Iotnet
BrownFineSecurity/iothackbot
IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications.
This skill should be used when the user asks to "analyze network traffic with Wireshark", "capture packets for troubleshooting", "filter PCAP files", "follow TCP/UDP streams", "detect network…
$ npx skills add zebbern/claude-code-guide --skill wireshark-analysis -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install zebbern/claude-code-guide wireshark-analysis --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/zebbern/claude-code-guide.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/wireshark-analysis .claude/skills/wireshark-analysis && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "wireshark-analysis" agent skill from https://github.com/zebbern/claude-code-guide/tree/main/skills/wireshark-analysis into .claude/skills/wireshark-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wireshark-analysis", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/zebbern/claude-code-guide/tree/main/skills/wireshark-analysisType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add zebbern/claude-code-guide --skill wireshark-analysis -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install zebbern/claude-code-guide wireshark-analysis --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zebbern/claude-code-guide.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/wireshark-analysis .agents/skills/wireshark-analysis && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "wireshark-analysis" agent skill from https://github.com/zebbern/claude-code-guide/tree/main/skills/wireshark-analysis into .agents/skills/wireshark-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wireshark-analysis", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add zebbern/claude-code-guide --skill wireshark-analysis -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install zebbern/claude-code-guide wireshark-analysis --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zebbern/claude-code-guide.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/wireshark-analysis .cursor/skills/wireshark-analysis && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "wireshark-analysis" agent skill from https://github.com/zebbern/claude-code-guide/tree/main/skills/wireshark-analysis into .cursor/skills/wireshark-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wireshark-analysis", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/zebbern/claude-code-guide.git --path skills/wireshark-analysis--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add zebbern/claude-code-guide --skill wireshark-analysis -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install zebbern/claude-code-guide wireshark-analysis --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zebbern/claude-code-guide.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/wireshark-analysis .gemini/skills/wireshark-analysis && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "wireshark-analysis" agent skill from https://github.com/zebbern/claude-code-guide/tree/main/skills/wireshark-analysis into .gemini/skills/wireshark-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wireshark-analysis", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install zebbern/claude-code-guide wireshark-analysisInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add zebbern/claude-code-guide --skill wireshark-analysis -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/zebbern/claude-code-guide.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/wireshark-analysis .github/skills/wireshark-analysis && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "wireshark-analysis" agent skill from https://github.com/zebbern/claude-code-guide/tree/main/skills/wireshark-analysis into .github/skills/wireshark-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wireshark-analysis", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add zebbern/claude-code-guide --skill wireshark-analysis -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install zebbern/claude-code-guide wireshark-analysis --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zebbern/claude-code-guide.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/wireshark-analysis .opencode/skills/wireshark-analysis && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "wireshark-analysis" agent skill from https://github.com/zebbern/claude-code-guide/tree/main/skills/wireshark-analysis into .opencode/skills/wireshark-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wireshark-analysis", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
wireshark-analysisThis skill should be used when the user asks to "analyze network traffic with Wireshark", "capture packets for troubleshooting", "filter PCAP files", "follow TCP/UDP streams", "detect network…
Wireshark Analysis is an agent skill from zebbern/claude-code-guide. This skill should be used when the user asks to "analyze network traffic with Wireshark", "capture packets for troubleshooting", "filter PCAP files", "follow TCP/UDP streams", "detect network anomalies", "investigate suspicious traffic", or "perform protocol analysis". It provides comprehensive techniques for network packet capture, filtering, and analysis using Wireshark.
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Network security. It works with Wireshark. The repository describes itself as: Claude Code Guide - Setup, Commands, workflows, agents, skills & tips-n-tricks from beginner to power user! The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9cde898. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
sshFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use ssh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Wireshark Analysis loads about 3k tokens when it runs. Until then it costs about 99 tokens; SKILL.md has 708 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from zebbern/claude-code-guide at commit 9cde898, republished under its MIT licence (© zebbern). 708 words, ~3,040 tokens.
