mcpcap
About
A modular Python MCP (Model Context Protocol) Server for analyzing PCAP files. mcpcap enables LLMs to read and analyze network packet captures with protocol-specific analysis tools that accept local file paths or remote URLs as parameters (no file uploads - provide the path or UR
Explore
- Stateless MCP Tools: Each analysis accepts PCAP file paths or URLs as parameters (no file uploads)
- Modular Architecture: DNS, DHCP, ICMP, and CapInfos modules with easy extensibility for new protocols
- Local & Remote PCAP Support: Analyze files from local storage or HTTP URLs
- Scapy Integration: Leverages scapy's comprehensive packet parsing capabilities
- Specialized Analysis Prompts: Security, networking, and forensic analysis guidance
- JSON Responses: Structured data format optimized for LLM consumption
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
mcpcapCommand (node, npx, python, etc.)Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
mcpcap requires Python 3.10 or greater.
``bash``
uvx mcpcap
bash
mcpcap --modules dns,dhcp,icmp,capinfos --max-packets 500
analyze_dns_packets
Analyze DNS packets from a PCAP file and return comprehensive analysis results. ⚠️ FILE UPLOAD LIMITATION: This MCP tool cannot process files uploaded through Claude's web interface. Files must be accessible via URL or local file path. SUPPORTED INPUT FORMATS: - Remote files: "https://example.com/capture.pcap" - Local files: "/absolute/path/to/capture.pcap" UNSUPPORTED: - Files uploaded through Claude's file upload feature - Base64 file content - Relative file paths Args: pcap_file: HTTP URL or absolute local file path to PCAP file Returns: A structured dictionary containing DNS packet analysis results
analyze_dhcp_packets
Analyze DHCP packets from a PCAP file and return comprehensive analysis results. ⚠️ FILE UPLOAD LIMITATION: This MCP tool cannot process files uploaded through Claude's web interface. Files must be accessible via URL or local file path. SUPPORTED INPUT FORMATS: - Remote files: "https://example.com/capture.pcap" - Local files: "/absolute/path/to/capture.pcap" UNSUPPORTED: - Files uploaded through Claude's file upload feature - Base64 file content - Relative file paths Args: pcap_file: HTTP URL or absolute local file path to PCAP file Returns: A structured dictionary containing DHCP packet analysis results
analyze_icmp_packets
Analyze ICMP packets from a PCAP file and return comprehensive analysis results. ⚠️ FILE UPLOAD LIMITATION: This MCP tool cannot process files uploaded through Claude's web interface. Files must be accessible via URL or local file path. SUPPORTED INPUT FORMATS: - Remote files: "https://example.com/capture.pcap" - Local files: "/absolute/path/to/capture.pcap" UNSUPPORTED: - Files uploaded through Claude's file upload feature - Base64 file content - Relative file paths Args: pcap_file: HTTP URL or absolute local file path to PCAP file Returns: A structured dictionary containing ICMP packet analysis results
analyze_capinfos
Return metadata from a PCAP file, similar to Wireshark's capinfos utility. IMPORTANT: This tool expects a FILE PATH or URL, not file content. - For local files: "/path/to/capture.pcap" - For remote files: "https://example.com/capture.pcap" - File uploads are NOT supported - save the file locally first Args: pcap_file: Path to local PCAP file or HTTP URL to remote PCAP file (NOT file content - must be a path or URL) Returns: A structured dictionary containing PCAP metadata including: - File information (size, name, encapsulation type) - Packet statistics (count, data size, average sizes) - Temporal data (duration, timestamps, rates)
- analyze_dns_packets(pcap_file): Complete DNS traffic analysis
- Extract DNS queries and responses
- Identify queried domains and subdomains
- Analyze query types (A, AAAA, MX, CNAME, etc.)
- Track query frequency and patterns
- Detect potential security issues
- analyze_dhcp_packets(pcap_file): Complete DHCP traffic analysis
- Track DHCP transactions (DISCOVER, OFFER, REQUEST, ACK)
- Identify DHCP clients and servers
- Monitor IP address assignments and lease information
- Analyze DHCP options and configurations
- Detect DHCP anomalies and security issues
- analyze_icmp_packets(pcap_file): Complete ICMP traffic analysis
- Analyze ping requests and replies with response times
- Identify network connectivity and reachability issues
- Track TTL values and routing paths (traceroute data)
- Detect ICMP error messages (unreachable, time exceeded)
- Monitor for potential ICMP-based attacks or reconnaissance
- analyze_capinfos(pcap_file): PCAP file metadata and statistics
- File information (size, name, link layer encapsulation)
- Packet statistics (count, data size, average packet size)
- Temporal analysis (duration, timestamps, packet rates)
- Data throughput metrics (bytes/second, bits/second)
- Similar to Wireshark's capinfos(1) utility
````
MCP Client Request → analyze_*_packets(pcap_file)
→ BaseModule.analyze_packets()
→ Module._analyze_protocol_file()
→ Structured JSON Response
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"mcpcap": {
"mcpcap": {
"command": "uvx",
"args": [
"mcpcap"
]
}
}
}
}
McpServers
{
"mcpcap": {
"command": "uvx",
"args": [
"mcpcap"
]
}
}
A modular Python MCP (Model Context Protocol) Server for analyzing PCAP files. mcpcap enables LLMs to read and analyze network packet captures with protocol-specific analysis tools that accept local file paths or remote URLs as parameters (no file uploads - provide the path or URL to your PCAP file).
Overview
mcpcap uses a modular architecture to analyze different network protocols found in PCAP files. Each module provides specialized analysis tools that can be called independently with any PCAP file, making it perfect for integration with Claude Desktop and other MCP clients.Key Features
- Stateless MCP Tools: Each analysis accepts PCAP file paths or URLs as parameters (no file uploads) - Modular Architecture: DNS, DHCP, ICMP, and CapInfos modules with easy extensibility for new protocols - Local & Remote PCAP Support: Analyze files from local storage or HTTP URLs - Scapy Integration: Leverages scapy's comprehensive packet parsing capabilities - Specialized Analysis Prompts: Security, networking, and forensic analysis guidance - JSON Responses: Structured data format optimized for LLM consumptionInstallation
mcpcap requires Python 3.10 or greater.Using pip
``bash
pip install mcpcap
`
Using uv
`bash
uv add mcpcap
`
Using uvx (for one-time usage)
`bash
uvx mcpcap
`
Quick Start
1. Start the MCP Server
Start mcpcap as a stateless MCP server:
``bashSign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



