update your server code, redeploy, and test the integration.

This guide breaks down exactly how to use Truto to generate a secure, managed MCP server for Intruder, connect it natively to Claude Desktop, and execute complex security operations using natural language.

> Want to give your AI agents secure, authenticated access to Intruder and 100+ other SaaS APIs? Let's talk about managed MCP architecture.
>
> [Talk to us](https://truto.one/book-a-demo/)

## The Engineering Reality of the Intruder API

A custom [MCP server](https://truto.one/the-hands-on-guide-to-building-mcp-servers-for-ai-agents-2026/) is a self-hosted integration layer. While the open MCP standard provides a predictable way for models to discover tools, the reality of implementing it against specialized B2B APIs is painful. Intruder is built to manage continuous attack surface monitoring, and its API reflects the complexity of tracking ephemeral vulnerabilities across shifting infrastructure.

If you decide to build a custom Intruder MCP server, here are the specific integration challenges you will face:

**The Issue vs. Occurrence Data Model**
Intruder separates the concept of an "Issue" (the theoretical vulnerability, like "Outdated Nginx Version") from an "Occurrence" (the specific instance of that vulnerability on a specific target port). If you ask an LLM to "fix an issue," it cannot just patch the top-level issue record. It must list all occurrences of that issue, extract the stable `occurrence_id` (which persists across scans, unlike the ephemeral `id` which may change), and interact with those specific occurrences. Your MCP server must expose discrete endpoints for both entities and provide schemas that explicitly guide the LLM on how to map `issue_id` to `occurrence_id`.

**Asynchronous Scan Lifecycles**
Starting a vulnerability scan in Intruder is an asynchronous operation. When an LLM calls the scan creation endpoint, it receives a scan ID, not the results. The scan could take minutes or hours depending on the target scope. An LLM cannot leave a connection hanging. Your integration layer must provide polling mechanisms - separate tools for checking scan status and retrieving completed scan details - so the agent can check back periodically without timing out the initial JSON-RPC request.

**Target Authentication Payloads**
Adding a target to Intruder is rarely just providing an IP address. When adding targets that require authentication (like web apps behind login screens), the API requires complex nested schemas (`target_authentication`) or multipart form uploads for API schemas. Building a tool definition that accurately represents this multipart schema to an LLM, while keeping the tool payload flat enough for reliable function calling, requires significant data transformation logic in your MCP router.

## How to Generate the Intruder MCP Server

Truto eliminates the need to build a custom server by dynamically generating an MCP JSON-RPC endpoint directly from your connected Intruder account. You can create this server through the Truto UI or programmatically via the API.

### Method 1: Via the Truto UI

For teams managing integrations manually, the UI provides the fastest path to an MCP URL.

1. Navigate to the **Integrated Accounts** page in your Truto dashboard.
2. Select your connected Intruder account.
3. Click the **MCP Servers** tab.
4. Click **Create MCP Server**.
5. Select your desired configuration (name, allowed methods, tags, and expiration).
6. Copy the generated MCP server URL (e.g., `https://api.truto.one/mcp/a1b2c3d4e5f6...`).

### Method 2: Via the Truto API

For developers embedding AI features into their own applications, you can generate MCP servers programmatically. Truto validates the integration, generates a cryptographically hashed token, stores it in Cloudflare KV for low-latency lookup, and returns the ready-to-use URL.

```typescript
// POST /integrated-account/{integrated_account_id}/mcp
const response = await fetch('https://api.truto.one/integrated-account/int_abc123/mcp', {
  method: 'POST',
  headers: {
    'Authorization': 'Bearer YOUR_TRUTO_API_KEY',
    'Content-Type': 'application/json'
  },
  body: JSON.stringify({
    name: "SecOps Triage Agent MCP",
    config: {
      methods: ["read", "write"], // Restrict to specific HTTP methods
      require_api_token_auth: false
    },
    expires_at: "2026-12-31T23:59:59Z" // Optional time-to-live
  })
});

const mcpServer = await response.json();
console.log(mcpServer.url); 
// Output: https://api.truto.one/mcp/a1b2c3d4e5f6...
```

## How to Connect the MCP Server to Claude

Once you have your Truto MCP URL, connecting it to Claude requires zero additional coding. The URL contains a secure cryptographic token that encodes the specific Intruder account and access policies.

### Method A: Via the Claude UI (Desktop/Web)

If you are using Claude Desktop or the web interface with Enterprise/Team plans, you can add the server visually:

1. Open Claude and navigate to **Settings** -> **Integrations** -> **Add MCP Server**.
2. Provide a recognizable name (e.g., "Intruder Security").
3. Paste the Truto MCP URL into the connection field.
4. Click **Add**. Claude will automatically perform the MCP handshake and populate the available Intruder tools.

