The Investigation Insights – WireShark OUI integration allows you to look up MAC addresses against the OUI (Organizationally Unique Identifier) information from the WireShark OUI database. The returned information includes the short name and vendor information for the given OUI. The OUI is the first three octets of a MAC address and is used to identify the manufacturer of a network device.
Examples
Wireshark OUI Data Overview
- Vendor Name: When looking up a MAC address, analysts will be able to quickly tell what vendor is associated with that MAC address. Enabling quick triage on what a tool might be in an analyst’s environment.
