Wireshark MCP Server
This project exposes PyShark functionality through the Model Context Protocol (MCP), allowing AI assistants like Claude to interact with network packet capture and analysis capabilities.
Installation
- Install the required dependencies:
# Install with uv (recommended)
uv add mcp[cli] pyshark
# Or with pip
pip install mcp[cli] pyshark
- Clone this repository:
git clone https://github.com/A-G-U-P-T-A/wireshark-mcp
cd wireshark-mcp
Requirements
- Python 3.8+
- TShark (Wireshark's command-line component) must be installed
- Administrative/root privileges for live packet capture
Usage
Running the server
You can run the server in development mode with the MCP Inspector:
mcp dev pyshark_mcp.py
Or install it directly in Claude Desktop:
mcp install pyshark_mcp.py
Available functionality
This MCP server exposes the following:
Resources
pyshark://version- Gets the PyShark version informationpyshark://config- Gets the PyShark configurationpyshark://capture-history- Gets history of previous packet captures
Tools
list_interfaces- Lists all available network interfacescapture_live_packets- Captures live packets from a network interfaceread_pcap_file- Reads and analyzes a packet capture fileanalyze_traffic- Analyzes network traffic patterns from a capture
Advanced tools provided in advanced_captures.py:
capture_targeted_traffic- Captures traffic targeted to specific host, port, or protocolcapture_to_file- Captures network traffic and saves to a pcap fileanalyze_http_traffic- Analyzes HTTP traffic from a capture filedetect_network_protocols- Detects and reports network protocols in use
Prompts
packet_capture_help- Provides help information about packet capturing with PyShark
Example usage in Claude
Once the server is installed in Claude Desktop, you can interact with it like this:
You: What interfaces are available for network capture?
Claude: Let me check the available network interfaces on your system.
[Calls list_interfaces tool]
You: Can you capture HTTP traffic for 10 seconds?
Claude: I'll capture HTTP traffic for 10 seconds.
[Calls capture_live_packets with appropriate parameters]
You: Can you analyze the traffic I just captured?
Claude: Here's an analysis of the captured traffic:
[Calls analyze_traffic to provide insights]
Remember to always ensure you have permission to capture network traffic.
Security Considerations
Network packet capture is a sensitive operation. Please ensure:
- You have proper authorization to capture network traffic
- You comply with all applicable laws and regulations
- You don't capture sensitive or private data inadvertently
- You handle capture files securely to prevent unauthorized access
Requirements
- PyShark: Python wrapper for TShark
- TShark: Command-line version of Wireshark (must be installed separately)
- Administrative privileges: Often required for live packet capture
Customization
You can customize this MCP server by:
- Adding more advanced capture and analysis tools
- Implementing filters for specific traffic types
- Creating specialized analysis functions for protocols of interest
- Extending the capture history management capabilities
Metadata
Release files for iflow-mcp_a-g-u-p-t-a_pyshark-mcp 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| iflow_mcp_a_g_u_p_t_a_pyshark_mcp-0.1.0.tar.gz | 28.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| iflow_mcp_a_g_u_p_t_a_pyshark_mcp-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 57.8 kB
Release files / iflow_mcp_a_g_u_p_t_a_pyshark_mcp-0.1.0.tar.gz
| Download URL | iflow_mcp_a_g_u_p_t_a_pyshark_mcp-0.1.0.tar.gz |
|---|---|
| Size | 28.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
0909c6894a4c0ff26dc653f76cd219f3cb2b3c04ecd8ee0596779ffe4234d3e8
|
|
BLAKE2b-256 checksum How to use checksums |
ff7aea057003ef878a4d88f7f4d04b159640ab5b03e48cbee7fc22db286f78c0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.9.28 {"installer":{"name":"uv","version":"0.9.28","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Debian GNU/Linux","version":"13","id":"trixie","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|
Release files / iflow_mcp_a_g_u_p_t_a_pyshark_mcp-0.1.0-py3-none-any.whl
| Download URL | iflow_mcp_a_g_u_p_t_a_pyshark_mcp-0.1.0-py3-none-any.whl |
|---|---|
| Size | 29.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8d5ac3d54b8b634d76431971cd83e4ac6e1a164dcd3151ece0df47ca802f8176
|
|
BLAKE2b-256 checksum How to use checksums |
14d099256d6e50c60f21e5230c1f008ff38bde7a603004ed09b25de39b8b68d7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.9.28 {"installer":{"name":"uv","version":"0.9.28","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Debian GNU/Linux","version":"13","id":"trixie","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|