{"repo":"0xKoda/WireMCP","free":true,"listed":false,"github":"https://github.com/0xKoda/WireMCP","clone":"git clone https://github.com/0xKoda/WireMCP.git","description":"An MCP for WireShark (tshark). Empower LLM's with realtime network traffic analysis capability","language":"JavaScript","stars":570,"topics":["llm","mcp","network-analysis","wireshark"],"license":"MIT","category":"ai-agents","readme_excerpt":"WireMCP WireMCP is a Model Context Protocol (MCP) server designed to empower Large Language Models (LLMs) with real-time network traffic analysis capabilities. By leveraging tools built on top of Wireshark's tshark , WireMCP captures and processes live network data, providing LLMs with structured context to assist in tasks like threat hunting, network diagnostics, and anomaly detection. Features WireMCP exposes the following tools to MCP clients, enhancing LLM understanding of network activity: - capture packets : Captures live traffic and returns raw packet data as JSON, enabling LLMs to analyze packet-level details (e.g., IP addresses, ports, HTTP methods). - get summary stats : Provides protocol hierarchy statistics, giving LLMs an overview of traffic composition (e.g., TCP vs. UDP usage). - get conversations : Delivers TCP/UDP conversation statistics, allowing LLMs to track communication flows between endpoints. - check threats : Captures IPs and checks them against the URLhaus blacklist, equipping LLMs with threat intelligence context for identifying malicious activity. - check ip threats : Performs targeted threat intelligence lookups for specific IP addresses against multiple threat feeds, providing detailed reputation and threat data. - analyze pcap : Analyzes PCAP files to provide comprehensive packet data in JSON format, enabling detailed post-capture analysis of network traffic. - extract credentials : Scans PCAP files for potential credentials from various protoco","default_branch":null,"files":null,"tree":[],"storefront":"/r/0xKoda","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/0xKoda/WireMCP/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}