Comprehensive Wireshark + Nmap MCP server for network analysis with threat intelligence
Wellknown found it in public sources; nobody has proven control of it yet. Claiming takes one click if the repository is under your GitHub account, or a small file on your domain otherwise. Verified owners get the badge, 15-minute checks, status alerts, edits that outrank crawled data, and a ranking boost.
Agents can do it too: POST https://wellknown.network/api/v1/claims with {"agent":"iflow-mcp-mixelpixx-wireshark-mcp-server","method":"well_known_file"} — machine-readable steps at claim.json, guide at /docs/claim.
Everything here was measured by our prober or read from a registry. Nothing is self-reported.
Attributed to the source that supplied each field. Treated as claims, not facts.
# Wireshark MCP Server A comprehensive Model Context Protocol (MCP) server that provides AI assistants with professional-grade network analysis capabilities. Combines Wireshark packet analysis with nmap scanning, threat intelligence, and modern MCP features for enhanced network troubleshooting and security analysis. ## Features ### Core Wireshark Capabilities - **Live Packet Capture**: Real-time network traffic capture from any interface - **PCAP File Analysis**: Advanced analysis of capture files with filtering - **Protocol Statistics**: Comprehensive protocol hierarchy and conversation stats - **Stream Following**: Reconstruct TCP/UDP conversations from captures - **Data Export**: Export packets to JSON, CSV formats ### Network Scanning (Nmap Integration) - **Port Scanning**: Multiple scan types (SYN, connect, UDP) - **Service Detection**: Identify services and versions - **OS Fingerprinting**: Operating system detection - **Vulnerability Scanning**: NSE vulnerability detection scripts - **Quick & Comprehensive Scans**: Flexible scan options ### Security Features - **Threat Intelligence**: URLhaus and AbuseIPDB integration - **Malicious IP Detection**: Automatic threat checking - **Security Audit Workflows**: Guided security analysis prompts - **Credential Scanning**: Detect cleartext credentials - **Defense in Depth**: Multiple layers of input validation ### Modern MCP Features - **MCP Resources**: Dynamic access to interfaces and captures - **MCP Prompts**: Guided workflows for security audits and troubleshooting - **Structured JSON Output**: LLM-optimized response formats - **Rate Limiting**: Prevent abuse of scanning operations - **Async Operations**: Non-blocking high-performance analysis ## Installation ### Quick Install (PyPI) ```bash pip install wireshark-mcp-server ``` ### Development Install ```bash # Clone repository git clone https://github.com/yourusername/wireshark-mcp.git cd wireshark-mcp # Install in development mode pip install -e . …
Mapped onto the structured taxonomy from declared text and observed tool names. Confidence shown for derived entries.
Every source is kept verbatim. Field changes are logged as events.