Skip to content

Repository files navigation

Cross-platform JavaScript Dataset Networking - MAC address manufacturer lookup database combining IEEE, Nmap, Wireshark and HDM Mac-Tracker, with downloadable formats and a browser lookup.

Project website / live view

Typing SVG


OUIs Formats Updates License Live Demo

Stars Forks Repo Size Last Commit Visitors

OUI Master Database Logo

> what_is_this

ringmast4r@github:~$ cat oui-master-db.txt

  PURPOSE:        MAC address vendor lookup, the comprehensive way
  SCOPE:          Every IEEE registry + Wireshark + Nmap + HDM Mac-Tracker
  COVERAGE:       58,997 unique OUIs, 110,501 cross-validated entries
  FORMATS:        TXT, CSV, TSV, JSON, JSON-min, XML, SQLite, SQL, Kismet, Kismet.gz
  UPDATES:        First of every month via GitHub Actions
  USE CASES:      Wardriving | Network forensics | IoT discovery | Threat intel

  STATUS:         [ LIVE & AUTO-UPDATING ]

OUI = the first 3 bytes of a MAC address that identifies the manufacturer. Most lookup databases pick one source. We merged all of them.


> stats --live

METRIC COUNT NOTES
Total Unique OUIs 58,997 Deduplicated across 4 sources
Cross-Validated 110,501 Same OUI from multiple sources
IEEE Registry Total 58,902 MA-L + MA-M + MA-S + IAB + CID
Device Categories 25 Auto-classified
File Formats 10 TXT to SQLite
Monthly New OUIs ~-22294 IEEE assignments

> growth --monthly

%%{init: {'theme':'dark', 'themeVariables': {'xyChart': {'backgroundColor':'#00000000','plotColorPalette':'#1E40AF','titleColor':'#1E40AF','xAxisLabelColor':'#ffffff','yAxisLabelColor':'#ffffff'}}}}%%
xychart-beta
    title "OUI Count Growth (Last 6 Auto-Updates)"
    x-axis ["2026-08-21", "2026-09-01", "2026-09-11", "2026-09-21", "2026-09-30", "2026-10-01"]
    y-axis "Total OUIs" 58800 --> 90400
    bar [89890, 90028, 90168, 90281, 58972, 58997]
    line [89890, 90028, 90168, 90281, 58972, 58997]
Loading

+-30,893 OUIs in ~6 weeks · IEEE assigns roughly -22,294 new vendors/month · Next refresh: first of next month


> sources --breakdown

%%{init: {'theme':'dark', 'themeVariables': {'pie1':'#1E40AF','pie2':'#3B82F6','pie3':'#60A5FA','pie4':'#93C5FD','pie5':'#FFD700','pie6':'#1E3A8A','pieTitleTextSize':'18px','pieLegendTextSize':'14px'}}}%%
pie showData
    title Where Each OUI Comes From
    "All 3 (IEEE+Wireshark+Nmap)" : 51666
    "IEEE+Wireshark" : 6751
    "IEEE+Nmap" : 415
    "mac-tracker" : 94
    "IEEE only" : 67
    "Nmap only" : 4
Loading

51,666 OUIs (88%) are confirmed by all three primary sources. The remaining single-source entries fill gaps that no individual database would catch on its own. That's the point.

Source Roster

SOURCE ENTRIES LICENSE URL
IEEE 58,902 Public Domain standards-oui.ieee.org
Wireshark 58,417 GPLv2 wireshark.org
Nmap 52,085 GPLv2 (mod.) nmap-mac-prefixes
HDM 59,020 MIT hdm/mac-tracker

> registries --ieee

%%{init: {'theme':'dark', 'themeVariables': {'pie1':'#1E40AF','pie2':'#3B82F6','pie3':'#60A5FA','pie4':'#93C5FD','pie5':'#FFD700','pieTitleTextSize':'18px','pieLegendTextSize':'14px'}}}%%
pie showData
    title IEEE Registry Distribution (58,902 entries)
    "MA-L (Large, ~16M each)" : 40286
    "MA-S (Small, ~4K each)" : 7211
    "MA-M (Medium, ~1M each)" : 6610
    "IAB (Individual Block)" : 4575
    "CID (Company ID)" : 220
Loading
REGISTRY ENTRIES BLOCK SIZE TYPICAL USE
MA-L 40,286 24-bit (~16M MACs) Large-scale manufacturers
MA-S 7,211 36-bit (~4K MACs) IoT, niche hardware
MA-M 6,610 28-bit (~1M MACs) Mid-volume vendors
IAB 4,575 Individual Legacy individual blocks
CID 220 Company-only ID Non-MAC company markers

> classification --devices

⚠ IEEE doesn't expose device category. Our classifier is a heuristic on company name + known-vendor lookups, so only 30,875 of 58,997 OUIs (52.3%) get a category. The remaining 28,122 stay Unclassified rather than guessed.

