OpenCTI connector

macadress.com for OpenCTI.

An internal enrichment connector that takes a Mac-Addr observable and adds the vendor identity, device category, virtualization detection, and randomization confidence for it, from the macadress.com API.

Official connector: merged into OpenCTI's connectors repository in PR #7463, shipping from release 7.260901.0. Listed on the Filigran Hub under Infrastructure & Attack Surface Visibility.

What it does

The connector registers as an internal enrichment connector for the Mac-Addr observable type. Run it from the enrichment menu, or on autopilot, and it calls macadress.com and:

Set up

Quota

Each enriched observable is one API call against your macadress.com plan quota, the same as any other lookup: see pricing for the per-plan budgets. The free plan allows 1,000 lookups on a rolling 30-day cycle.

Source and support

Licensed Apache-2.0, maintained in the OpenCTI connectors monorepo. Community-supported. API reference is at macadress.com/docs. Questions or a bug: get in touch.