Cross-platform JavaScript Dataset Networking - MAC address manufacturer lookup database combining IEEE, Nmap, Wireshark and HDM Mac-Tracker, with downloadable formats and a browser lookup.
ringmast4r@github:~$ cat oui-master-db.txt
PURPOSE: MAC address vendor lookup, the comprehensive way
SCOPE: Every IEEE registry + Wireshark + Nmap + HDM Mac-Tracker
COVERAGE: 58,997 unique OUIs, 110,501 cross-validated entries
FORMATS: TXT, CSV, TSV, JSON, JSON-min, XML, SQLite, SQL, Kismet, Kismet.gz
UPDATES: First of every month via GitHub Actions
USE CASES: Wardriving | Network forensics | IoT discovery | Threat intel
STATUS: [ LIVE & AUTO-UPDATING ]OUI = the first 3 bytes of a MAC address that identifies the manufacturer. Most lookup databases pick one source. We merged all of them.
| METRIC | COUNT | NOTES |
|---|---|---|
| Total Unique OUIs | 58,997 |
Deduplicated across 4 sources |
| Cross-Validated | 110,501 |
Same OUI from multiple sources |
| IEEE Registry Total | 58,902 |
MA-L + MA-M + MA-S + IAB + CID |
| Device Categories | 25 |
Auto-classified |
| File Formats | 10 |
TXT to SQLite |
| Monthly New OUIs | ~-22294 |
IEEE assignments |
%%{init: {'theme':'dark', 'themeVariables': {'xyChart': {'backgroundColor':'#00000000','plotColorPalette':'#1E40AF','titleColor':'#1E40AF','xAxisLabelColor':'#ffffff','yAxisLabelColor':'#ffffff'}}}}%%
xychart-beta
title "OUI Count Growth (Last 6 Auto-Updates)"
x-axis ["2026-08-21", "2026-09-01", "2026-09-11", "2026-09-21", "2026-09-30", "2026-10-01"]
y-axis "Total OUIs" 58800 --> 90400
bar [89890, 90028, 90168, 90281, 58972, 58997]
line [89890, 90028, 90168, 90281, 58972, 58997]
+-30,893 OUIs in ~6 weeks · IEEE assigns roughly -22,294 new vendors/month · Next refresh: first of next month
%%{init: {'theme':'dark', 'themeVariables': {'pie1':'#1E40AF','pie2':'#3B82F6','pie3':'#60A5FA','pie4':'#93C5FD','pie5':'#FFD700','pie6':'#1E3A8A','pieTitleTextSize':'18px','pieLegendTextSize':'14px'}}}%%
pie showData
title Where Each OUI Comes From
"All 3 (IEEE+Wireshark+Nmap)" : 51666
"IEEE+Wireshark" : 6751
"IEEE+Nmap" : 415
"mac-tracker" : 94
"IEEE only" : 67
"Nmap only" : 4
51,666 OUIs (88%) are confirmed by all three primary sources. The remaining single-source entries fill gaps that no individual database would catch on its own. That's the point.
| SOURCE | ENTRIES | LICENSE | URL |
|---|---|---|---|
58,902 |
Public Domain | standards-oui.ieee.org | |
58,417 |
GPLv2 | wireshark.org | |
52,085 |
GPLv2 (mod.) | nmap-mac-prefixes | |
59,020 |
MIT | hdm/mac-tracker |
%%{init: {'theme':'dark', 'themeVariables': {'pie1':'#1E40AF','pie2':'#3B82F6','pie3':'#60A5FA','pie4':'#93C5FD','pie5':'#FFD700','pieTitleTextSize':'18px','pieLegendTextSize':'14px'}}}%%
pie showData
title IEEE Registry Distribution (58,902 entries)
"MA-L (Large, ~16M each)" : 40286
"MA-S (Small, ~4K each)" : 7211
"MA-M (Medium, ~1M each)" : 6610
"IAB (Individual Block)" : 4575
"CID (Company ID)" : 220
| REGISTRY | ENTRIES | BLOCK SIZE | TYPICAL USE |
|---|---|---|---|
| MA-L | 40,286 |
24-bit (~16M MACs) | Large-scale manufacturers |
| MA-S | 7,211 |
36-bit (~4K MACs) | IoT, niche hardware |
| MA-M | 6,610 |
28-bit (~1M MACs) | Mid-volume vendors |
| IAB | 4,575 |
Individual | Legacy individual blocks |
| CID | 220 |
Company-only ID | Non-MAC company markers |
⚠ IEEE doesn't expose device category. Our classifier is a heuristic on company name + known-vendor lookups, so only 30,875 of 58,997 OUIs (52.3%) get a category. The remaining 28,122 stay
Unclassifiedrather than guessed.
