Skip to main content
Glama
bx33661

Wireshark MCP

by bx33661

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault

No arguments

Capabilities

Features and capabilities supported by this server

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
wireshark_list_interfacesA

List available network interfaces for capture.

wireshark_captureB

Capture live network traffic. capture_filter: BPF syntax. ring_buffer: "filesize:1024,files:5".

wireshark_filter_saveB

Filter packets from a pcap and save to a new file using a Wireshark display filter.

wireshark_stats_protocol_hierarchyC

[PHS] Protocol hierarchy statistics showing distribution of protocols in the capture.

wireshark_stats_endpointsB

[Endpoints] List all endpoints and traffic stats. type: 'eth'|'ip'|'ipv6'|'tcp'|'udp'|'sctp'|'wlan'.

wireshark_stats_conversationsB

[Conversations] Communication pairs and stats. type: 'eth'|'ip'|'ipv6'|'tcp'|'udp'|'sctp'|'wlan'.

wireshark_stats_io_graphA

[I/O Graph] Traffic volume over time. interval: bucket size in seconds. filters: optional semicolon-separated display filters to break the traffic out by type, e.g. 'tcp;udp;dns'.

wireshark_stats_expert_infoC

[Expert Info] Automatic anomaly detection: retransmissions, errors, warnings, protocol issues.

wireshark_stats_service_response_timeC

[SRT] Service response time statistics. protocol: 'http'|'dns'|'smb' etc.

wireshark_get_packet_listC

[Summary] Packet list (top pane). TSV: No/Time/Src/Dst/Proto/Len/Info. custom_columns: comma-separated fields.

wireshark_get_packet_detailsA

[Detail] Full JSON for one packet. layers: comma-separated protocol filter (e.g. "ip,tcp,http").

wireshark_get_packet_bytesB

[Bytes] Raw hex/ASCII dump of a single packet.

wireshark_get_packet_contextB

[Context] Packets surrounding a specific frame (count before and after).

wireshark_read_packetsB

[DEPRECATED] JSON packet data. Use get_packet_list + get_packet_details instead.

wireshark_extract_fieldsB

[Tabular] Extract fields as TSV. fields: comma-separated (e.g. "ip.src,tcp.port,http.host").

wireshark_search_packetsC

[Search] Find packets by content.

wireshark_follow_streamC

[Stream] Reassemble stream with pagination. protocol: tcp|udp|tls|http|http2. output_mode: ascii|hex|raw.

wireshark_get_file_infoA

Get capture file metadata (type, packet count, duration, size) via capinfos.

wireshark_merge_pcapsC

Merge multiple capture files into one. input_files: comma-separated paths.

wireshark_quick_analysisC

[Agent] One-call traffic overview: file info, protocols, top talkers, conversations, hostnames, anomalies.

wireshark_get_capabilitiesA

Get Wireshark suite capabilities for this MCP server instance (available tools and versions).

wireshark_editcap_trimC

Trim capture to a timestamp window. Times in editcap format.

wireshark_editcap_splitC

Split capture into multiple files by packet count or time interval.

wireshark_editcap_time_shiftC

Shift packet timestamps by a relative number of seconds.

wireshark_editcap_deduplicateB

Remove duplicate packets using editcap's duplicate window matching.

wireshark_text2pcap_importB

Convert ASCII or hex dump into a capture file using text2pcap. encapsulation: link-layer type (default: ether).

wireshark_decode_asC

[Dissection] Decode-as for non-standard ports. Rules: 'tcp.port==8080,http;udp.port==5353,dns'.

wireshark_set_protocol_prefsD

[Dissection] Protocol preference overrides. Prefs: 'tcp.desegment_tcp_streams:TRUE;http.ssl.port:8443'.

wireshark_decrypt_tlsB

[Decrypt] Decrypt TLS traffic using SSLKEYLOGFILE, show HTTP data.

wireshark_decrypt_wpaB

[Decrypt] Decrypt WPA/WPA2 traffic with passphrase (+SSID).

wireshark_extract_framesA

[File] Extract specific frame ranges to a new pcap. Ranges: '1-10 15 20-30'.

wireshark_flow_graphB

[Stats] Flow/sequence graph showing packet exchange. Types: 'any', 'tcp', 'icmp'.

wireshark_analyze_protocolB

[Protocol] Analyze one protocol with the right fields and display filter already chosen.