### Method B: Via Manual Config File

If you are running Claude Desktop locally and prefer file-based configuration, or if you are integrating with an open-source agent framework, you can use the Server-Sent Events (SSE) transport via the official MCP CLI.

Edit your `claude_desktop_config.json` file (typically located in `~/Library/Application Support/Claude/` on macOS or `%APPDATA%\Claude\` on Windows):

```json
{
  "mcpServers": {
    "intruder_truto": {
      "command": "npx",
      "args": [
        "-y",
        "@modelcontextprotocol/server-sse",
        "https://api.truto.one/mcp/a1b2c3d4e5f6..."
      ]
    }
  }
}
```

Restart Claude Desktop. The application will initialize the connection and Truto will dynamically generate the tool definitions based on Intruder's active API schemas.

## Hero Tools for Intruder

When Claude connects to the Intruder MCP server, it gains access to a curated set of tools. Truto derives these tools dynamically from the integration's resource definitions. 

Here are the most high-leverage tools available for orchestrating security workflows.

### List All Intruder Issues

This tool retrieves the top-level vulnerabilities currently identified in your infrastructure. It supports robust filtering by severity, snoozing status, target addresses, and time bounds.

**Contextual Usage Notes:** Use this tool as the starting point for triage. Because Intruder groups vulnerabilities by issue, this endpoint returns the `id` required to fetch specific occurrences. 

> "Fetch all critical and high-severity issues discovered in Intruder over the past 7 days that are not currently snoozed."

### List All Intruder Issue Occurrences

Retrieves the specific instances of an issue across your targets. 

**Contextual Usage Notes:** An LLM must provide the `issue_id` retrieved from the previous tool. This tool returns the `occurrence_id` (the stable ID that persists across scans) and the `target` details, which are necessary for commenting or remediation verification.

> "For the issue ID 'iss_89234', list all specific occurrences so I can see which internal IP addresses and ports are affected."

### Create an Intruder Target

Adds a new target (IP address, hostname, or URL) to your Intruder attack surface.

**Contextual Usage Notes:** When adding web targets, you can also pass `target_authentication` parameters if the endpoint requires logging in to scan properly. The API returns the new target's `id` and `target_status`.

> "Add staging-api.example.com as a new target in Intruder. Tag it as 'pre-production'."

### Intruder Targets Bulk Create

Adds multiple targets simultaneously, including expanding CIDR ranges into individual target entities.

**Contextual Usage Notes:** This is essential for infrastructure-as-code pipelines where an LLM is given a subnet mask and needs to register the entire block for scanning.

> "Bulk register the following CIDR range in Intruder: 192.168.1.0/24, and tag all resulting targets as 'internal-network'."

### Create an Intruder Scan

Triggers an immediate vulnerability scan.

**Contextual Usage Notes:** By default, calling this with no body will scan *all* targets in the account. To limit the blast radius, pass specific `target_addresses` or `tag_names` in the body payload. The tool returns a `scan_id` which must be saved for polling.

> "Start a new Intruder scan exclusively targeting infrastructure tagged with 'pre-production'. Give me the scan ID so we can check on it later."

### Create an Intruder Occurrence Comment

Appends a note or status update to a specific vulnerability occurrence.

**Contextual Usage Notes:** Requires both `issue_id` and `occurrence_id`. This is highly useful for AI agents performing automated triage, allowing them to document their findings directly in the Intruder dashboard for human review.

> "Add a comment to occurrence 'occ_123' under issue 'iss_456' stating: 'Investigated via Claude. False positive due to internal WAF blocking external payload. Recommending snooze.'"

*For the complete inventory of Intruder tools and their detailed JSON schemas, view the [Intruder integration page](https://truto.one/integrations/detail/intruder).* 

## Workflows in Action

An LLM's true power lies in orchestrating multiple tools to complete complex tasks. Here is how an [AI agent](https://truto.one/connect-intruder-to-ai-agents-orchestrate-scans-issue-remediation/) uses the Intruder MCP server in real-world SecOps scenarios.

### Workflow 1: Attack Surface Expansion & Scanning

When DevOps spins up new infrastructure, security teams need to ensure it is immediately monitored.

> "We just deployed a new cluster on 10.0.50.0/28. Add this entire CIDR range to Intruder, tag it as 'kubernetes-nodes', and immediately kick off a scan for just those new targets."