%%{init: {'theme':'dark', 'themeVariables': {'pie1':'#1E40AF','pie2':'#3B82F6','pie3':'#60A5FA','pie4':'#93C5FD','pie5':'#FFD700','pie6':'#1E3A8A','pie7':'#00D4FF','pie8':'#9FEF00','pie9':'#FF00FF','pie10':'#8B5CF6','pie11':'#FF6B6B','pie12':'#00FF88','pieTitleTextSize':'16px','pieLegendTextSize':'12px'}}}%%
pie showData
    title Classified Device Types (30,875 of 58,997)
    "Phone" : 6665
    "Industrial" : 3989
    "Router" : 3788
    "IoT" : 2243
    "Access Point" : 2187
    "Smart Home" : 2163
    "Automotive" : 1193
    "Laptop" : 1144
    "Camera" : 1051
    "Medical" : 859
    "Audio" : 827
    "Other (14 cats)" : 4766
Loading
Full device-type table (24 categories)
CATEGORY COUNT CATEGORY COUNT
Phone 6,665 Modem 599
Industrial 3,989 Media Player 498
Router 3,788 Printer 456
IoT 2,243 Switch 408
Access Point 2,187 VoIP 335
Smart Home 2,163 Appliance 298
Automotive 1,193 Gaming 251
Laptop 1,144 Storage 206
Camera 1,051 Server 153
Medical 859 Wearable 142
Audio 827 Tablet 52
TV 689 Thermostat 33
Computer 646

> demo --live

Live Demo

Search by MAC address or manufacturer name. Runs entirely in your browser. No tracking.


> example

MAC Address:  3C:D9:2B:12:34:56
              └─OUI─┘ └─Device─┘

OUI:          3C:D9:2B
Manufacturer: Hewlett Packard
Device Type:  Computer
Country:      US
Registry:     MA-L
Sources:      IEEE + Wireshark + Nmap

Why this matters:

  • Identify rogue/unauthorized devices on your network
  • Categorize WiFi APs by vendor while wardriving
  • Discover IoT devices, cameras, printers across a subnet
  • Detect MAC spoofing (compare OUI registry vs claimed vendor)

> ls LISTS/

Direct Downloads

FORMAT SIZE BEST FOR DOWNLOAD
TXT minimal grep/awk, legacy tools master_oui.txt
CSV full Spreadsheets, dataframes master_oui.csv
TSV medium Excel/Sheets (no quote issues) master_oui.tsv
JSON pretty APIs, human-readable master_oui.json
JSON-min compact Scripts, fast loading master_oui.min.json
XML enterprise Java, XSLT master_oui.xml
SQLite indexed Ready-to-query DB master_oui.db
SQL script Postgres/MySQL/D1 import import-to-d1.sql
Kismet text Kismet wireless IDS kismet_manuf.txt
Kismet.gz compressed Kismet drop-in install kismet_manuf.txt.gz

Raw URLs (cron / curl friendly)

https://raw.githubusercontent.com/Ringmast4r/OUI-Master-Database/master/LISTS/master_oui.txt
https://raw.githubusercontent.com/Ringmast4r/OUI-Master-Database/master/LISTS/master_oui.csv
https://raw.githubusercontent.com/Ringmast4r/OUI-Master-Database/master/LISTS/master_oui.json
https://raw.githubusercontent.com/Ringmast4r/OUI-Master-Database/master/LISTS/master_oui.db

> data_fields

FIELD TYPE EXAMPLE
oui string 3C:D9:2B
manufacturer string Hewlett Packard (canonical - one name per organization)
registrant_raw string Hewlett Packard Enterprise (the literal registry text)
short_name string HP
registry enum MA-L, MA-M, MA-S, IAB, CID
device_type enum Router, Phone, Camera, IoT, ...
address string 11445 Compaq Center Dr, Houston TX US
country iso2 US, CN, DE, JP
registered_date date 2012-05-15
status enum current (IEEE lists it today), deregistered (IEEE deleted it), legacy (only Wireshark/Nmap still carry it)
deregistered_date date 2021-03-02 (only for deregistered)
registrant_history string TEKELEC | PRIVATE | TEKELEC | Oracle (every registrant the block has had, oldest first; only when it changed)
sources array ["IEEE","Wireshark","Nmap"]

manufacturer is unified per organization: IEEE keeps every spelling a registrant ever typed (Nintendo Co., Ltd. and Nintendo Co.,Ltd were 110 blocks under two names), so the build resolves each registry string through the curated organization map in data/organizations.json and falls back to the most common spelling in the build. registrant_raw always carries the registry's own text, so nothing is lost.