%%{init: {'theme':'dark', 'themeVariables': {'pie1':'#1E40AF','pie2':'#3B82F6','pie3':'#60A5FA','pie4':'#93C5FD','pie5':'#FFD700','pie6':'#1E3A8A','pie7':'#00D4FF','pie8':'#9FEF00','pie9':'#FF00FF','pie10':'#8B5CF6','pie11':'#FF6B6B','pie12':'#00FF88','pieTitleTextSize':'16px','pieLegendTextSize':'12px'}}}%%
pie showData
title Classified Device Types (30,875 of 58,997)
"Phone" : 6665
"Industrial" : 3989
"Router" : 3788
"IoT" : 2243
"Access Point" : 2187
"Smart Home" : 2163
"Automotive" : 1193
"Laptop" : 1144
"Camera" : 1051
"Medical" : 859
"Audio" : 827
"Other (14 cats)" : 4766
Full device-type table (24 categories)
| CATEGORY | COUNT | CATEGORY | COUNT |
|---|---|---|---|
| Phone | 6,665 |
Modem | 599 |
| Industrial | 3,989 |
Media Player | 498 |
| Router | 3,788 |
Printer | 456 |
| IoT | 2,243 |
Switch | 408 |
| Access Point | 2,187 |
VoIP | 335 |
| Smart Home | 2,163 |
Appliance | 298 |
| Automotive | 1,193 |
Gaming | 251 |
| Laptop | 1,144 |
Storage | 206 |
| Camera | 1,051 |
Server | 153 |
| Medical | 859 |
Wearable | 142 |
| Audio | 827 |
Tablet | 52 |
| TV | 689 |
Thermostat | 33 |
| Computer | 646 |
MAC Address: 3C:D9:2B:12:34:56
└─OUI─┘ └─Device─┘
OUI: 3C:D9:2B
Manufacturer: Hewlett Packard
Device Type: Computer
Country: US
Registry: MA-L
Sources: IEEE + Wireshark + Nmap
Why this matters:
- Identify rogue/unauthorized devices on your network
- Categorize WiFi APs by vendor while wardriving
- Discover IoT devices, cameras, printers across a subnet
- Detect MAC spoofing (compare OUI registry vs claimed vendor)
| FORMAT | SIZE | BEST FOR | DOWNLOAD |
|---|---|---|---|
| minimal | grep/awk, legacy tools |
master_oui.txt | |
| full | Spreadsheets, dataframes | master_oui.csv | |
| medium | Excel/Sheets (no quote issues) | master_oui.tsv | |
| pretty | APIs, human-readable | master_oui.json | |
| compact | Scripts, fast loading | master_oui.min.json | |
| enterprise | Java, XSLT | master_oui.xml | |
| indexed | Ready-to-query DB | master_oui.db | |
| script | Postgres/MySQL/D1 import | import-to-d1.sql | |
| text | Kismet wireless IDS | kismet_manuf.txt | |
| compressed | Kismet drop-in install | kismet_manuf.txt.gz |
https://raw.githubusercontent.com/Ringmast4r/OUI-Master-Database/master/LISTS/master_oui.txt
https://raw.githubusercontent.com/Ringmast4r/OUI-Master-Database/master/LISTS/master_oui.csv
https://raw.githubusercontent.com/Ringmast4r/OUI-Master-Database/master/LISTS/master_oui.json
https://raw.githubusercontent.com/Ringmast4r/OUI-Master-Database/master/LISTS/master_oui.db| FIELD | TYPE | EXAMPLE |
|---|---|---|
oui |
string | 3C:D9:2B |
manufacturer |
string | Hewlett Packard (canonical - one name per organization) |
registrant_raw |
string | Hewlett Packard Enterprise (the literal registry text) |
short_name |
string | HP |
registry |
enum | MA-L, MA-M, MA-S, IAB, CID |
device_type |
enum | Router, Phone, Camera, IoT, ... |
address |
string | 11445 Compaq Center Dr, Houston TX US |
country |
iso2 | US, CN, DE, JP |
registered_date |
date | 2012-05-15 |
status |
enum | current (IEEE lists it today), deregistered (IEEE deleted it), legacy (only Wireshark/Nmap still carry it) |
deregistered_date |
date | 2021-03-02 (only for deregistered) |
registrant_history |
string | TEKELEC | PRIVATE | TEKELEC | Oracle (every registrant the block has had, oldest first; only when it changed) |
sources |
array | ["IEEE","Wireshark","Nmap"] |
manufacturer is unified per organization: IEEE keeps every spelling a registrant ever typed (Nintendo Co., Ltd. and Nintendo Co.,Ltd were 110 blocks under two names), so the build resolves each registry string through the curated organization map in data/organizations.json and falls back to the most common spelling in the build. registrant_raw always carries the registry's own text, so nothing is lost.
