An MCP server for offline network forensic analysis and threat intelligence, enabling LLMs to analyze PCAP files, extract streams, detect threats, and identify credentials using tshark.
| Tool name | Description | Destructive? |
|---|---|---|
| capture_packets | ✓ no | |
| get_summary_stats | ✓ no | |
| get_conversations | ✓ no | |
| extract_stream_content | ✓ no | |
| get_stream_info | ✓ no |
| get_top_ips | ✓ no | |
| extract_stream_chunks | ✓ no | |
| check_threats | ✓ no | |
| analyze_pcap | ✓ no | |
| extract_credentials | ✓ no |