Every source spells a block its own way (00:55:DA:0 at IEEE, 00:55:DA:00/28 in Wireshark, 0055DA0 in Nmap), so the merge now keys everything by the IEEE form; the same assignment no longer appears twice. status says whether IEEE lists a block today, has deleted it (deregistered_date), or whether only the community lists still carry it - old captures need those rows, but they are not current registrations. registrant_history comes from runZero's mac-tracker, which has tracked every IEEE add, change and delete since 1998.


> usage

python

import json

with open('LISTS/master_oui.min.json') as f:
    db = json.load(f)

def lookup(mac):
    oui = mac[:8].upper()
    return db.get(oui, {'manufacturer': 'Unknown'})

print(lookup('00:00:0C:12:34:56'))
# {'manufacturer': 'Cisco Systems, Inc', 'device_type': 'Router', 'country': 'US'}

node.js

const db = require('./LISTS/master_oui.json');
const lookup = mac => db[mac.substring(0,8).toUpperCase()] || { manufacturer: 'Unknown' };
console.log(lookup('00:00:0C:12:34:56'));

sqlite3

sqlite3 LISTS/master_oui.db "SELECT * FROM oui_registry WHERE oui = '00:00:0C'"
sqlite3 LISTS/master_oui.db "SELECT device_type, COUNT(*) FROM oui_registry GROUP BY device_type ORDER BY 2 DESC"

grep (TXT)

grep "3CD92B" LISTS/master_oui.txt
grep -i "apple" LISTS/master_oui.txt | head

curl (one-liner)

curl -s https://raw.githubusercontent.com/Ringmast4r/OUI-Master-Database/master/LISTS/master_oui.txt | grep -i "00000C"

> cli_tool

Cross-platform Node.js CLI in CLI TOOL/ — works on Windows / Linux / macOS.

cd "CLI TOOL"
node oui-lookup.js --interactive          # Continuous lookup REPL
node oui-lookup.js 00:00:0C:12:34:56      # Single lookup
node oui-lookup.js --search cisco         # Search by manufacturer
node oui-lookup.js --wifi                 # Scan nearby WiFi + show vendors
node oui-lookup.js --bluetooth            # Scan BT devices + show vendors
node oui-lookup.js --arp                  # Local ARP table with vendors
node oui-lookup.js --stats                # Database statistics
FEATURE WIN LINUX MAC
WiFi Scan netsh wlan nmcli airport
Bluetooth PowerShell bluetoothctl system_profiler
ARP Table arp -a arp -a arp -a

> generate --fresh

git clone https://github.com/Ringmast4r/OUI-Master-Database.git
cd OUI-Master-Database
npm install

bash download-sources.sh        # Pulls IEEE + Wireshark + Nmap + HDM
node merge-oui-databases.js     # Merges into LISTS/master_oui.*

Windows: double-click update-database.bat.


> update_schedule

The repo auto-updates on a monthly cron via GitHub Actions:

.github/workflows/update.yml -> runs at 02:00 UTC on the 1st of each month

Why monthly and not weekly? IEEE assigns ~300-400 OUIs/month. Polling more often just generates churn for marginal freshness on a slow-moving registry.

To self-host updates:

0 0 1 * * cd /path/to/OUI-Master-Database && bash download-sources.sh && node merge-oui-databases.js

> use_cases

%%{init: {'theme':'dark', 'themeVariables': {'pie1':'#1E40AF','pie2':'#3B82F6','pie3':'#60A5FA','pie4':'#93C5FD','pie5':'#FFD700','pie6':'#9FEF00','pieTitleTextSize':'16px','pieLegendTextSize':'12px'}}}%%
pie showData
    title Who Uses This (and How)
    "Wardriving / WiFi mapping" : 30
    "Network forensics & IR" : 22
    "IoT / asset discovery" : 18
    "Threat intel pipelines" : 12
    "Educational / classroom" : 10
    "Spoofing detection" : 8
Loading

> credits

Combining four authoritative sources, with respect for each license:

This project is MIT — use commercially, modify, redistribute, embed in proprietary tools.


> related_projects

WiFi Mothership FLOCK Tower-Hunter MAC-SPOOFER


> contributing

Issues and PRs welcome. Most-wanted contributions:

  • Better device-type heuristics (we're at 17.6% classified; let's get to 30%+)
  • Country-code derivation from address strings
  • Additional authoritative sources beyond the current four
  • API wrapper libraries (Go, Rust, Ruby)

Last updated: 2026-10-01 · Total OUIs: 58,997 · Maintained by @Ringmast4r

About

`Cross-platform` `JavaScript` `Dataset` `Networking` - MAC address manufacturer lookup database combining IEEE, Nmap, Wireshark and HDM Mac-Tracker, with downloadable formats and a browser lookup. https://ringmast4r.github.io/OUI-Master-Database/

Topics

Resources

Stars

132 stars

Watchers

5 watching

Forks

Releases

Packages

Contributors

Languages