Overview
Features
Stateless MCP Tools
Each analysis accepts PCAP file paths or URLs as parameters (no file uploads).
Modular Architecture
DNS, DHCP, ICMP, and CapInfos modules with easy extensibility for new protocols.
Local & Remote PCAP Support
Analyze files from local storage or HTTP URLs.
Scapy Integration
Leverages Scapy's comprehensive packet parsing capabilities.
Specialized Analysis Prompts
Security, networking, and forensic analysis guidance.
JSON Responses
Structured data format optimized for LLM consumption.
Client Integration Friendly
Designed for seamless integration with Claude Desktop and other MCP clients.
Remote File Handling
Automatic temporary download and cleanup; supports .pcap, .pcapng, and .cap; HTTP/HTTPS supported.
Who Is This For?
- LLM developers:Integrate mcpcap into MCP clients to enable protocol-specific PCAP analysis via prompts.
- Network security analysts:Utilize mcpcap to analyze DNS, DHCP, ICMP, and CapInfos data for security insights.
- Forensic investigators:Perform protocol-specific PCAP analyses to aid timeline reconstruction and evidence gathering.




