Guide ยท Wireshark & tshark
How to Update or Override Wireshark's MAC Vendor Database
Current Wireshark versions compile their default IEEE manufacturer database into the application. A personal manuf file still lets you add or override vendor mappings without waiting for the next release.
Updated August 25, 2026
Open Wireshark, look at any packet's Ethernet layer, and you'll see something like Cisco_1a:2b:3c instead of a bare MAC address. Current Wireshark versions compile their default IEEE manufacturer database directly into the application rather than installing it as a separate manuf file, a change Wireshark made in 2023 for faster startup. Wireshark still reads a custom manuf file from its configuration folders if one exists, letting you supplement or override the built-in vendor mappings without waiting for a new Wireshark release. See Wireshark's own User's Guide chapter on name resolution for how it documents this itself.
Where the file lives
Wireshark looks in two places, in this order: a personal configuration directory that overrides the bundled copy, and the install directory itself. Replacing the personal copy is the one worth doing, since it survives Wireshark upgrades and doesn't need administrator privileges.
| OS | Personal config (recommended) |
|---|---|
| macOS | ~/Library/Application Support/Wireshark/manuf |
| Linux | ~/.config/wireshark/manuf |
| Windows | %APPDATA%\Wireshark\manuf |
Not sure that's right for your install? Wireshark will tell you: open Help > About Wireshark and check the Folders tab for the exact "Personal configuration" path on your machine.
Replacing it
- Download the current file from macadress.com/downloads (direct link: manuf.txt).
- Rename it to
manuf, no extension, and place it in your personal configuration directory from the table above (create the folder if it doesn't exist yet). - Restart Wireshark, or the next tshark run, so it re-reads the file.
- Confirm it worked: open a capture, check a packet's Ethernet layer for a resolved vendor name, or open Edit > Preferences > Name Resolution and make sure MAC name resolution is enabled.
- Optional: before or after overriding it, run
tshark -G manufto export Wireshark's current compiled-in vendor table in the same format. Useful as a quick diff against the file you're about to install, or as a backup of what Wireshark shipped with before you replace it.
tshark reads the same personal configuration directory as the GUI, so there's nothing extra to do for command-line captures.
What's different from Wireshark's own file
Wireshark's official manuf file pairs each OUI with two names: a short, hand-picked abbreviation (Cisco) and IEEE's full registered organization name (Cisco Systems, Inc). That abbreviation is curated by the Wireshark project by hand and isn't part of IEEE's public data, so our file uses the full registered name in both fields instead: you'll see CISCO SYSTEMS, INC. where Wireshark's own file would show Cisco. Longer, but unambiguous, and it's the same tradeoff every third-party OUI file makes.
The format itself matches Wireshark's spec, including how it represents blocks narrower than a /24: a /28 block prints as a full 6-byte prefix with a /28 suffix (for example D07AB50000/28) rather than being dropped, so nothing from the smaller MA-M, MA-S, IAB, or CID allocations gets lost the way it would in a strict 24-bit format.
Already have a capture, an arp -a dump, or a log file with MAC addresses in it and just want the vendors, once, without touching your Wireshark install? Paste it into the extract tool instead. Scripting vendor resolution into something else entirely? The free JSON API covers that.
More guides