Monitoring · Security

WireMCP (Wireshark) logo

WireMCP (Wireshark)

0xkoda/wiremcp

WireMCP is a Model Context Protocol (MCP) server designed to empower Large Language Models (LLMs) with real-time network traffic analysis capabilities.

Install

Client configuration

{
  "mcpServers": {
    "wiremcp": {
      "command": "node",
      "args": [
        "/ABSOLUTE_PATH_TO/WireMCP/index.js"
      ]
    }
  }
}
GitHub stars
98
Author
@0xkoda
Category
Monitoring, Security
License
MIT
Updated
Oct 6, 2026

About WireMCP (Wireshark)

By leveraging tools built on top of Wireshark's tshark, WireMCP captures and processes live network data, providing LLMs with structured context to assist in tasks like threat hunting, network diagnostics, and anomaly detection.

Features

  • capture_packets: Captures live traffic and returns raw packet data as JSON, enabling LLMs to analyze packet-level details (e.g., IP addresses, ports, HTTP methods).

  • get_summary_stats: Provides protocol hierarchy statistics, giving LLMs an overview of traffic composition (e.g., TCP vs. UDP usage).

  • get_conversations: Delivers TCP/UDP conversation statistics, allowing LLMs to track communication flows between endpoints.

  • check_threats: Captures IPs and checks them against the URLhaus blacklist, equipping LLMs with threat intelligence context for identifying malicious activity.

  • check_ip_threats: Performs targeted threat intelligence lookups for specific IP addresses against multiple threat feeds, providing detailed reputation and threat data.

  • analyze_pcap: Analyzes PCAP files to provide comprehensive packet data in JSON format, enabling detailed post-capture analysis of network traffic.

  • extract_credentials: Scans PCAP files for potential credentials from various protocols (HTTP Basic Auth, FTP, Telnet), aiding in security audits and forensic analysis.

  • Contextualizing Traffic: Converts live packet captures into structured outputs (JSON, stats) that LLMs can parse and reason about.

  • Threat Detection: Integrates IOCs (currently URLhaus) to flag suspicious IPs, enhancing LLM-driven security analysis.

  • Diagnostics: Offers detailed traffic insights, enabling LLMs to assist with troubleshooting or identifying anomalies.

Details on this page are taken from the project's README. Open README

Supported clients

Clients mentioned in this server's README:

View all
Claude Desktop logo

Claude Desktop

Desktop · Freemium · Proprietary

Anthropic's official Claude AI desktop application. Supports MCP servers to extend functionality.

WindowsMacOS
Cursor logo

Cursor

Desktop · Freemium · Proprietary

The first agentic IDE. The Cursor editor truly merges how developers and AI work together, delivering a magical coding experience.

WindowsMacOSLinux

Related MCP servers

More servers
2344 logo

2344

comet-ml/opik

7k

Opik is the open-source LLM observability and evaluation platform for AI agent tracing, LLM evaluation, prompt management, and production monitoring. Built by Comet. Apache-2.0 licensed, free to self-host the full platform, with 20,000+ GitHub stars.

Monitoring
MCP Grafana logo

MCP Grafana

grafana/mcp-grafana

612

A Model Context Protocol (MCP) server for Grafana.

Monitoring
Vite Plugin Vue MCP logo

Vite Plugin Vue MCP

webfansplz/vite-plugin-vue-mcp

407

Vite plugin that enables a MCP server for your Vue app to provide information about the component tree, state, routes, and pinia tree and state.

Monitoring
api200 logo

api200

API-200/api200

169

API 200 is all-in-one gateway for managing third-party APIs efficiently. Integrate third-party APIs or setup MCP server in minutes with auto-generated code, docs, auth, caching and error handling – so you can focus on what really matters.

Monitoring
gospy logo

gospy

monsterxx03/gospy

90

A tool for inspecting and analyzing running Go processes, including goroutine states, memory statistics, and binary information.

Monitoring
AWS Cost Explorer MCP Server logo

AWS Cost Explorer MCP Server

aarora79/aws-cost-explorer-mcp-server

86

This tool provides a convenient way to analyze and visualize AWS cloud spending data using Anthropic's Claude model as an interactive interface. It functions as an MCP server that exposes AWS Cost Explorer API functionality to Claude Desktop, allowing you to ask questions about your AWS spend in natural language.

Monitoring