.claude/skills/wireshark-analysis/SKILL.md (or your agent's skills folder).Execute comprehensive network traffic analysis using Wireshark to capture, filter, and examine network packets for security investigations, performance optimization, and troubleshooting. This skill enables systematic analysis of network protocols, detection of anomalies, and reconstruction of network conversations from PCAP files.
Begin capturing packets on network interface:
1. Launch Wireshark
2. Select network interface from main screen
3. Click shark fin icon or double-click interface
4. Capture begins immediately| Action | Shortcut | Description |
|---|---|---|
| Start/Stop Capture | Ctrl+E | Toggle capture on/off |
| Restart Capture | Ctrl+R | Stop and start new capture |
| Open PCAP File | Ctrl+O | Load existing capture file |
| Save Capture | Ctrl+S | Save current capture |
Apply filters before capture to limit data collection:
# Capture only specific host
host 192.168.1.100
# Capture specific port
port 80
# Capture specific network
net 192.168.1.0/24
# Exclude specific traffic
not arp
# Combine filters
host 192.168.1.100 and port 443Filter captured packets for analysis:
# IP address filters
ip.addr == 192.168.1.1 # All traffic to/from IP
ip.src == 192.168.1.1 # Source IP only
ip.dst == 192.168.1.1 # Destination IP only
# Port filters
tcp.port == 80 # TCP port 80
udp.port == 53 # UDP port 53
tcp.dstport == 443 # Destination port 443
tcp.srcport == 22 # Source port 22Filter by specific protocols:
# Common protocols
http # HTTP traffic
https or ssl or tls # Encrypted web traffic
dns # DNS queries and responses
ftp # FTP traffic
ssh # SSH traffic
icmp # Ping/ICMP traffic
arp # ARP requests/responses
dhcp # DHCP traffic
smb or smb2 # SMB file sharingIdentify specific connection states:
tcp.flags.syn == 1 # SYN packets (connection attempts)
tcp.flags.ack == 1 # ACK packets
tcp.flags.fin == 1 # FIN packets (connection close)
tcp.flags.reset == 1 # RST packets (connection reset)
tcp.flags.syn == 1 && tcp.flags.ack == 0 # SYN-only (initial connection)Search for specific content:
frame contains "password" # Packets containing string
http.request.uri contains "login" # HTTP URIs with string
tcp contains "GET" # TCP packets with stringIdentify potential issues:
tcp.analysis.retransmission # TCP retransmissions
tcp.analysis.duplicate_ack # Duplicate ACKs
tcp.analysis.zero_window # Zero window (flow control)
tcp.analysis.flags # Packets with issues
dns.flags.rcode != 0 # DNS errorsUse logical operators for complex queries:
# AND operator
ip.addr == 192.168.1.1 && tcp.port == 80
# OR operator
dns || http
# NOT operator
!(arp || icmp)
# Complex combinations
(ip.src == 192.168.1.1 || ip.src == 192.168.1.2) && tcp.port == 443View complete TCP conversation:
1. Right-click on any TCP packet
2. Select Follow > TCP Stream
3. View reconstructed conversation
4. Toggle between ASCII, Hex, Raw views
5. Filter to show only this stream| Stream | Access | Use Case |
|---|---|---|
| TCP Stream | Follow > TCP Stream | Web, file transfers, any TCP |
| UDP Stream | Follow > UDP Stream | DNS, VoIP, streaming |
| HTTP Stream | Follow > HTTP Stream | Web content, headers |
| TLS Stream | Follow > TLS Stream | Encrypted traffic (if keys available) |
View protocol distribution:
Statistics > Protocol Hierarchy
Shows:
- Percentage of each protocol
- Packet counts
- Bytes transferred
- Protocol breakdown treeAnalyze communication pairs:
Statistics > Conversations
Tabs:
- Ethernet: MAC address pairs
- IPv4/IPv6: IP address pairs
- TCP: Connection details (ports, bytes, packets)
- UDP: Datagram exchangesView active network participants:
Statistics > Endpoints
Shows:
- All source/destination addresses
- Packet and byte counts
- Geographic information (if enabled)Visualize packet sequence:
