Wireshark-MCP
Wireshark-MCP,Give your AI assistant a packet analyzer. Drop a .pcap file, ask questions in plain English — get answers backed by real tshark data.
Documentation
What is this?
An MCP server that wraps `tshark` (and optional Wireshark suite tools) into a structured analysis interface. Works with Claude Desktop, Claude Code, Cursor, VS Code, and 18+ other MCP clients.
You: "Find all DNS queries going to suspicious domains in this capture."
Claude: [calls wireshark_extract_dns_queries → wireshark_detect_dns_tunnel]
"Found repeated high-entropy DNS queries consistent with tunneling: ..."Install
Prerequisites: Python 3.10+ and Wireshark with `tshark` on PATH.
pip install wireshark-mcp
wireshark-mcp install # auto-configures all detected MCP clientsRestart your AI client — done.
Run `wireshark-mcp doctor` if anything looks off. See docs/manual-configuration.md for manual setup or platform-specific notes.
Quick Start
Point your AI client at a `.pcap` file and try:
Analyze capture.pcap using the Wireshark MCP tools.
Start with wireshark_open_file, then run wireshark_quick_analysis.
Write findings to report.md.Tools
51 tools, each backed by real `tshark` output — organized into categories:
| Category | Highlights | Count |
|---|---|---|
| Entry & Workflow | `wireshark_open_file`, `wireshark_quick_analysis` | 2 |
| Packet Analysis | Packet list, details, bytes, context, stream follow, search, file info | 8 |
| Data Extraction | HTTP requests, DNS queries, arbitrary fields, object export | 4 |
| Statistics | Protocol hierarchy, endpoints, conversations, I/O graph, expert info, service response time, flow graph | 7 |
| Security & Anomaly | Credential scan, port scan, DNS tunnel, DoS, beaconing, exfiltration, protocol anomalies, YARA | 8 |
| Protocol Analysis | `wireshark_analyze_protocol` (20 protocols), TCP health, ARP spoofing | 3 |
| Decrypt & Dissection | TLS/WPA decrypt, decryption check, decode-as, protocol preferences | 5 |
| Forensics & Enrichment | TLS fingerprints, file signature scan, GeoIP | 3 |
| File Ops, Capture & Suite | Live capture, interfaces, merge, filter-save, editcap trim/split/dedup/time-shift, frame extract, text2pcap, capabilities | 11 |
One tool covers 20 protocols rather than 20 tools covering one each: `wireshark_analyze_protocol` takes a `protocol` argument (`tls_handshakes`, `mqtt`, `modbus`, `s7comm`, `zigbee`, `wifi`, `rtp`, `kerberos`, …) and applies the right fields and display filter for it. The field names are the point — `s7comm.param.item.dbnum` is not something a caller should have to guess, and a wrong guess returns an empty result that reads like a clean capture.
The server starts with only `tshark` required. Optional tools (`capinfos`, `mergecap`, `editcap`, `dumpcap`, `text2pcap`) are auto-detected and enable extra features when present.
Context cost
The tool list travels in the prompt prefix of every request your client sends, so its size is a fixed per-request cost. The default surface is ~21 KB — about 9 KB of parameter schema, 5 KB of descriptions, and 3 KB of read/write annotations — and it is byte-identical across restarts so clients can cache the prefix rather than re-reading it each session.
If your client never captures live traffic or writes pcaps, `--profile` advertises less:
| Profile | Tools | Payload | Drops |
|---|---|---|---|
| `full` (default) | 51 | ~21 KB | nothing |
| `analysis` | 41 | ~17 KB | live capture, interface listing, all file-writing tools |
| `core` | 33 | ~14 KB | the above, plus decryption, dissection overrides, and low-level views |
wireshark-mcp serve --profile coreEvery profile still contains every tool the bundled prompts, resources, skill files, and protocol recommendations can point the model at, so reducing the surface never leaves it chasing a tool that is not there.
Tool results are bounded too, since a result stays in the conversation for the rest of the session. Output over 8000 characters is truncated head-and-tail with a marker, and the tool's `offset` / `limit` / `display_filter` parameters are the way to page through the rest. Raise or lower the ceiling with:
export WIRESHARK_MCP_MAX_RESULT_CHARS=16000Every tool also declares whether it reads or writes, so clients can auto-approve the 40 read-only analysis tools and still prompt for the 11 that create files (live capture, merge, filter-save, editcap, text2pcap, frame extract, object export).
Documentation
| Topic | Link |
|---|---|
| Platform setup (macOS/Linux/Windows) | docs/platform-validation.md |
| Manual client configuration | docs/manual-configuration.md |
| Prompt templates | docs/prompt-engineering.md |
| Release checklist | docs/release-checklist.md |
| Contributing | CONTRIBUTING.md |
| Changelog | GitHub Releases |
| Security policy | SECURITY.md |
Development
pip install -e ".[dev]"
pytest tests/ -v
ruff check src/ tests/See CONTRIBUTING.md for the full guide.
Frequently asked questions
What is Wireshark-MCP?
Wireshark-MCP is Wireshark-MCP,Give your AI assistant a packet analyzer. Drop a .pcap file, ask questions in plain English — get answers backed by real tshark data.
How do I install Wireshark-MCP?
Open the GitHub repository and follow its README. Most MCP servers are added to your client's MCP config, then called by your agent.
Is Wireshark-MCP open source?
Yes — it is hosted on GitHub at https://github.com/bx33661/Wireshark-MCP and has 224 stars.
Related MCP tools
eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via MCP and humans via dashboard.
⚡ 需求分析效率提升 200%!全球首个为 AI 编程时代设计的团队协作 MCP 服务器,自动分析需求自动编写前后端代码,下载切图
MCP server and Claude plugin for Postgres skills and documentation. Helps AI coding tools generate better PostgreSQL code.
Decision audit trail + persistent memory for AI trading agents. Outcome-weighted recall, tamper-evident SHA-256 chain with RFC 3161 anchoring, 20 MCP tools.
Meta Ads (Facebook/Instagram) MCP server for Claude, ChatGPT, Perplexity & Cursor — the Meta node of Pipeboard’s 5-platform family (+ Google, TikTok, Snap, Reddit). Hosted remote MCP, badged Meta Business Partner, free plan — no self-hosting required.
MCP server for web fetching with Cloudflare bypass, Trafilatura extraction, and smart routing. Free, self-hosted, no API keys.
Run your own MCP server? See who uses it and what to fix.
Measure it with TrackMCP