Skip to content

How to Detect Suspicious Logins with Claude

Detect suspicious login locations with Claude and ToolRouter. IP-based fraud detection in seconds.

Tool
IP Geolocation icon
IP Geolocation

Claude brings analytical rigor to login anomaly detection by calculating geographic distance, assessing travel feasibility, and evaluating ISP fingerprints against user baselines. It asks clarifying questions about your security thresholds to refine the risk assessment for each flagged login attempt.

Connect ToolRouter to Claude

1Open connector settings Open Settings
2Add a custom connector with these details
Name
ToolRouter
URL
https://api.toolrouter.com/mcp
3Let Claude set you up Open Claude

Steps

Once connected (see setup above), use the IP Geolocation tool:

  1. Ask Claude: "Look up the location of this login IP using ip-geolocation" and provide the IP
  2. Claude returns the geographic details
  3. Ask: "Compare this location against the user's previous logins from New York"
  4. Claude flags whether the location is suspicious based on distance and timing

Example Prompt

Try this with Claude using the IP Geolocation tool
Look up the location of 185.220.101.34. A user who normally logs in from San Francisco just authenticated from this IP. Is this suspicious?

Tips

  • Check for VPN and proxy indicators in the ISP data
  • Compare timestamps between logins to detect impossible travel
  • Build a baseline of normal login locations for each user