Statistics > Flow Graph
Options:
- All packets or displayed only
- Standard or TCP flow
- Shows packet timing and directionPlot traffic over time:
Statistics > I/O Graph
Features:
- Packets per second
- Bytes per second
- Custom filter graphs
- Multiple graph overlaysIdentify reconnaissance activity:
# SYN scan detection (many ports, same source)
ip.src == SUSPECT_IP && tcp.flags.syn == 1
# Review Statistics > Conversations for anomalies
# Look for single source hitting many destination portsFilter for anomalies:
# Traffic to unusual ports
tcp.dstport > 1024 && tcp.dstport < 49152
# Traffic outside trusted network
!(ip.addr == 192.168.1.0/24)
# Unusual DNS queries
dns.qry.name contains "suspicious-domain"
# Large data transfers
frame.len > 1400Identify ARP attacks:
# Duplicate ARP responses
arp.duplicate-address-frame
# ARP traffic analysis
arp
# Look for:
# - Multiple MACs for same IP
# - Gratuitous ARP floods
# - Unusual ARP patternsAnalyze file transfers:
# HTTP file downloads
http.request.method == "GET" && http contains "Content-Disposition"
# Follow HTTP Stream to view file content
# Use File > Export Objects > HTTP to extract filesInvestigate DNS activity:
# All DNS traffic
dns
# DNS queries only
dns.flags.response == 0
# DNS responses only
dns.flags.response == 1
# Failed DNS lookups
dns.flags.rcode != 0
# Specific domain queries
dns.qry.name contains "domain.com"View Wireshark's automated findings:
Analyze > Expert Information
Categories:
- Errors: Critical issues
- Warnings: Potential problems
- Notes: Informational items
- Chats: Normal conversation events| Finding | Meaning | Action |
|---|---|---|
| TCP Retransmission | Packet resent | Check for packet loss |
| Duplicate ACK | Possible loss | Investigate network path |
| Zero Window | Buffer full | Check receiver performance |
| RST | Connection reset | Check for blocks/errors |
| Out-of-Order | Packets reordered | Usually normal, excessive is issue |
| Action | Shortcut |
|---|---|
| Open file | Ctrl+O |
| Save file | Ctrl+S |
| Start/Stop capture | Ctrl+E |
| Find packet | Ctrl+F |
| Go to packet | Ctrl+G |
| Next packet | ↓ |
| Previous packet | ↑ |
| First packet | Ctrl+Home |
| Last packet | Ctrl+End |
| Apply filter | Enter |
| Clear filter | Ctrl+Shift+X |
# Web traffic
http || https
# Email
smtp || pop || imap
# File sharing
smb || smb2 || ftp
# Authentication
ldap || kerberos
# Network management
snmp || icmp
# Encrypted
tls || sslFile > Export Specified Packets # Save filtered subset
File > Export Objects > HTTP # Extract HTTP files
File > Export Packet Dissections # Export as text/CSVScenario: Investigate potential plaintext credential transmission
1. Filter: http.request.method == "POST"
2. Look for login forms
3. Follow HTTP Stream
4. Search for username/password parametersFinding: Credentials transmitted in cleartext form data.
Scenario: Identify command and control traffic
1. Filter: dns
2. Look for unusual query patterns
3. Check for high-frequency beaconing
4. Identify domains with random-looking names
5. Filter: ip.dst == SUSPICIOUS_IP
6. Analyze traffic patternsIndicators:
Scenario: Diagnose slow web application
1. Filter: ip.addr == WEB_SERVER
2. Check Statistics > Service Response Time
3. Filter: tcp.analysis.retransmission
4. Review I/O Graph for patterns
5. Check for high latency or packet lossFinding: TCP retransmissions indicating network congestion.
© zebbern, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/wireshark-analysis of zebbern/claude-code-guide.
Open the folder on GitHubat commit 9cde898
We found 18 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 8 other GitHub owners. This page covers the copy in zebbern/claude-code-guide, which our catalogue first saw on October 7, 2026.
