{"topic_id":1783005,"version_number":1,"captured_at":"2026-03-19T08:08:18.036Z","is_encrypted":false,"main_post":{"post_number":1,"reply_to_post_number":null,"author_username":"bx33661","created_at":"2026-03-19T07:58:58.966Z","content_html":"<h1><a name=\"p-15321855-wireshark-mcp-llm-1\" class=\"anchor\" href=\"#p-15321855-wireshark-mcp-llm-1\" aria-label=\"标题链接\"></a>Wireshark-MCP：为 LLM 提供原生的抓包分析能力</h1>\n<p>项目地址：<a href=\"https://github.com/bx33661/Wireshark-MCP\" rel=\"noopener nofollow ugc\">https://github.com/bx33661/Wireshark-MCP</a></p>\n<p><span alt=\"PixPin2026-03-1915-45-04.png\" class=\"broken-image\" title=\"此图片已损坏\"><svg class=\"fa d-icon d-icon-link-slash svg-icon\" aria-hidden=\"true\"><use href=\"#link-slash\"></use></svg></span></p>\n<p>Wireshark MCP，主要想解决在让大模型辅助做网络排障、安全分析或 CTF 时，缺乏直接操作底层网络数据包手段的痛点。</p>\n<p>通过把 Wireshark 套件封装为标准的 MCP（Model Context Protocol）接口，现在你可以直接在 Cursor、Claude 等客户端里把 <code>.pcap</code> 文件丢给 AI，它会调用底层的原生工具做可靠的分析。</p>\n<h3><a name=\"p-15321855-h-2\" class=\"anchor\" href=\"#p-15321855-h-2\" aria-label=\"标题链接\"></a>核心特性</h3>\n<ul>\n<li><strong>基于原生工具</strong>：核心逻辑直接基于本地的 <code>tshark</code>。如果系统内检测到 <code>capinfos</code>、<code>editcap</code>、<code>dumpcap</code> 等工具，它会自动扩展出包裁剪、合并甚至实施抓包的能力。AI 得出的结论都有确凿的帧编号和流索引作为证据，不再靠猜。</li>\n<li><strong>Agentic Workflows</strong>：除了基础的查询和提取，也封装了高级的一键分析流（例如 <code>wireshark_quick_analysis</code> 和 <code>wireshark_security_audit</code>），直接覆盖威胁情报查杀（联动 URLhaus）、明文扫描、异常端口探测等常见场景。</li>\n<li><strong>开箱即用的配置</strong>：很多人配 MCP 会因为环境路径卡住。我们做了自动化检测，提供 <code>wireshark-mcp install</code> 命令，一行代码即可自动寻找并注入 Cursor、Claude Desktop、VS Code、Cline 等近 20 种 AI 客户端的配置中，并解决路径透传问题。</li>\n</ul>\n<h3><a name=\"p-15321855-h-3\" class=\"anchor\" href=\"#p-15321855-h-3\" aria-label=\"标题链接\"></a>安装步骤</h3>\n<p>前置条件：系统已安装 Python 3.10+，以及至少包含 <code>tshark</code> 的 Wireshark。</p>\n<pre><code>bash\n# 1. 安装核心包\npip install wireshark-mcp\n# 2. 自动检测并写入你的 AI 客户端配置\nwireshark-mcp install\n</code></pre>\n<p>完成后重启 AI 客户端即可。如果不放心，可以运行 <code>wireshark-mcp doctor</code> 检查环境是否全部就绪。</p>\n<h3><a name=\"p-15321855-h-4\" class=\"anchor\" href=\"#p-15321855-h-4\" aria-label=\"标题链接\"></a>如何使用</h3>\n<p>在客户端中直接发一段 prompt 测试即可：</p>\n<blockquote>\n<p>使用 Wireshark MCP 工具来分析 <code>&lt;path/to/file.pcap&gt;</code>。请先运行 <code>wireshark_open_file</code> 建立全局画像，然后做一次深度安全审计，并将结果整理成报告。</p>\n</blockquote>\n<h3><a name=\"p-15321855-h-5\" class=\"anchor\" href=\"#p-15321855-h-5\" aria-label=\"标题链接\"></a>相关链接</h3>\n<p>项目地址：<a href=\"https://github.com/bx33661/Wireshark-MCP\" rel=\"noopener nofollow ugc\">https://github.com/bx33661/Wireshark-MCP</a></p>","normalized_text":"Wireshark-MCP：为 LLM 提供原生的抓包分析能力 项目地址： https://github.com/bx33661/Wireshark-MCP Wireshark MCP，主要想解决在让大模型辅助做网络排障、安全分析或 CTF 时，缺乏直接操作底层网络数据包手段的痛点。 通过把 Wireshark 套件封装为标准的 MCP（Model Context Protocol）接口，现在你可以直接在 Cursor、Claude 等客户端里把 .pcap 文件丢给 AI，它会调用底层的原生工具做可靠的分析。 核心特性 基于原生工具 ：核心逻辑直接基于本地的 tshark 。如果系统内检测到 capinfos 、 editcap 、 dumpcap 等工具，它会自动扩展出包裁剪、合并甚至实施抓包的能力。AI 得出的结论都有确凿的帧编号和流索引作为证据，不再靠猜。 Agentic Workflows ：除了基础的查询和提取，也封装了高级的一键分析流（例如 wireshark_quick_analysis 和 wireshark_security_audit ），直接覆盖威胁情报查杀（联动 URLhaus）、明文扫描、异常端口探测等常见场景。 开箱即用的配置 ：很多人配 MCP 会因为环境路径卡住。我们做了自动化检测，提供 wireshark-mcp install 命令，一行代码即可自动寻找并注入 Cursor、Claude Desktop、VS Code、Cline 等近 20 种 AI 客户端的配置中，并解决路径透传问题。 安装步骤 前置条件：系统已安装 Python 3.10+，以及至少包含 tshark 的 Wireshark。 bash # 1. 安装核心包 pip install wireshark-mcp # 2. 自动检测并写入你的 AI 客户端配置 wireshark-mcp install 完成后重启 AI 客户端即可。如果不放心，可以运行 wireshark-mcp doctor 检查环境是否全部就绪。 如何使用 在客户端中直接发一段 prompt 测试即可： 使用 Wireshark MCP 工具来分析 <path/to/file.pcap> 。请先运行 wireshark_open_file 建立全局画像，然后做一次深度安全审计，并将结果整理成报告。 相关链接 项目地址： https://github.com/bx33661/Wireshark-MCP"},"replies":[{"post_number":2,"reply_to_post_number":null,"author_username":"apocalypse","created_at":"2026-03-19T08:03:09.400Z","content_html":"<p>牛逼，小鲨鱼的界面确实不太友好。</p>","normalized_text":"牛逼，小鲨鱼的界面确实不太友好。"},{"post_number":3,"reply_to_post_number":null,"author_username":"bing_666","created_at":"2026-03-19T08:05:05.707Z","content_html":"<p>感谢分享</p>","normalized_text":"感谢分享"},{"post_number":4,"reply_to_post_number":null,"author_username":"suncodes","created_at":"2026-03-19T08:06:48.259Z","content_html":"<p>6666~</p>","normalized_text":"6666~"}]}