0xKoda/WireMCP

An MCP for WireShark (tshark). Empower LLM's with realtime network traffic analysis capability

39
/ 100
Emerging

Exposes six specialized tools including packet capture, protocol statistics, conversation tracking, and credential extraction from PCAP files—all structured as JSON for LLM consumption. Built as an MCP server that wraps `tshark` binaries and integrates threat intelligence feeds (URLhaus, with roadmap support for IPsum and Emerging Threats) to contextualize network data for security analysis tasks. Integrates with MCP-compliant clients like Cursor and Claude Desktop via stdio transport, auto-detecting or locating `tshark` across macOS, Windows, and Linux environments.

383 stars. No commits in the last 6 months.

Stale 6m No Package No Dependents
Maintenance 2 / 25
Adoption 10 / 25
Maturity 9 / 25
Community 18 / 25

How are scores calculated?

Stars

383

Forks

47

Language

JavaScript

License

MIT

Last pushed

Jul 09, 2025

Commits (30d)

0

Get this data via API

curl "https://pt-edge.onrender.com/api/v1/quality/mcp/0xKoda/WireMCP"

Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.