A Model Context Protocol server for comprehensive network packet capture and analysis using Wireshark/tshark
Wellknown found it in public sources; nobody has proven control of it yet. Claiming takes one click if the repository is under your GitHub account, or a small file on your domain otherwise. Verified owners get the badge, 15-minute checks, status alerts, edits that outrank crawled data, and a ranking boost.
Agents can do it too: POST https://wellknown.network/api/v1/claims with {"agent":"awslabs-pcap-analyzer-mcp-server","method":"well_known_file"} — machine-readable steps at claim.json, guide at /docs/claim.
Everything here was measured by our prober or read from a registry. Nothing is self-reported.
Attributed to the source that supplied each field. Treated as claims, not facts.
# PCAP Analyzer MCP Server [](https://pypi.org/project/awslabs.pcap-analyzer-mcp-server/) [](https://github.com/aws-samples/sample-pcap-analyzer-mcp/blob/main/LICENSE) A Model Context Protocol (MCP) server for comprehensive network packet capture and analysis using Wireshark/tshark. [GitHub Repository](https://github.com/aws-samples/sample-pcap-analyzer-mcp) • [Full Documentation](https://github.com/aws-samples/sample-pcap-analyzer-mcp#readme) ## Overview This MCP server enables AI models to perform sophisticated network packet capture and analysis. It provides **46 specialized tools** across 11 categories for deep network analysis, troubleshooting, and security assessment. ### Architecture Two deployment patterns are supported: 1. **Local (IDE)** — Run alongside your IDE (Claude Desktop, VS Code, Cursor, Kiro, Amazon Q Developer). The MCP client communicates with the server via stdio, which invokes tshark for packet analysis. 2. **Cloud (AgentCore Gateway + Lambda)** — Deploy as a Lambda function behind AgentCore Gateway with OAuth2/Cognito inbound auth and IAM outbound auth. PCAPs are read from S3. See the [full architecture diagrams on GitHub](https://github.com/aws-samples/sample-pcap-analyzer-mcp#architecture). ### Key Capabilities - 🔧 Network interface discovery and live packet capture - 📊 Comprehensive protocol analysis (TCP, TLS, QUIC/HTTP3, BGP, DNS, HTTP) - 🔒 Security analysis (TLS handshakes, PQC detection, ARP spoofing, DNS tunneling, credential exposure) - ⚡ Performance metrics (latency, throughput, bandwidth, connection reuse, quality) - 🔍 Advanced diagnostics (MTU/fragmentation, connection timeouts, out-of-order packets) - 🌐 Network intelligence (Geo/ASN mapping, ICMP error classification, TCP reset analysis) ## Prerequisites - **Python 3.10+** - **uv** — [Install uv](https://docs.astral.sh/uv/g…
Mapped onto the structured taxonomy from declared text and observed tool names. Confidence shown for derived entries.
Every source is kept verbatim. Field changes are logged as events.