Every source spells a block its own way (00:55:DA:0 at IEEE, 00:55:DA:00/28 in Wireshark, 0055DA0 in Nmap), so the merge now keys everything by the IEEE form; the same assignment no longer appears twice. status says whether IEEE lists a block today, has deleted it (deregistered_date), or whether only the community lists still carry it - old captures need those rows, but they are not current registrations. registrant_history comes from runZero's mac-tracker, which has tracked every IEEE add, change and delete since 1998.
import json
with open('LISTS/master_oui.min.json') as f:
db = json.load(f)
def lookup(mac):
oui = mac[:8].upper()
return db.get(oui, {'manufacturer': 'Unknown'})
print(lookup('00:00:0C:12:34:56'))
# {'manufacturer': 'Cisco Systems, Inc', 'device_type': 'Router', 'country': 'US'}const db = require('./LISTS/master_oui.json');
const lookup = mac => db[mac.substring(0,8).toUpperCase()] || { manufacturer: 'Unknown' };
console.log(lookup('00:00:0C:12:34:56'));sqlite3 LISTS/master_oui.db "SELECT * FROM oui_registry WHERE oui = '00:00:0C'"
sqlite3 LISTS/master_oui.db "SELECT device_type, COUNT(*) FROM oui_registry GROUP BY device_type ORDER BY 2 DESC"grep "3CD92B" LISTS/master_oui.txt
grep -i "apple" LISTS/master_oui.txt | headcurl -s https://raw.githubusercontent.com/Ringmast4r/OUI-Master-Database/master/LISTS/master_oui.txt | grep -i "00000C"Cross-platform Node.js CLI in CLI TOOL/ — works on Windows / Linux / macOS.
cd "CLI TOOL"
node oui-lookup.js --interactive # Continuous lookup REPL
node oui-lookup.js 00:00:0C:12:34:56 # Single lookup
node oui-lookup.js --search cisco # Search by manufacturer
node oui-lookup.js --wifi # Scan nearby WiFi + show vendors
node oui-lookup.js --bluetooth # Scan BT devices + show vendors
node oui-lookup.js --arp # Local ARP table with vendors
node oui-lookup.js --stats # Database statistics| FEATURE | WIN | LINUX | MAC |
|---|---|---|---|
| WiFi Scan | netsh wlan |
nmcli |
airport |
| Bluetooth | PowerShell | bluetoothctl |
system_profiler |
| ARP Table | arp -a |
arp -a |
arp -a |
git clone https://github.com/Ringmast4r/OUI-Master-Database.git
cd OUI-Master-Database
npm install
bash download-sources.sh # Pulls IEEE + Wireshark + Nmap + HDM
node merge-oui-databases.js # Merges into LISTS/master_oui.*Windows: double-click update-database.bat.
The repo auto-updates on a monthly cron via GitHub Actions:
.github/workflows/update.yml -> runs at 02:00 UTC on the 1st of each month
Why monthly and not weekly? IEEE assigns ~300-400 OUIs/month. Polling more often just generates churn for marginal freshness on a slow-moving registry.
To self-host updates:
0 0 1 * * cd /path/to/OUI-Master-Database && bash download-sources.sh && node merge-oui-databases.js%%{init: {'theme':'dark', 'themeVariables': {'pie1':'#1E40AF','pie2':'#3B82F6','pie3':'#60A5FA','pie4':'#93C5FD','pie5':'#FFD700','pie6':'#9FEF00','pieTitleTextSize':'16px','pieLegendTextSize':'12px'}}}%%
pie showData
title Who Uses This (and How)
"Wardriving / WiFi mapping" : 30
"Network forensics & IR" : 22
"IoT / asset discovery" : 18
"Threat intel pipelines" : 12
"Educational / classroom" : 10
"Spoofing detection" : 8
Combining four authoritative sources, with respect for each license:
- IEEE Registration Authority · public domain · standards-oui.ieee.org
- Wireshark Manufacturer DB · GPLv2 · wireshark.org
- Nmap MAC Prefixes · modified GPLv2 · nmap.org
- HDM Mac-Tracker · MIT · hdm/mac-tracker
This project is MIT — use commercially, modify, redistribute, embed in proprietary tools.
Issues and PRs welcome. Most-wanted contributions:
- Better device-type heuristics (we're at 17.6% classified; let's get to 30%+)
- Country-code derivation from address strings
- Additional authoritative sources beyond the current four
- API wrapper libraries (Go, Rust, Ruby)
Last updated: 2026-10-01 · Total OUIs: 58,997 · Maintained by @Ringmast4r

