Best Wireshark MCP Servers
Wireshark is a network protocol analyzer that allows users to capture and examine data traveling across a network. It's widely used for network troubleshooting, analysis, software development, and education.
Why this server?
Performs deep packet inspection and network forensics on PCAP files, including protocol analysis and credential extraction using TShark.
AsecurityAlicense-qualityA comprehensive security testing MCP server providing 51 tools for penetration testing, network forensics, memory analysis, and vulnerability assessment. It enables automated security audits and technical investigations across web applications, cloud environments, and network captures.Last updated 11 days ago511493MITWhy this server?
Provides tools for analyzing network traffic and pcap files, including packet summarization, deep packet dissection, stream reassembly, and automated extraction of HTTP requests, DNS queries, and credentials.
AsecurityAlicense-qualityAn MCP server that enables LLMs to analyze pcap files by providing tools for packet dissection, stream following, and data extraction via tshark. It supports protocol hierarchy analysis, credential scanning, and threat intelligence checks on captured network traffic.Last updated 13 days ago2471MITWhy this server?
Leverages Wireshark's tshark tool to capture and analyze live network traffic, providing packet-level data, protocol statistics, conversation tracking, and credential extraction capabilities for network diagnostics and security analysis.
Why this server?
Provides network packet capture analysis capabilities similar to Wireshark's capinfos utility, enabling analysis of PCAP files for DNS, DHCP, ICMP, and TCP protocols with metadata extraction and packet statistics.
AsecurityAlicense-qualityEnables LLMs to analyze network packet captures (PCAP files) from local or remote sources through a modular architecture. Supports DNS traffic analysis with structured JSON responses for network security and troubleshooting tasks.Last updated 17 days ago833MITWhy this server?
Enables packet capture and analysis through Wireshark/tshark integration, allowing the agent to start recording network traffic, analyze packet contents, apply filters, decrypt SSL/TLS traffic, and troubleshoot network issues
Why this server?
Enables packet capture and analysis using Wireshark's CLI tool (tshark) for network traffic inspection.
AsecurityFlicense-qualityEnables AI assistants to perform authorized penetration testing and security assessments by exposing 20+ Kali Linux security tools (nmap, sqlmap, gobuster, hydra, etc.) through a safe, validated interface with command allowlists, rate limiting, and input sanitization.Last updated 4 months ago19Why this server?
Suggested as a tool for analyzing network traffic to extract Eufy RoboVac device credentials.
AsecurityFlicense-qualityA Model Context Protocol server for controlling Eufy RoboVac vacuum cleaners, enabling users to scan for devices, connect to them, and execute various cleaning commands through natural language.Last updated 9 months ago201,0301Why this server?
Enables network traffic analysis through tshark and Wireshark tools for examining packet captures and forensic investigation of network communications.
-securityAlicense-qualityExposes common CTF and cybersecurity tools (crypto, forensics, malware analysis, steganography, reverse engineering, pwn, OSINT) so LLMs can help solve capture-the-flag challenges in a controlled lab environment.Last updated 4 months agoMITWhy this server?
Enables network packet analysis and sniffing through the kali_sniffing_spoofing tool alongside other network capture utilities.
AsecurityFlicense-qualityProvides access to 20+ Kali Linux penetration testing tools through isolated Docker containers, enabling network scanning, vulnerability assessment, password cracking, web security testing, and forensics through natural language commands.Last updated 4 months ago262