Wireshark MCP server
Professional network analysis with tshark. Security audits, deep-dives, and threat detection.
272 stars396 downloads/wk
Reviews
Write oneNobody has reviewed Wireshark yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Wireshark tools (32, 1 write)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
wireshark_captureCapture live network traffic.
wireshark_decode_payload[Utils] Decode common encodings (Base64, Hex, URL, Gzip, etc.).
wireshark_editcap_deduplicatewrite actionRemove duplicate packets using editcap's duplicate window matching.
wireshark_editcap_splitSplit a capture into multiple files using editcap.
wireshark_editcap_time_shiftShift packet timestamps by a relative number of seconds using editcap.
wireshark_editcap_trimTrim a capture file to a timestamp window using editcap.
wireshark_extract_fields[Tabular] Extract specific fields as comma/tab-separated data.
wireshark_filter_saveFilter packets from a pcap and save to a new file.
wireshark_follow_stream[Stream] Reassemble and view complete stream content. Supports pagination to avoid token limits.
wireshark_get_capabilitiesGet the current Wireshark suite capabilities for this MCP server instance.
wireshark_get_file_infoGet detailed metadata about a capture file. Uses capinfos to show: file type, packet count, duration, size, etc.
wireshark_get_packet_bytes[Bytes] Get raw Hex/ASCII dump (like Wireshark's 'Packet Bytes' pane).
wireshark_get_packet_context[Context] View packets surrounding a specific frame (before and after). Useful for understanding what led to an error or what happened immediately after.
wireshark_get_packet_details[Detail] Get full details for a SINGLE packet (like Wireshark's bottom pane).
wireshark_get_packet_list[Summary] Get a summary list of packets (like Wireshark's top pane). Use this first to scan traffic before drilling down.
wireshark_list_interfacesList available network interfaces for capture.
wireshark_list_ips[Convenience] List all unique IP addresses in capture.
wireshark_merge_pcapsMerge multiple capture files into one.
wireshark_open_file[Entry Point] Open a pcap file and activate relevant analysis tools.
wireshark_plot_protocols[Visualization] Generate an ASCII tree of protocol hierarchy. Shows the distribution of protocols (e.g., how much is HTTP vs DNS).
wireshark_plot_traffic[Visualization] Generate an ASCII bar chart of traffic volume (I/O Graph). Useful for identifying traffic spikes, DDoS start times, or silence patterns.
wireshark_quick_analysis[Agent] One-call traffic overview and analysis.
wireshark_read_packets[DEPRECATED] Read packet data in structured JSON format. WARNING: This tool can return very large, complex JSON. Prefer `wireshark_get_packet_list` and `wireshark_get_packet_details` for efficient analysis.
wireshark_search_packets[Search] Find packets containing specific data.
wireshark_security_audit[Agent] One-call comprehensive security audit.
wireshark_stats_conversations[Conversations] Show communication pairs and their stats.
wireshark_stats_endpoints[Endpoints] List all endpoints and their traffic stats.
wireshark_stats_expert_info[Expert Info] Automatic anomaly detection. Detects: retransmissions, errors, warnings, protocol issues.
wireshark_stats_io_graph[I/O Graph] Traffic volume over time.
wireshark_stats_protocol_hierarchy[PHS] Get Protocol Hierarchy Statistics. Shows distribution of protocols in the capture.
wireshark_stats_service_response_time[SRT] Service Response Time statistics.
wireshark_text2pcap_importConvert an ASCII or hex dump into a capture file using text2pcap.
Public scan report
scanner v0.1.10 · 2026-09-27 · same rubric, same numbers if you re-run it
- Code scan30 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 22 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Install Wireshark in Claude Code, Cursor or VS Code
claude mcp add wireshark-mcp -- uvx wireshark-mcp
What the publisher says
From the Wireshark repository's README, as published. We do not edit it. Read it on GitHub
<!-- mcp-name: io.github.bx33661/wireshark-mcp -->
Wireshark MCP
Give your AI assistant a packet analyzer.
Drop a .pcap file, ask questions in plain English — get answers backed by real tshark data.
English • 中文 • Docs • Changelog • Roadmap • Contributing
What is this?
An MCP server that wraps tshark (and optional Wireshark suite tools) into a structured analysis interface. Works with Claude Desktop, Claude Code, Cursor, VS Code, and 18+ other MCP clients.
You: "Find all DNS queries going to suspicious domains in this capture."
Claude: [calls wireshark_extract_dns_queries → wireshark_detect_dns_tunnel]
"Found repeated high-entropy DNS queries consistent with tunneling: ..."Install
Prerequisites: Python 3.10+ and Wireshark with tshark on PATH.
Wireshark MCP 3.0 uses the stable MCP Python SDK 2.x line (mcp>=2.1.1,<3).
pip install wireshark-mcp
wireshark-mcp install # choose from detected MCP clientsRestart your AI client — done.
Run wireshark-mcp doctor if anything looks off. See docs/manual-configuration.md for manual setup or platform-specific notes.
Quick Start
Point your AI client at a .pcap file and try:
Analyze capture.pcap using the Wireshark MCP tools.
Start with wireshark_open_file, then run wireshark_quick_analysis.
Use wireshark_aggregate for any capture-wide count or distribution.
Write findings to report.md.Tools
52 tools, each backed by real tshark output — organized into categories:
Shortened. The full README is on GitHub.
Nothing above is checked by us. What we check is on the safety report.
Wireshark: common questions
- Is Wireshark MCP server safe?
- Yes, by our scan: it is graded A (92/100). Read the Wireshark safety report
- How do I install Wireshark?
- It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
- Does Wireshark need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Wireshark maintained?
- The last commit was 23 days ago (2026-09-05). The latest release is v0.6.5.
- What can I use instead of Wireshark?
- Servers from other publishers that do the same job: Npm Sentinel MCP server, npm Registry MCP Server and CrowdStrike Falcon MCP Server. Compare all Wireshark alternatives.
Alternatives to Wireshark
Same job from other publishers: the closest match first, then the best rated.
- Npm SentinelAdvanced NPM analysis: Recursive security scanning, ecosystem awareness, and deep insights.not reviewedGrowingA
- npm Registry MCP Servernpm registry MCP server — package intelligence, security audits, dependency analysisnot reviewedGrowingB
- CrowdStrike Falcon MCP ServerConnects AI agents with CrowdStrike Falcon for security analysis and automation.not reviewedEstablishedA
- Reversecore MCPSecurity-first MCP server for reverse engineering, malware analysis, forensics, and SAST.not reviewedEstablishedB
- Mastyf AIRuntime proxy for MCP security, cost governance & auditnot reviewedGrowingB