**Execution Steps:**
1. **`intruder_targets_bulk_create`**: The agent parses the CIDR range and sends the bulk payload with the tag 'kubernetes-nodes'.
2. **`create_a_intruder_scan`**: The agent triggers a new scan, explicitly passing `tag_names: ["kubernetes-nodes"]` in the body so it only hits the new infrastructure.
3. **Output**: Claude informs the user how many IPs were added from the CIDR block and provides the `scan_id` of the job that is currently running.

```mermaid
sequenceDiagram
    participant User as SecOps Engineer
    participant Claude as Claude Desktop
    participant Truto as Truto MCP Server
    participant Intruder as Intruder API

    User->>Claude: Add 10.0.50.0/28 and scan it
    Claude->>Truto: call intruder_targets_bulk_create (CIDR, tag)
    Truto->>Intruder: POST /targets/bulk
    Intruder-->>Truto: Target IDs created
    Truto-->>Claude: Return target summary
    Claude->>Truto: call create_a_intruder_scan (tag_names)
    Truto->>Intruder: POST /scans
    Intruder-->>Truto: scan_id: scn_8819
    Truto-->>Claude: Return scan_id
    Claude-->>User: Targets added and scan scn_8819 started.
```

### Workflow 2: Automated Vulnerability Triage

Alert fatigue is a massive issue. AI agents can act as first responders by analyzing new issues, drilling into the occurrences, and annotating the records.

> "Find all critical issues in Intruder. For each one, fetch its occurrences and add a comment that the AI SecOps assistant is currently cross-referencing these ports with our active WAF rules."

**Execution Steps:**
1. **`list_all_intruder_issues`**: The agent queries for issues with the parameter `severity: "critical"`.
2. **`list_all_intruder_issue_occurrences`**: The agent loops through the returned issues, calling this tool for each `issue_id` to retrieve the `occurrence_id`s.
3. **`create_a_intruder_occurrence_comment`**: The agent fires off comments to every identified occurrence, leaving an audit trail in the UI.
4. **Output**: Claude provides a summary list of exactly which occurrences were commented on.

## Security and Access Control

Exposing a security tool like Intruder to an AI model requires strict governance. If an LLM hallucinates, you do not want it accidentally deleting targets or cancelling critical compliance scans. Truto provides multiple layers of control at the MCP token level:

*   **Method Filtering**: You can configure the server to only allow `read` operations. This ensures the LLM can pull issue reports and target lists, but cannot call `create_a_intruder_scan` or `delete_a_intruder_target_by_id`.
*   **Tag Filtering**: Restrict the MCP server to only expose specific operational groups. For example, you can limit the LLM to only see tools tagged for `targets` and `issues`, hiding infrastructure and billing tools.
*   **Token Expiration (`expires_at`)**: Generate ephemeral MCP servers. If you are deploying an agent for a weekend security audit, set the server to expire on Monday morning. The Cloudflare KV entry automatically purges, instantly revoking access.
*   **Double Authentication (`require_api_token_auth`)**: By default, the cryptographically hashed MCP URL is the only authentication required. By enabling this flag, the client must also provide a valid Truto API token in the `Authorization` header, preventing usage if the URL leaks in logs.

## Handling Rate Limits in Truto

When automating Intruder with an LLM, the agent can easily make dozens of rapid requests - especially when looping through issues and occurrences. 

Truto operates as a transparent proxy for rate limits. **Truto does not automatically retry, throttle, or absorb rate limit errors.** If your agent hits Intruder's API limits and Intruder returns an HTTP 429 (Too Many Requests), Truto passes that 429 directly back to the MCP client.

However, to make programmatic backoff easier, Truto normalizes the upstream rate limit information into standardized IETF headers, regardless of how Intruder natively formats them. Every response includes:
*   `ratelimit-limit`: The total allowed requests in the current window.
*   `ratelimit-remaining`: The number of requests left.
*   `ratelimit-reset`: The timestamp when the quota resets.

Your MCP client, LangChain implementation, or AI agent framework is responsible for reading these headers and implementing its own retry or backoff logic.

## Strategic Wrap-Up

Connecting Claude to Intruder transforms your [vulnerability management platform](https://truto.one/connect-intruder-to-chatgpt-automate-vulnerability-scans-audits/) from a passive dashboard into an active participant in your security operations. Instead of manually clicking through menus to triage occurrences or update target lists, your team can orchestrate the entire attack surface through natural language.

By leveraging Truto's managed MCP architecture, you bypass the friction of OAuth lifecycles, API versioning, and schema mapping. You get a production-ready, fully authenticated JSON-RPC server that gives your AI agents immediate, secure access to your Intruder environment.

> Ready to connect your AI agents to Intruder, AWS, Jira, and your entire security stack? Book a demo to see Truto's managed MCP infrastructure in action.
>
> [Talk to us](https://truto.one/book-a-demo/)
