Developer tool
Wireshark agent skills for Claude Code, Codex and other agents.
- skills
- 28
- Type
- Developer tool
- Website
- wireshark.org
- Official GitHub
- wireshark
- Reviews
- See Wireshark on Enlisted
Wireshark skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | 1.Dfir Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation. | transilienceai/ | 559 | — | ~1.5k | Automated safety check: Pass | MIT | 2 mo ago |
| 2 | 2.Iotnet IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications. | BrownFineSecurity/ | 858 | 1 repo | ~1k | Automated safety check: Notes | MIT | 4 mo ago |
| 3 | This skill should be used when the user asks to "analyze network traffic with Wireshark", "capture packets for troubleshooting", "filter PCAP files", "follow TCP/UDP streams", "detect network… | zebbern/ | 4.6k | 7 repos | ~3k | Automated safety check: Pass | MIT | today |
| 4 | Guides authorized packet capture and analysis with TShark, Wireshark's command-line tool, for security investigations, malware detection and forensic examination of network traffic. | AgentSecOps/ | 219 | 1 repo | ~4.8k | Automated safety check: Notes | Unknown | 5 mo ago |
| 5 | Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic. | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 6 | A skill your agent uses for authorized reverse engineering of custom binary protocols, Protobuf/gRPC, WebSocket frames, and PCAP-driven protocol recovery. | zhaoxuya520/ | 40k | 2 repos | ~620 | Automated safety check: Warn | MIT | 15 days ago |
| 7 | Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation. | wshobson/ | 40k | 7 repos | ~3.2k | Automated safety check: Pass | MIT | 2 days ago |
| 8 | 8.Net 嵌入式网络调试工具,用于发现接口、抓包、分析 pcap/pcapng、做连通性测试、端口扫描和流量统计. An agent skill from zhinkgit/embeddedskills. | zhinkgit/ | 731 | — | ~1.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 9 | Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct network communications, extract transferred files, identify malicious traffic… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 10 | Detect Layer 2 ARP poisoning/spoofing by deploying ARPWatch, Dynamic ARP Inspection (DAI), Wireshark packet analysis, and custom Python monitoring scripts that flag gratuitous ARP floods, IP-to-MAC… | mukul975/ | 34k | — | ~3.8k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 11 | Capture and analyze network traffic using Wireshark and tshark to reconstruct network events from PCAP/PCAPNG files, extract transferred files and credentials, and identify command-and-control… | mukul975/ | 34k | — | ~3k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 12 | Deploy Zeek (formerly Bro) as a passive network security monitor to generate structured logs of protocol metadata (HTTP, DNS, TLS, SSH, SMTP, FTP, and more), write custom detection scripts, and… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 13 | Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and… | mukul975/ | 34k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 14 | Analyzes network traffic generated by malware during sandbox execution or live incident response to identify C2 protocols, data exfiltration channels, payload downloads, and lateral movement… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 15 | Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations… | mukul975/ | 34k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 16 | Automate network traffic analysis using tshark (Wireshark CLI) and pyshark to compute protocol distribution statistics, detect suspicious flows such as port scans and beaconing, extract IOCs (IPs… | mukul975/ | 34k | — | ~610 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 17 | A skill your agent uses whenever the user asks about Wireshark, tcpdump, packet capture, pcap analysis, HTTP/DNS/TCP/DHCP/TLS capture interpretation, network lab reports, protocol fields observed in… | mingchen666/ | 236 | — | ~657 | Automated safety check: Pass | No licence | 16 days ago |
| 18 | Traffic analysis and PCAP forensics playbook. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~2.8k | Automated safety check: Notes | MIT | 24 days ago |
| 19 | CTF 数字取证与信号分析技术。当挑战提供磁盘镜像(.dd/.E01)、内存 dump(.raw/.vmem)、网络抓包(.pcap/.pcapng)、隐写图片/音频、Windows 事件日志(.evtx)时使用。覆盖 Volatility 内存分析、Wireshark 流量还原、binwalk 隐写提取、文件系统恢复等取证全链路 | wgpsec/ | 1.8k | — | ~878 | Automated safety check: Notes | No licence | 3 days ago |
| 20 | Fast workflow to inspect PCAPs and extract protocol-level details using tshark | benchflow-ai/ | 1.8k | — | ~328 | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 21 | Analyze packet captures and network telemetry for intrusion evidence — capture and handling, the Wireshark/tshark triage funnel, Zeek log mining, Suricata rule runs, beacon and DNS-tunnel detection… | trilwu/ | 156 | — | ~5.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 22 | CML packet capture — start, stop, download pcaps from CML lab links, integrate with Packet Buddy for analysis. | automateyournetwork/ | 674 | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 23 | Guidance for analyzing network packet captures (PCAP files) and computing network statistics using Python, with tested utility functions. | benchflow-ai/ | 1.8k | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 24 | Reverse engineer undocumented binary network protocols from packet captures and the client that speaks them — recovering framing and field structure, identifying length prefixes, opcodes, checksums… | trilwu/ | 156 | — | ~1.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 25 | 25.Soe This skill should be used when the user asks to "analyze security alerts", "parse vulnerability scan report", "analyze vulnerability scan report", "verify CVE fix", "analyze WAF attack log"… | infometa/ | 342 | — | ~2.3k | Automated safety check: Notes | No licence | today |
| 26 | 26.Re Iot Proto 物联网协议:MQTT/CoAP/BLE/Zigbee;BLE 链路层(广播解析/配对加密)与 NFC/智能卡(ISO14443/APDU/MIFARE)。 | dslsdzc/ | 117 | — | ~3.2k | Automated safety check: Notes | Apache-2.0 | 2 days ago |
| 27 | Conducts digital forensics investigations following a personal data breach, covering evidence preservation, chain of custody documentation, log analysis, scope determination, and root cause analysis. | mukul975/ | 295 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 28 | RouterOS packet capture and TZSP streaming for protocol debugging. | aiskillstore/ | 430 | — | ~2.6k | Automated safety check: Pass | No licence | today |
Questions, answered from the data.
What is the best Wireshark skill?
Dfir from transilienceai/communitytools ranks first of the 28 Wireshark skills listed here, with the highest score: its repository has 559 GitHub stars, its SKILL.md loads about 1.5k tokens and it passes the automated safety check with no findings. Next come Iotnet and Wireshark Analysis.
Is there an official Wireshark skill?
None yet. All 28 Wireshark skills listed here come from community repositories; a skill counts as official when the product's own GitHub organization publishes it.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.