WireMCP

0xKoda/WireMCP

4.0

If you are the rightful owner of WireMCP and would like to certify it and/or have it hosted online, please leave a comment on the right or send an email to dayong@mcphub.com.

WireMCP is a Model Context Protocol server that enhances Large Language Models with real-time network traffic analysis capabilities using tools built on Wireshark's `tshark`.

Tools

Functions exposed to the LLM to take actions

capture_packets

Capture live traffic and provide raw packet data as JSON for LLM analysis

get_summary_stats

Capture live traffic and provide protocol hierarchy statistics for LLM analysis

get_conversations

Capture live traffic and provide TCP/UDP conversation statistics for LLM analysis

check_threats

Capture live traffic and check IPs against URLhaus blacklist

check_ip_threats

Check a given IP address against URLhaus blacklist for IOCs

analyze_pcap

Analyze a PCAP file and provide general packet data as JSON for LLM analysis

extract_credentials

Extract potential credentials (HTTP Basic Auth, FTP, Telnet) from a PCAP file for LLM analysis

Prompts

Interactive templates invoked by user choice

capture_packets_prompt

summary_stats_prompt

conversations_prompt

check_threats_prompt

check_ip_threats_prompt

analyze_pcap_prompt

extract_credentials_prompt

Resources

Contextual data attached and managed by the client

No resources