Wireshark Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Wireshark Analysis this skillzebbern/claude-code-guide | 4.7k | 8 repos | ~3k | Automated safety check: Pass | MIT | |
| IotnetBrownFineSecurity/iothackbot | 859 | 1 repos | ~1k | Automated safety check: Notes | MIT | |
| Netzhinkgit/embeddedskills | 734 | — | ~1.1k | Automated safety check: Pass | MIT | |
| Performing Network Forensics With Wiresharkmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Notes | Apache-2.0 | |
| Performing Network Traffic Analysis With Zeekmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.2k | Automated safety check: Notes | Apache-2.0 | |
| Analyzing Network Traffic With Wiresharkmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 |
BrownFineSecurity/iothackbot
IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications.
zhinkgit/embeddedskills
嵌入式网络调试工具,用于发现接口、抓包、分析 pcap/pcapng、做连通性测试、端口扫描和流量统计. An agent skill from zhinkgit/embeddedskills.
mukul975/Anthropic-Cybersecurity-Skills
Capture and analyze network traffic using Wireshark and tshark to reconstruct network events from PCAP/PCAPNG files, extract transferred files and credentials, and identify command-and-control…
mukul975/Anthropic-Cybersecurity-Skills
Deploy Zeek (formerly Bro) as a passive network security monitor to generate structured logs of protocol metadata (HTTP, DNS, TLS, SSH, SMTP, FTP, and more), write custom detection scripts, and…
mukul975/Anthropic-Cybersecurity-Skills
Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations…
mukul975/Anthropic-Cybersecurity-Skills
Automate network traffic analysis using tshark (Wireshark CLI) and pyshark to compute protocol distribution statistics, detect suspicious flows such as port scans and beaconing, extract IOCs (IPs…
zebbern/claude-code-guide
This skill should be used when setting up, auditing, or enforcing internationalization/localization in UI codebases (React/TS, i18next or similar, JSON locales), including installing/configuring the…
zebbern/claude-code-guide
Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export.
zebbern/claude-code-guide
Generate publication-quality PNG chart images from data, supporting line, bar, area, candlestick, pie, and heatmap charts.
zebbern/claude-code-guide
Analyze codebases and automatically generate architecture diagrams, flowcharts, and org charts.
zebbern/claude-code-guide
Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection.
zebbern/claude-code-guide
This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"…
Works with
Categories
This skill should be used when the user asks to "analyze network traffic with Wireshark", "capture packets for troubleshooting", "filter PCAP files", "follow TCP/UDP streams", "detect network…. Wireshark Analysis is an agent skill from zebbern/claude-code-guide. This skill should be used when the user asks to "analyze network traffic with Wireshark", "capture packets for troubleshooting", "filter PCAP files", "follow TCP/UDP streams", "detect network anomalies", "investigate suspicious traffic", or "perform protocol analysis".
Wireshark Analysis fits situations like: asks to analyze network traffic with Wireshark; capture packets for troubleshooting; filter PCAP files; follow TCP/UDP streams.
Run `npx skills add zebbern/claude-code-guide --skill wireshark-analysis -a claude-code`. Or copy the skill folder (skills/wireshark-analysis in zebbern/claude-code-guide) into .claude/skills/wireshark-analysis in your project. Claude Code loads it when a task matches its description.
Run `npx skills add zebbern/claude-code-guide --skill wireshark-analysis -a codex`. Or copy the skill folder (skills/wireshark-analysis in zebbern/claude-code-guide) into .agents/skills/wireshark-analysis in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zebbern/claude-code-guide --skill wireshark-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wireshark-analysis, .gemini/skills/wireshark-analysis, .github/skills/wireshark-analysis and .opencode/skills/wireshark-analysis in your project.
Going by SKILL.md and its folder, Wireshark Analysis needs the command-line tools its instructions call (ssh).
SKILL.md contains no URLs. Its commands use ssh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Wireshark Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Wireshark Analysis: Iotnet (BrownFineSecurity/iothackbot, 859 stars), Net (zhinkgit/embeddedskills, 734 stars), Performing Network Forensics With Wireshark (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Performing Network Traffic Analysis With Zeek (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
zebbern (a GitHub user) maintains it in zebbern/claude-code-guide, which has 4,652 GitHub stars. The repository holds 46 skills in this directory. The repository was last updated on October 9, 2026.
Source: zebbern/claude-code-guide on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.