Wireshark-MCP
Related Servers
Alternatives to Wireshark-MCP
No user-submitted related servers found.
Related Servers
- FlicenseCqualityDmaintenanceEnables LLMs to capture, analyze, and summarize network traffic using Wireshark CLI tools, supporting live capture, pcap analysis, and LLM-oriented summaries.76-
- AlicenseAqualityAmaintenanceEnables AI assistants to analyze, filter, and capture network traffic using Wireshark/tshark, allowing natural language interaction with packet captures.1462 PyPI58MIT
- AlicenseNot gradedqualityDmaintenanceEnables AI assistants to analyze network traffic using Wireshark/tshark, providing packet statistics, protocol analysis, and anomaly detection through natural language interaction.69MIT
- AlicenseAqualityDmaintenanceEnables LLMs to analyze network packet captures (PCAP files) from local or remote sources through a modular architecture. Supports DNS traffic analysis with structured JSON responses for network security and troubleshooting tasks.9177 PyPI51MIT
- FlicenseNot gradedqualityDmaintenanceExposes Wireshark/tshark packet capture, analysis, threat detection, and reporting tools for AI agents and local testing.-
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to analyze PCAP files for network forensics using Wireshark/tshark, providing high-performance packet inspection, filtering, and protocol analysis through the Model Context Protocol.2MIT
TDQS
Scored across 34 tools
Multiple tools overlap in purpose, especially in the webshell and detection categories (detect_webshell vs. auto_webshell vs. analyze_webshell; detect_suspicious vs. detect_port_scan vs. advanced_threat_detection). Also quick_triage overlaps with summary_stats and get_top_talkers, and analyze_lateral_movement overlaps with analyze_rdp_attack_chain and extract_ntlm_hashes. The descriptions help, but the boundaries remain unclear.
Most tools follow a verb_noun pattern (detect_, analyze_, extract_, capture_, run_, list_), but there are notable outliers like advanced_threat_detection, quick_triage, auto_webshell, and summary_stats which use adjective or noun forms. The mixed style is still readable and largely predictable, but not fully consistent.
34 tools is on the heavier side, especially with several highly specific CTF/webshell utilities (solve_solar_challenge, brute_force_webshell). However, the domain is complex and warrants a broad toolkit, so the count is not excessive but feels bloated with overlapping features.
The server covers a wide range of traffic analysis, live capture, IOC extraction, credential harvesting, webshell decryption, and RDP/NTLM forensics. Gaps are minor, such as no direct packet modification or a dedicated tool for listing loaded sessions, but core workflows are well supported.