Macadress#
README
Macadress#
Enriches a MAC address observable with data from macadress.com: the registering vendor, an inferred device category, virtualization / container-network detection, special-use address classification (broadcast, multicast, VRRP, HSRP, STP, LACP, 802.1X, LLDP, ...), and MAC-randomization confidence. It calls the same lookup that backs the macadress.com JSON API, MCP server and website.
Supported data types#
macother(for deployments that store MAC addresses asother)
Configuration#
| Item | Required | Description |
|---|---|---|
api_key |
yes | macadress.com API key (Bearer token, starts with mk_). The free tier is 1,000 lookups/month with no card. Sign up at https://macadress.com/signup, then copy the key from the account page. |
The analyzer honours check_tlp / max_tlp (default max_tlp: 2, i.e.
TLP:RED observables are not sent off-box) and the PAP equivalents.
Output#
full is the raw macadress.com Result object
(https://macadress.com/docs). The summary taxonomies are:
| Taxonomy | Example | Level |
|---|---|---|
macadress:Vendor |
Apple, Inc. / locally-administered / unregistered |
info |
macadress:Device |
smartphone (omitted when unknown) |
info |
macadress:Virtualization |
VMware (only when detected) |
info |
macadress:SpecialUse |
VRRP (only when detected) |
info |
macadress:Randomized |
possible / likely |
info / suspicious |
artifacts surfaces the macadress.com vendor page URL(s) as url
observables.
Errors#
Explicit errorMessage is returned for a missing API key, an
unparseable MAC (HTTP 400), a rejected key (401), an exhausted quota or
rate limit (429), any other non-200, and network failures.
Macadress#
Author: Samy Massoud
License: AGPL-V3
Version: 1.0
Supported observables types:
- mac
- other
Registration required: True
Subscription required: True
Free subscription: True
Third party service: https://macadress.com
Description#
Identify the vendor, inferred device category, virtualization, special-use role and MAC-randomization confidence of a MAC address using macadress.com.
Configuration#
| api_key | macadress.com API key (Bearer token, starts with mk_). Free tier is 1,000 lookups per month with no card; sign up at https://macadress.com/signup |
|---|---|
| Default value if not configured | N/A |
| Type of the configuration item | string |
| The configuration item can contain multiple values | False |
| Is required | True |
Templates samples for TheHive#
No template samples to display.