Armory
Source
Browse
MCPs

netforensicmcp

An MCP server for offline network forensic analysis and threat intelligence, enabling LLMs to analyze PCAP files, extract streams, detect threats, and identify credentials using tshark.

Score
55.1682 signals
Evidence
6 stars · 1 fork
Last commit
as last read from GitHub; most reads are from 2 Sep 2026 or later
Listed

Install

No one-command install. Set it up from its source.

Alternatives · MCPs

  1. wiremcp-network-traffic-analysis577 stars · 62 forks96.760
  2. bx33661-wireshark272 stars · 28 forks94.764
  3. thomasxm-crowdsentinel206 stars · 32 forks94.345

What it is

An MCP server for offline network forensic analysis and threat intelligence, enabling LLMs to analyze PCAP files, extract streams, detect threats, and identify credentials using tshark.

When to use it

An MCP server for offline network forensic analysis and threat intelligence, enabling LLMs to analyze PCAP files, extract streams, detect threats, and identify credentials using tshark.

How to install / invoke

See Glama for the install config.

Notes

Listed from the Glama MCP registry.