Wireshark-MCP
Provides network traffic analysis capabilities using Wireshark/TShark, including PCAP analysis, live capture, threat detection, and forensic investigation tools.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Wireshark-MCPquick triage on /pcaps/attack.pcap"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Wireshark-MCP
一个基于 Model Context Protocol (MCP) 的网络流量分析服务器,让大语言模型 (LLM) 能够使用 Wireshark/TShark 的强大功能进行自动化的网络取证、威胁狩猎和流量分析。
✨ 核心功能
离线分析 (PCAP)
PCAP 分析: 加载并解析 .pcap/.cap 文件
CTF 工具集: Flag 搜索、熵值分析、自动解码
Webshell 检测: 冰蝎/哥斯拉/蚁剑指纹识别和流量解密
威胁检测: 自动识别 SQL 注入、XSS、Webshell、C2 通信等
IOC 提取: 自动提取 IP、域名、URL、User-Agent 等情报
流重组: 自动追踪 TCP 流并提取文件/文本
实时抓包
Live Capture: 从网络接口实时捕获流量
协议统计: 协议层次分析和会话统计
威胁情报: IP 黑名单查询 (URLhaus)
凭据提取: HTTP Basic/FTP/Telnet/Kerberos 凭据提取
AI 辅助
结构化输出: 统一的 JSON 格式
{summary, findings, next_steps}标准调查流程: CTF/取证专用调查 Prompt
智能工具调用: 详细的工具描述,自动引导 AI 使用
Related MCP server: Wireshark MCP
🚀 快速开始
详细安装、配置、使用请参阅:INSTALL_AND_CONFIG.md
MCP 客户端配置(Windows 本地 / Stdio)
将以下配置添加到你的 MCP 客户端配置文件中(如 mcp.json / Trae / Claude Desktop 配置)。该配置适配本仓库的 Windows 目录结构与 run_mcp.py 启动方式:
{
"mcpServers": {
"Local-win-wireshark": {
"command": "E:\\mcp-wireshark\\venv\\Scripts\\python.exe",
"args": [
"-u",
"E:\\mcp-wireshark\\run_mcp.py",
"--workdir",
"E:\\mcp-wireshark",
"--tshark-path",
"E:\\Wireshark\\tshark.exe",
"--allow-outside-workdir",
"--allow-all-tshark-args"
]
}
}
}可用工具列表
类别 | 工具名 | 功能 |
基础 |
| 列出目录中的 PCAP 文件 |
| 加载 PCAP 并创建分析会话 | |
| 获取协议统计和 Top Talkers | |
一键 |
| 快速态势感知:协议/Top Talkers/IOC/推荐下一步(支持 |
| 一键横向线索:NTLM/SMB/WinRM/RDP 关联(支持 | |
| 一键 Webshell:检测→提钥→尝试解密→提取战利品到 loot(支持 | |
| 题型一键:从 PCAP 自动抽取关键字段并计算最终 flag(支持 | |
过滤 |
| 应用显示过滤器 |
| 执行任意 tshark 命令 | |
追踪 |
| 追踪 TCP 流并提取内容 |
检测 |
| 基于规则检测可疑活动 |
| 检测端口扫描行为 | |
| 检测加密 Webshell 流量 | |
CTF |
| 搜索 CTF Flag 模式 |
| 香农熵分析(检测加密/压缩) | |
| 自动 Base64/hex/URL 解码 | |
Webshell |
| 提取解密密钥 |
| 解密冰蝎/哥斯拉/蚁剑流量 | |
| 字典爆破解密密钥 | |
取证 |
| 提取 IOC(IP、域名、URL) |
| 生成网络事件时间线 | |
| 导出 HTTP 对象和文件 | |
| 提取明文凭据和 Kerberos Hash | |
时序 |
| 检测 C2 心跳和周期性通信 |
实时 |
| 实时抓包并返回 JSON |
| 实时抓包并获取协议统计 | |
| 实时抓包并获取会话统计 | |
| 查询 IP 威胁情报 |
说明:
多数工具支持
session_id或pcap_path二选一(更方便 AI 直接对任意目录的 PCAP 做一次调用得到结果)。
decrypt_rdp/analyze_rdp_attack_chain输出以“取证线索/关联分析”为主,并不承诺一定能完成 TLS/NLA/CredSSP 全量解密。
CTF 使用示例
# 1. 加载 PCAP
load_pcap(pcap_path="./pcaps/attack.pcap")
# 2. 搜索 Flag
search_patterns(session_id="xxx", search_flag=True)
# 3. 检测加密
analyze_entropy(session_id="xxx", stream_index=5)
# 4. 自动解码
decode_stream(session_id="xxx", stream_index=5, encoding="auto")
# 5. 检测 Webshell
detect_webshell(session_id="xxx")
# 6. 暴力破解密钥
brute_force_webshell(session_id="xxx", tool_type="behinder", stream_index=5)📜 许可证
MIT License
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityBmaintenanceEnables LLMs to analyze network packet captures (PCAP files) from local or remote sources through a modular architecture. Supports DNS traffic analysis with structured JSON responses for network security and troubleshooting tasks.951MIT
- Flicense-qualityCmaintenanceExposes Wireshark/tshark packet capture, analysis, threat detection, and reporting tools for AI agents and local testing.
- AlicenseAqualityAmaintenanceEnables AI assistants to analyze, filter, and capture network traffic using Wireshark/tshark, allowing natural language interaction with packet captures.1454MIT
- Alicense-qualityDmaintenanceEnables AI assistants to analyze network traffic using Wireshark/tshark, providing packet statistics, protocol analysis, and anomaly detection through natural language interaction.66MIT
Related MCP Connectors
AI-powered threat intelligence, smart contract auditing, and cybersecurity OSINT.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Gentle-bae/mcp-wireshark'
If you have feedback or need assistance with the MCP directory API, please join our Discord server