wireshark
Provides tools for analyzing the open Wireshark capture with tshark and controlling the Wireshark GUI, including applying display filters, highlighting packets, marking frames, setting packet-list columns, and sending selected packets to Claude.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@wiresharkFilter to mDNS queries and highlight frames from 192.0.2.10"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
wireshark-claude-bridge
Work with Claude directly on the capture you have open in Wireshark. Claude can analyse the
capture with tshark, and it can change what you see in the Wireshark GUI: apply display
filters, highlight packets, mark frames, and define packet-list columns. You can also send
Claude the packet you are looking at with a right-click.
It has two parts:
File | Runs in | What it does |
| Claude Desktop (local MCP server) | Runs |
| Wireshark (Lua plugin) | Adds a Tools > Claude menu. Sync applies the queued commands inside the GUI |
Claude Desktop ──MCP──► wireshark_claude_mcp.py ──► tshark ──► capture file (analysis)
│
└──► %APPDATA%\Wireshark\claude_bridge\commands.txt
│
Wireshark ◄── claude_bridge.lua ┘ (you click Tools > Claude > Sync)Wireshark's Lua API has no timers or sockets, so the plugin cannot pick up Claude's commands on its own. One click on Sync is the trade-off.
Requirements
Windows 10/11 (macOS and Linux should work but are untested; see Other platforms)
Wireshark 3.6 or newer, which includes
tsharkand Lua supportPython 3.10 or newer
Claude Desktop
Related MCP server: Wireshark MCP
Installation
1. Get the files
git clone https://github.com/JimmyTaylor75/wireshark-claude-bridge.gitOr download the repository as a ZIP and extract it somewhere permanent, for example
C:\Tools\wireshark-claude-bridge. Claude Desktop runs the server from this location, so
don't leave it in Downloads.
2. Install the Python dependency
Use the same Python you will point Claude Desktop at in step 4:
"C:\Path\To\python.exe" -m pip install -r requirements.txtTo find your Python's full path, run where python (Windows) or py -0p.
3. Install the Wireshark plugin
In Wireshark, open Help > About Wireshark > Folders and note the Personal Lua Plugins path. On Windows it is usually
%APPDATA%\Wireshark\plugins.Copy
claude_bridge.luainto that folder (create it if it doesn't exist).Restart Wireshark, or use Analyze > Reload Lua Plugins (Ctrl+Shift+L).
Check that Tools > Claude now has Sync and Show bridge log. Show bridge log should say
Claude bridge v1.1 loaded.
4. Register the server in Claude Desktop
Open %APPDATA%\Claude\claude_desktop_config.json (in Claude Desktop: Settings > Developer >
Edit Config) and add a wireshark entry under mcpServers:
{
"mcpServers": {
"wireshark": {
"command": "C:\\Path\\To\\python.exe",
"args": ["C:\\Tools\\wireshark-claude-bridge\\wireshark_claude_mcp.py"],
"env": { "TSHARK_PATH": "C:\\Program Files\\Wireshark\\tshark.exe" }
}
}
}Every backslash in a JSON path must be doubled (
\\).commandmust be the full path to the Python from step 2. A barepythonmay resolve to a different interpreter that doesn't havemcpinstalled.If the file already has other servers, add
wiresharkalongside them inside the samemcpServersobject.
5. Restart Claude Desktop fully
Closing the window isn't enough, because Claude Desktop keeps running in the system tray. Right-click the tray icon and choose Quit, then start it again.
In Settings > Developer, the wireshark server should show as running. Start a new
chat so the tools are available in it.
Usage
Open a capture
Ask Claude to set the capture, using the full Windows path:
Set my capture to "C:\Users\me\Downloads\trace.pcapng"
Claude can now analyse the file. It also queues the file to open in the GUI, so click Tools > Claude > Sync to load it. Opening is asynchronous: if other commands were queued after the open, click Sync a second time once the file has loaded.
You can also open the file yourself with File > Open. Claude reads the file from disk, so
you are both looking at the same frames either way. Claude still needs set_capture to know
which file to analyse.
Ask questions
Analysis needs no Sync click. Examples:
Give me a summary of this capture.
Show every mDNS query for _googlecast with source, TTL and query name.
Which hosts send SSDP M-SEARCH, and does anything answer them?
Compare DHCP traffic between this capture and C:\caps\working.pcapng.
Show me the full decode of frame 1130.
Change the Wireshark view
GUI changes are queued, then applied when you click Tools > Claude > Sync:
Filter to mDNS and SSDP, highlight the queries from 192.0.2.10, and mark frame 1234.
Filters are checked with
tsharkbefore they are queued, so a typo is rejected instead of turning your filter bar red.Highlights use Wireshark's temporary colouring slots 1–9, the same slots as View > Colorize Conversation. They last until cleared or until Wireshark restarts. Sync repaints the packet list automatically.
Go to frame can't move your selection, because the Lua API has no function for it. Instead, the frame is marked in colour slot 10 and its number is copied to your clipboard. Press Ctrl+G, Ctrl+V, Enter to jump to it.
Columns are written to a dedicated Wireshark configuration profile called Claude. Wireshark only reads columns when a profile loads, so switch to the Claude profile (status bar, bottom right) after Claude sets them. If it's already active, switch away and back.
Show Claude a packet
Right-click a packet and choose Claude > Send frame to Claude, then ask your question:
What's wrong with the frame I just sent?