Returns a summary plus matching rows, or "no traffic found". limit caps rows; rtp and smb return fixed-size tables and ignore it.

wireshark_analyze_tcp_healthB

[TCP] Analyze TCP connection health (retransmissions, dup ACKs, zero window, resets).

wireshark_detect_arp_spoofingB

[ARP] Detect potential ARP spoofing (duplicate IP-MAC, gratuitous floods, reply storms).

wireshark_detect_beaconingB

[Anomaly] Detect periodic communication patterns (C2 beacons) by analyzing connection timing intervals and jitter.

wireshark_detect_dns_tunnelB

[Security] Detect DNS tunneling (long queries, TXT abuse, subdomain entropy).

wireshark_detect_dos_attackB

[Security] Detect DoS/DDoS patterns (SYN flood, ICMP/UDP flood, DNS amplification).

wireshark_detect_exfiltrationA

[Anomaly] Detect data exfiltration (large outbound transfers, DNS length anomalies, non-standard ports).

wireshark_detect_port_scanA

[Security] Detect port scanning (SYN, FIN, NULL, Xmas scans). threshold: min unique dst ports to flag.

wireshark_detect_protocol_anomaliesB

[Anomaly] Detect protocol anomalies (known protocols on non-standard ports, unusual protocol distributions).

wireshark_export_objectsB

[Export] Extract embedded files from traffic. protocol: 'http'|'smb'|'tftp'|'imf'|'dicom'.

wireshark_extract_credentialsA

[Security] Scan for plaintext credentials (HTTP Basic Auth, FTP passwords, Telnet).

wireshark_extract_dns_queriesA

[DNS] Extract DNS query details (name, type, response flag) as TSV.

wireshark_extract_fingerprintsA

[Forensics] Extract JA3 (client) and JA3S (server) TLS fingerprints.

Matches against ~/.wireshark-mcp/fingerprints/*.json if you maintain any; no fingerprint list ships with this package. A JA3 identifies a TLS configuration, not an application, so treat any match as a lead to corroborate.

wireshark_extract_http_requestsB

[HTTP] Extract HTTP request details (method, URI, host, user-agent) as TSV.

wireshark_geoip_enrichA

[Enrichment] GeoIP lookup for unique IPs — country, city, ASN. Needs GeoLite2 DB.

wireshark_scan_file_signaturesA

[Forensics] Count packets containing a file magic number (PE, ELF, PDF, Office, archives, images).

An indicator, not an extraction — use wireshark_export_objects to get file bytes. A hit may be a coincidental byte sequence.

wireshark_verify_ssl_decryptionC

[TLS] Verify TLS decryption with SSLKEYLOGFILE-format keylog file.

wireshark_yara_scanC

[Security] YARA scan exported files. Detects malware, webshells, shellcode. protocol: http|smb|tftp.

wireshark_open_fileB

[Entry Point] Open a pcap and get protocol-aware tool recommendations. Returns protocols and relevant tools.

Prompts

Interactive templates invoked by user choice

NameDescription
security_auditComprehensive security audit of a network capture file.
performance_analysisNetwork performance analysis of a capture file.
incident_responseIncident response investigation workflow.
traffic_overviewQuick traffic overview and summary.
analyze_with_hypothesisHypothesis-driven traffic analysis — form, test, and refine hypotheses systematically.
investigate_alertInvestigate a single IOC/alert and expand the analysis outward.

Resources

Contextual data attached and managed by the client

NameDescription
get_display_filter_referenceWireshark display filter syntax cheatsheet with common examples.
get_protocol_field_referenceCommon Wireshark protocol field names for use in filters and extraction.
get_usage_guideWireshark MCP usage guide with recommended analysis workflows.
get_capabilitiesMachine-readable capability summary for the current Wireshark toolchain.

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/bx33661/Wireshark-MCP'

If you have feedback or need assistance with the MCP directory API, please join our Discord server