{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_y8dmtz97cbwp","handle":"awslabs-pcap-analyzer-mcp-server","url":"https://wellknown.network/agents/awslabs-pcap-analyzer-mcp-server","links":{"self":"https://wellknown.network/agents/awslabs-pcap-analyzer-mcp-server/record.json","html":"https://wellknown.network/agents/awslabs-pcap-analyzer-mcp-server","markdown":"https://wellknown.network/agents/awslabs-pcap-analyzer-mcp-server/record.md","api":"https://wellknown.network/api/v1/agents/awslabs-pcap-analyzer-mcp-server","status":"https://wellknown.network/api/v1/agents/awslabs-pcap-analyzer-mcp-server/status","claim":"https://wellknown.network/agents/awslabs-pcap-analyzer-mcp-server/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/awslabs-pcap-analyzer-mcp-server/claim.json","badge":"https://wellknown.network/agents/awslabs-pcap-analyzer-mcp-server/badge.svg","openapi":"https://wellknown.network/openapi.json"},"ard":{"identifier":"urn:air::server:awslabs-pcap-analyzer-mcp-server","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"awslabs.pcap-analyzer-mcp-server","summary":"A Model Context Protocol server for comprehensive network packet capture and analysis using Wireshark/tshark","description":"# PCAP Analyzer MCP Server\n\n[![PyPI](https://img.shields.io/pypi/v/awslabs.pcap-analyzer-mcp-server.svg)](https://pypi.org/project/awslabs.pcap-analyzer-mcp-server/)\n[![License](https://img.shields.io/badge/License-MIT--0-blue.svg)](https://github.com/aws-samples/sample-pcap-analyzer-mcp/blob/main/LICENSE)\n\nA Model Context Protocol (MCP) server for comprehensive network packet capture and analysis using Wireshark/tshark.\n\n[GitHub Repository](https://github.com/aws-samples/sample-pcap-analyzer-mcp) •\n[Full Documentation](https://github.com/aws-samples/sample-pcap-analyzer-mcp#readme)\n\n## Overview\n\nThis MCP server enables AI models to perform sophisticated network packet capture and analysis. It provides **46 specialized tools** across 11 categories for deep network analysis, troubleshooting, and security assessment.\n\n### Architecture\n\nTwo deployment patterns are supported:\n\n1. **Local (IDE)** — Run alongside your IDE (Claude Desktop, VS Code, Cursor, Kiro, Amazon Q Developer). The MCP client communicates with the server via stdio, which invokes tshark for packet analysis.\n\n2. **Cloud (AgentCore Gateway + Lambda)** — Deploy as a Lambda function behind AgentCore Gateway with OAuth2/Cognito inbound auth and IAM outbound auth. PCAPs are read from S3.\n\nSee the [full architecture diagrams on GitHub](https://github.com/aws-samples/sample-pcap-analyzer-mcp#architecture).\n\n### Key Capabilities\n\n- 🔧 Network interface discovery and live packet capture\n- 📊 Comprehensive protocol analysis (TCP, TLS, QUIC/HTTP3, BGP, DNS, HTTP)\n- 🔒 Security analysis (TLS handshakes, PQC detection, ARP spoofing, DNS tunneling, credential exposure)\n- ⚡ Performance metrics (latency, throughput, bandwidth, connection reuse, quality)\n- 🔍 Advanced diagnostics (MTU/fragmentation, connection timeouts, out-of-order packets)\n- 🌐 Network intelligence (Geo/ASN mapping, ICMP error classification, TCP reset analysis)\n\n## Prerequisites\n\n- **Python 3.10+**\n- **uv** — [Install uv](https://docs.astral.sh/uv/g…","publisher":{"name":"Amazon Web Services","url":null},"homepage":"https://github.com/aws-samples/sample-pcap-analyzer-mcp#readme","repository":"https://github.com/aws-samples/sample-pcap-analyzer-mcp/issues","version":"1.0.2","license":"Apache-2.0","protocols":["mcp"],"tags":["mcp"],"pricing":null,"endpoints":[{"url":"pypi:awslabs.pcap-analyzer-mcp-server","type":"package_pypi","auth":null,"probeable":false}],"skills":null,"tools":null,"extra":null,"attribution":{"kind":"pypi","name":"pypi","license":"pypi","repoUrl":"pypi","summary":"pypi","version":"pypi","description":"pypi","homepageUrl":"pypi","publisherName":"pypi"}},"derived":{"capabilities":[{"slug":"infra.cloud","name":"Cloud Platforms","confidence":1,"provenance":"derived"},{"slug":"code.documentation","name":"Code Documentation","confidence":0.848,"provenance":"derived"},{"slug":"dev.version-control","name":"Version Control","confidence":0.825,"provenance":"derived"},{"slug":"dev.ci-cd","name":"CI/CD & Deploy","confidence":0.825,"provenance":"derived"},{"slug":"security.identity","name":"Identity & Access","confidence":0.722,"provenance":"derived"}],"categories":["code","dev","infra","security"],"language":"en"},"observed":{"status":"unknown","statusReason":"Distributed as a package to run locally; no network endpoint to check.","lastOkAt":null,"lastProbedAt":null,"statusComputedAt":null,"reliability30d":null,"latestObservations":[],"tools":null,"package":{"name":"awslabs.pcap-analyzer-mcp-server","registry":"pypi","observedAt":"2026-09-09T10:28:39.031Z","publishedAt":"2026-08-12T17:46:10.779686Z","latestVersion":"1.0.2"}},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"pypi","key":"awslabs.pcap-analyzer-mcp-server","url":"https://pypi.org/project/awslabs.pcap-analyzer-mcp-server/","firstSeenAt":"2026-09-09T10:26:09.295Z","fetchedAt":"2026-09-09T10:26:09.295Z","normalizedAt":"2026-09-09T10:26:09.295Z"}]},"firstSeenAt":"2026-09-09T10:26:09.295Z","updatedAt":"2026-09-09T10:28:39.031Z"}