PowerShell module

macadress.com for PowerShell.

A PowerShell client for the MAC address and OUI vendor lookup API: vendor name, IEEE block, country, address type, EUI-64 / IPv6 derivation, randomization confidence and a device guess. Pipeline-friendly cmdlets, no dependencies, Windows PowerShell 5.1 and PowerShell 7+.

On the PowerShell Gallery: Macadress. Windows PowerShell 5.1 or PowerShell 7+, MIT licensed, no external modules. Source at github.com/sapisos/macadress-powershell.

Install

Install-Module Macadress -Scope CurrentUser

Look up a vendor

The name-only lookup needs no API key:

Get-MacVendor "00:03:93:AB:12:34"   # "Apple, Inc."
Get-MacVendor "02:1a:2b:3c:4d:5e"   # $null (unregistered, private, or randomized)

# it takes the pipeline, so this works too
Get-NetAdapter | Select-Object -ExpandProperty MacAddress | Get-MacVendor

Full analysis

Everything else needs a free API key. Set it once for the session, then call Resolve-MacAddress:

Set-MacadressConfiguration -ApiKey "mk_live_xxx"   # or $env:MACADRESS_API_KEY

$r = Resolve-MacAddress "3C:22:FB:12:34:56"

$r.organization                # "Apple, Inc." | $null
$r.country                     # "US" | $null
$r.block_type                  # "MA-L" | $null
$r.potentially_randomized      # bool
$r.randomization_confidence    # "none" | "possible" | "likely"
$r.eui64                       # "3E:22:FB:FF:FE:12:34:56" | $null
$r.explanation                 # plain-English summary

# anything without a named property is still on the object
Resolve-MacAddress "3C:22:FB:12:34:56" -Raw | ConvertTo-Json -Depth 10

Batch and directory search

Resolve-MacAddress batches automatically: pass it two or more addresses, or pipe them in, and it sends one POST /v1/mac/batch per 100.

Get-Content .\macs.txt | Resolve-MacAddress |
    Select-Object input, organization, country |
    Export-Csv .\vendors.csv -NoTypeInformation

Find-MacVendor -Query "Cisco" -Country US -Limit 20 |
    Select-Object assignment, block_type, organization, country

Extract from text

Feed Get-MacAddressFromText an arp -a dump, a lease file, or any log, and it pulls out every MAC-shaped string and resolves each one:

arp -a | Out-String | Get-MacAddressFromText |
    Select-Object input, organization, country

Errors

Failures are terminating errors. The exception carries the HTTP status, the API request id and the raw body in .Data: 400 invalid input, 401 missing or invalid key, 429 rate limit or quota. Get-MacVendor returns $null (not an error) for a valid address with no vendor.

try {
    Resolve-MacAddress $value
}
catch {
    $_.Exception.Data["StatusCode"]    # 400
    $_.Exception.Data["RequestId"]
    $_.Exception.Data["ResponseBody"]
}

Quota

Each Resolve-MacAddress address, Get-MacAddressFromText address, and Find-MacVendor call is one API call against your plan, the same as a direct REST call: see pricing. The keyless Get-MacVendor endpoint is free for 1,000 lookups a day per IP; passing a key lifts that to your plan quota.

Links