0xKoda/WireMCP
A Model Context Protocol server that gives LLMs real-time network traffic analysis capabilities via Wireshark/tshark integration.

WireMCP is a Model Context Protocol server that bridges network traffic data with LLM comprehension. It exposes tools for capturing live packets, generating protocol statistics, performing threat lookups against threat feeds like URLhaus, analyzing PCAP files, and extracting credentials. The server converts raw network data into structured JSON outputs that LLMs can parse, enabling AI-driven threat hunting, network diagnostics, and anomaly detection.