WireMCP

0xKoda/WireMCP

3.9

WireMCP is hosted online, so all tools can be tested directly either in theInspector tabor in theOnline Client.

If you are the rightful owner of WireMCP and would like to certify it and/or have it hosted online, please leave a comment on the right or send an email to henry@mcphub.com.

WireMCP is a Model Context Protocol server that enhances Large Language Models with real-time network traffic analysis capabilities using tools built on Wireshark's `tshark`.

Try WireMCP with chat:

Tools

Functions exposed to the LLM to take actions

capture_packets

Capture live traffic and provide raw packet data as JSON for LLM analysis

get_summary_stats

Capture live traffic and provide protocol hierarchy statistics for LLM analysis

get_conversations

Capture live traffic and provide TCP/UDP conversation statistics for LLM analysis

check_threats

Capture live traffic and check IPs against URLhaus blacklist

check_ip_threats

Check a given IP address against URLhaus blacklist for IOCs

analyze_pcap

Analyze a PCAP file and provide general packet data as JSON for LLM analysis

extract_credentials

Extract potential credentials (HTTP Basic Auth, FTP, Telnet) from a PCAP file for LLM analysis

Prompts

Interactive templates invoked by user choice

capture_packets_prompt

summary_stats_prompt

conversations_prompt

check_threats_prompt

check_ip_threats_prompt

analyze_pcap_prompt

extract_credentials_prompt

Resources

Contextual data attached and managed by the client

No resources