Use when analyzing packet captures or live network traffic with Wireshark MCP; choose the right workflow for triage, security hunting, incident response, or troubleshooting, then produce evidence-backed findings with exact filters, streams, frames, and next steps.
Use the wireshark MCP server for authorized packet capture and analysis with TShark. Apply when investigating live traffic, reading pcap/pcapng files, debugging DNS/HTTP/TLS, or working on the wireshark-mcp codebase itself.