Claude can't see your selection unless you send it this way, or tell it the frame number.
Check what happened
Tools > Claude > Show bridge log in Wireshark lists every command applied or failed.
Ask Claude "what's the GUI state?". It reads the last Sync result, any frame you sent, and any commands still waiting for a Sync.
Tools reference
Analysis (runs immediately)
Tool | Purpose |
| Select the capture to analyse, and optionally queue opening it in the GUI |
| Protocol hierarchy and top IPv4 conversations |
| Table of matching packets with any Wireshark fields; frame number and relative time are always included |
| Full protocol tree for one frame, optionally limited to some layers |
| Any |
| Same query against the current capture and another one, side by side |
GUI (applied on Sync)
Tool | Purpose |
| Apply a display filter (validated first). Empty string clears it |
| Colour matching packets using slot 1–9 |
| Clear all ten colour slots |
| Mark the frame (slot 10) and copy its number for Ctrl+G |
| Write packet-list columns to the Claude profile |
| Last Sync state, the frame you sent, and pending commands |
gui_set_columns takes a list like
[{"title": "TTL", "field": "ip.ttl"}, {"title": "Info", "field": "%i"}]. Built-in columns
use Wireshark's format codes: %m (No.), %t (Time), %Rt (relative time), %s (Source),
%d (Destination), %p (Protocol), %L (Length), %i (Info).
Troubleshooting
Symptom | Fix |
Claude says it has no Wireshark tools | Check Settings > Developer in Claude Desktop. Quit fully from the tray and restart, then start a new chat |
Server shows an error in Claude Desktop | Read |
| Set |
No Tools > Claude menu | The plugin isn't loaded. Check the folder in Help > About Wireshark > Folders, then Ctrl+Shift+L. Help > About Wireshark > Plugins shows load errors |
Sync says "nothing queued" | The commands were already applied by an earlier Sync. Ask Claude for the GUI state |
Highlights don't show | Toggle View > Colorize Packet List off and on. The bridge log says whether the automatic repaint ran |
Columns don't change | Switch to the Claude profile, or away and back if it's already active |
Commands after an | The file was still loading. Click Sync again |
To test the server outside Claude Desktop, run it in a terminal:
"C:\Path\To\python.exe" "C:\Tools\wireshark-claude-bridge\wireshark_claude_mcp.py"It should sit silently, waiting for MCP input (press Ctrl+C to stop). A traceback shows what's wrong.
Other platforms
The server finds Wireshark's configuration folder at %APPDATA%\Wireshark on Windows and
~/.config/wireshark on macOS and Linux. If your Wireshark uses a different folder (check
Help > About Wireshark > Folders > Personal configuration), set WS_CLAUDE_CONF_DIR to it
in the server's env block. On macOS, tshark usually lives at
/Applications/Wireshark.app/Contents/MacOS/tshark.
Environment variables
Variable | Purpose |
| Full path to |
| Wireshark personal configuration folder, if not the default |
Limitations
GUI changes need a click on Sync.
The plugin can't move the packet selection. Go to frame marks the frame and copies its number instead.
Columns only load on a profile switch.
Command output is capped at 20,000 characters per call, so very broad queries are truncated. Narrow the filter or lower the row limit.
Privacy and data handling
Packet contents reach Claude through tool results in your conversation. Captures can contain IP and MAC addresses, hostnames, credentials and other personal or confidential data. Check your organisation's data-handling rules before using this on production or customer captures.
Changelog
v1.1
Go to frame now marks the frame in colour slot 10 and copies its number to the clipboard. The previous version called a function that doesn't exist in Wireshark's Lua API.
Sync repaints the packet list after colour changes.
Highlight slots are limited to 1–9; slot 10 is reserved for go-to-frame.
v1.0
Initial release.
This server cannot be deployed
Maintenance
Related MCP Connectors
Use your own Mac from ChatGPT, Claude or Codex: files, commands, documents, and a browser.
A paid remote MCP for ClawManager, built to return verdicts, receipts, usage logs, and audit-ready J
Financial data MCP server for Claude, ChatGPT, Cursor and Codex. Real-time stock quotes, financial statements, options flow, SEC filings, insider trades, 13F holdings, macro data and market news from gloom.sh, the open-source Bloomberg Terminal alternative.
- QuallaaOAuthcom.quallaa
Talk to your public-facing AI from any MCP client — Claude, ChatGPT, Cursor, Cline, Windsurf.
Related MCP Servers
- AlicenseBqualityDmaintenanceEnables LLMs to load and analyze PCAP/PCAPNG files using Wireshark's sharkd interface, supporting packet inspection, traffic structure, conversations, and protocol statistics through natural language.3075MIT
- FlicenseNot gradedqualityDmaintenanceExposes Wireshark/tshark packet capture, analysis, threat detection, and reporting tools for AI agents and local testing.-
- AlicenseNot gradedqualityCmaintenanceBridges AI assistants and network packet analysis by exposing Wireshark/TShark functionality through MCP, enabling PCAP investigation, protocol discovery, packet filtering, stream analysis, and live capture.MIT
- AlicenseNot gradedqualityBmaintenanceEnables AI assistants to interact with tshark and related command-line tools for live packet capture, PCAP analysis, filtering, stream following, and capture file merging.1MIT