This Python toolkit enables seamless integration between Wireshark and MCP (Machine Control Protocol), allowing you to interact with Wireshark using natural language through Claude Desktop for advanced network analysis.
Clone the repository:
git clone https://github.com/shubham-s-pandey/WiresharkMCP.git
cd WiresharkMCP
Install required Python dependencies:
pip install -r requirements.txt
Configure the Lua extension for Wireshark:
cp wireshark_extension.lua ~/.wireshark/plugins/
For Windows users:
copy wireshark_extension.lua %APPDATA%\Wireshark\plugins\
Launch the Python MCP server to establish the communication bridge:
python mcp_server.py
The server will initialize and display available network interfaces.
Use the following commands in the CLI interface:
# View all available interfaces
show interfaces
# Analyze specific protocols
analyze http
# Filter packets by IP address
filter ip 192.168.1.100
# Export capture to file
export capture.pcap
With Claude Desktop running, you can use natural language to analyze packets:
The MCP server implements smart buffering to optimize performance:
# Adjust buffer size (in packets)
set buffer 1000
# Clear current buffer
clear buffer
Export your analysis results for later review:
# Save current analysis to file
save analysis report.txt
# Export filtered packets
export filtered capture.pcap
show interfaces
to verify available network interfacesset buffer
commandCheck the log files for detailed error information:
cat ~/.wireshark-mcp/logs/server.log
There are two ways to add an MCP server to Cursor. The most common way is to add the server globally in the ~/.cursor/mcp.json
file so that it is available in all of your projects.
If you only need the server in a single project, you can add it to the project instead by creating or adding it to the .cursor/mcp.json
file.
To add a global MCP server go to Cursor Settings > MCP and click "Add new global MCP server".
When you click that button the ~/.cursor/mcp.json
file will be opened and you can add your server like this:
{
"mcpServers": {
"cursor-rules-mcp": {
"command": "npx",
"args": [
"-y",
"cursor-rules-mcp"
]
}
}
}
To add an MCP server to a project you can create a new .cursor/mcp.json
file or add it to the existing one. This will look exactly the same as the global MCP server example above.
Once the server is installed, you might need to head back to Settings > MCP and click the refresh button.
The Cursor agent will then be able to see the available tools the added MCP server has available and will call them when it needs to.
You can also explictly ask the agent to use the tool by mentioning the tool name and describing what the function does.