Skip to main content
Glama
bx33661

Wireshark MCP

by bx33661

Give your AI assistant a packet analyzer.

Drop a .pcap file, ask questions in plain English — get answers backed by real tshark data.


What is this?

An MCP server that wraps tshark (and optional Wireshark suite tools) into a structured analysis interface. Works with Claude Desktop, Claude Code, Cursor, VS Code, and 18+ other MCP clients.

You:    "Find all DNS queries going to suspicious domains in this capture."
Claude: [calls wireshark_extract_dns_queries → wireshark_detect_dns_tunnel]
        "Found repeated high-entropy DNS queries consistent with tunneling: ..."

Related MCP server: AutoSOC Agent

Install

Prerequisites: Python 3.10+ and Wireshark with tshark on PATH.

pip install wireshark-mcp
wireshark-mcp install   # auto-configures all detected MCP clients

Restart your AI client — done.

Run wireshark-mcp doctor if anything looks off. See docs/manual-configuration.md for manual setup or platform-specific notes.


Quick Start

Point your AI client at a .pcap file and try:

Analyze capture.pcap using the Wireshark MCP tools.
Start with wireshark_open_file, then run wireshark_quick_analysis.
Write findings to report.md.

Tools

51 tools, each backed by real tshark output — organized into categories:

Category

Highlights

Count

Entry & Workflow

wireshark_open_file, wireshark_quick_analysis

2

Packet Analysis

Packet list, details, bytes, context, stream follow, search, file info

8

Data Extraction

HTTP requests, DNS queries, arbitrary fields, object export

4

Statistics

Protocol hierarchy, endpoints, conversations, I/O graph, expert info, service response time, flow graph

7

Security & Anomaly

Credential scan, port scan, DNS tunnel, DoS, beaconing, exfiltration, protocol anomalies, YARA

8

Protocol Analysis

wireshark_analyze_protocol (20 protocols), TCP health, ARP spoofing

3

Decrypt & Dissection

TLS/WPA decrypt, decryption check, decode-as, protocol preferences

5

Forensics & Enrichment

TLS fingerprints, file signature scan, GeoIP

3

File Ops, Capture & Suite

Live capture, interfaces, merge, filter-save, editcap trim/split/dedup/time-shift, frame extract, text2pcap, capabilities

11

One tool covers 20 protocols rather than 20 tools covering one each: wireshark_analyze_protocol takes a protocol argument (tls_handshakes, mqtt, modbus, s7comm, zigbee, wifi, rtp, kerberos, …) and applies the right fields and display filter for it. The field names are the point — s7comm.param.item.dbnum is not something a caller should have to guess, and a wrong guess returns an empty result that reads like a clean capture.

The server starts with only tshark required. Optional tools (capinfos, mergecap, editcap, dumpcap, text2pcap) are auto-detected and enable extra features when present.

Context cost

The tool list travels in the prompt prefix of every request your client sends, so its size is a fixed per-request cost. The default surface is ~21 KB — about 9 KB of parameter schema, 5 KB of descriptions, and 3 KB of read/write annotations — and it is byte-identical across restarts so clients can cache the prefix rather than re-reading it each session.

If your client never captures live traffic or writes pcaps, --profile advertises less:

Profile

Tools

Payload

Drops

full (default)

51

~21 KB

nothing

analysis

41

~17 KB

live capture, interface listing, all file-writing tools

core

33

~14 KB

the above, plus decryption, dissection overrides, and low-level views

wireshark-mcp serve --profile core

Every profile still contains every tool the bundled prompts, resources, skill files, and protocol recommendations can point the model at, so reducing the surface never leaves it chasing a tool that is not there.

Tool results are bounded too, since a result stays in the conversation for the rest of the session. Output over 8000 characters is truncated head-and-tail with a marker, and the tool's offset / limit / display_filter parameters are the way to page through the rest. Raise or lower the ceiling with:

export WIRESHARK_MCP_MAX_RESULT_CHARS=16000

Every tool also declares whether it reads or writes, so clients can auto-approve the 40 read-only analysis tools and still prompt for the 11 that create files (live capture, merge, filter-save, editcap, text2pcap, frame extract, object export).


Documentation

Topic

Link

Platform setup (macOS/Linux/Windows)

docs/platform-validation.md

Manual client configuration

docs/manual-configuration.md

Prompt templates

docs/prompt-engineering.md

Release checklist

docs/release-checklist.md

Contributing

CONTRIBUTING.md

Changelog

GitHub Releases

Security policy

SECURITY.md


Development

pip install -e ".[dev]"
pytest tests/ -v
ruff check src/ tests/

See CONTRIBUTING.md for the full guide.


Install Server
A
license - permissive license
B
quality
A
maintenance

Maintenance

Maintainers
Response time
2wRelease cycle
14Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    -
    quality
    B
    maintenance
    An MCP server that enables AI-assisted network packet analysis using Wireshark's TShark tool. It provides tools for pcap file overview, session extraction, protocol filtering, and statistical analysis through a standardized interface.
    Last updated
    1
    MIT
  • F
    license
    -
    quality
    D
    maintenance
    An automated security operations center MCP server that uses LLMs and network analysis tools like Tshark to detect threats in traffic data. It enables users to automatically ingest PCAP files, query specific packets, and generate intelligent security analysis reports.
    Last updated
  • F
    license
    -
    quality
    D
    maintenance
    An MCP server for analyzing network traffic and pcap files using tshark. It enables users to list TCP streams, extract application-layer payloads, and perform packet analysis with BPF filters.
    Last updated
    2

View all related MCP servers

Related MCP Connectors

  • MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.

  • Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.

  • MCP server providing access to the Scorecard API to evaluate and optimize LLM systems.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/bx33661/Wireshark-MCP'

If you have feedback or need assistance with the MCP directory API, please join our Discord server