Security

Wireshark MCP: packet analysis with tshark for agents

Wraps tshark as 52 tools: give an agent a pcap and it can tally traffic, follow streams and flag DNS tunnels or port scans, all backed by tshark output.

Project and installation docs

View project

https://github.com/bx33661/Wireshark-MCP

Given a capture of several hundred megabytes, finding which host is tunneling over DNS, whether credentials crossed in cleartext, or which connection beacons on a timer means writing filter after filter in Wireshark. Handing the pcap straight to a model doesn’t work: it can’t read the binary and tends to invent conclusions. Wireshark MCP wraps tshark in structured tools, so the model asks the questions and tshark does the counting and extraction, and every finding traces back to real output. It had about 290 stars as of 2026-10-06.

What it does

  • Getting started: wireshark_open_file loads a capture and wireshark_quick_analysis summarizes it; wireshark_aggregate handles capture-wide counts, grouping and top-k.
  • Security checks: eight detectors for credentials, port scans, DNS tunneling, DoS, beaconing, exfiltration, protocol anomalies and YARA matches.
  • Protocol analysis: one tool, wireshark_analyze_protocol, covers 20 protocols including TLS handshakes, MQTT, Modbus, S7comm and Kerberos, applying the right field names and filters.
  • Decryption and forensics: TLS and WPA decryption, TLS fingerprints, file signature scans and GeoIP lookups.
  • Context control: --profile core exposes 32 tools, and results over 8,000 characters are truncated, with offset, limit and display filters for paging.

Who it’s for

  • Incident responders who need to spot anomalous connections in traffic fast.
  • Network engineers who want help reading TCP retransmissions and service response times.

Setup

Needs Python 3.10+ and Wireshark with tshark on your PATH. The installer detects your MCP clients and writes their config:

pip install wireshark-mcp
wireshark-mcp install

If something looks off, run wireshark-mcp doctor.

Our take

A carefully made small project. The author anticipated real pitfalls: protocol field names are filled in by the tool, so a wrong guess doesn’t return an empty result that reads like a clean capture, and the tool list stays byte-identical across restarts so clients can cache it. The 41 read-only analysis tools are annotated separately from the 11 that write files, so clients can prompt only for the latter. Since 3.0, file-writing tools refuse to run until WIRESHARK_MCP_ALLOWED_DIRS is set, and HTTP mode binds to loopback by default. Live capture needs the corresponding system privileges; use it only on networks you’re authorized to monitor. One person maintains it, and it’s actively updated. Licensed MIT.