What a MAC address is
A MAC address is the hardware address of a network interface: six bytes, or 48 bits, usually shown as twelve hex digits. It identifies a device on a local network, where an IP address identifies it on the internet. Every network card, Wi-Fi radio and virtual adapter has one.
The same six bytes are written in three notations. Windows and many tools use hyphens
(00-1A-2B-3C-4D-5E); Unix, Linux and most documentation use colons
(00:1a:2b:3c:4d:5e); Cisco equipment groups the bytes in threes separated by dots
(001a.2b3c.4d5e). All three describe the identical address, which is why a viewer that
normalises them to one form is useful when a log mixes sources.
The first three bytes are the OUI, an identifier assigned to the hardware vendor; the last three are assigned by that vendor to the individual device.
How to extract MAC addresses from text
- Paste your text. ARP tables, DHCP leases, switch and router output, packet-capture summaries, syslog — anything with hardware addresses in it.
- Choose the output format. Pick colon, hyphen, Cisco dotted or bare. Every address found is rewritten to that single format, so a file mixing all three styles comes out consistent.
- Click Extract. The three notations are matched, then anything sitting inside a longer hex string is discarded, so a MAC is not cut out of the middle of a token.
- Copy or download. Copy the plain list, or download a .csv carrying the address, its cast, its administration and the OUI (the first three bytes, which identify the vendor).
What comes out
- Every MAC address in colon, hyphen or Cisco dotted notation, rewritten to the single output format you choose.
- Unicast or multicast, read from the lowest bit of the first byte — a multicast address is a group, not a single device.
- Universal or locally administered, read from the second bit — a locally administered address was randomised, virtualised or set by hand rather than assigned to real hardware, which is exactly what a phone doing MAC randomisation looks like.
- The OUI, the first three bytes, which identify the vendor.
- Counts of multicast and locally administered addresses, and a CSV export carrying every column.
What is supported, and what is not
Matched: the colon form, the hyphen form and the Cisco dotted-quad form, in upper or lower case. Every match is validated as exactly six bytes and then boundary-checked: an address touching another hex digit or separator on either side is rejected, so a MAC is never sliced out of the middle of a longer hex token such as a hash or a serial number.
Not done: vendor lookup. The OUI is shown, but it is not resolved to a company name. Resolving it means either shipping a large database or, far worse, sending your addresses to an online OUI service — which would defeat the point of extracting them privately. Look the OUI up yourself against the IEEE registry if you need the vendor.
Not matched: EUI-64 (64-bit) addresses, and the MAC portion embedded inside an IPv6 link-local address, which needs un-flipping first. Bare twelve-digit hex with no separators is not matched either, because at that point it is indistinguishable from any other 48-bit hex value.
Why the log never leaves your device
Matching runs as JavaScript in your browser. Nothing you paste is transmitted. For the full explanation of how browser-based processing works, see the security page.
Network logs are sensitive in their own right. A MAC address is a stable device identifier — it can track a specific laptop or phone across a network — and it usually appears next to IP addresses, hostnames and usernames in the same log line. Extracting locally means none of that surrounding context is disclosed to anyone.
What this tool does not do
This tool finds, normalises and classifies addresses. It deliberately does not:
- Look up the vendor. The OUI is shown; resolving it to a company would need a database or a third-party request.
- Resolve to a device. It does not tell you which machine an address belongs to.
- Match bare unseparated hex. Twelve hex digits with no colons, hyphens or dots are not treated as a MAC, because they are indistinguishable from any other hex value.
- Un-flip IPv6 interface identifiers. A MAC hidden inside an EUI-64 or a link-local address is not recovered.
Who extracts MAC addresses
- Network administrators — pulling the unique hardware addresses out of an ARP table or a set of DHCP leases to build an inventory.
- Security work — collecting the addresses seen on a segment during an incident to spot rogue or unexpected devices.
- Switch and Wi-Fi audits — extracting every address from port or association output to reconcile against an asset list.
- Access-control lists — gathering addresses to allow or block, normalised to the format the firewall expects.
- Troubleshooting — finding whether MAC randomisation is in play, which the locally-administered flag reveals.
MAC addresses compared with IP addresses and other identifiers
A MAC address identifies a device on the local network and normally never changes; an IP address identifies it on the internet and is often reassigned. They appear side by side in ARP tables, DHCP leases and firewall logs, which is why the two extractors pair up. To pull the IP addresses out of the same log, use the IP address extractor.
For the hashes and UUIDs that show up in the same operational data, use the hash extractor and the UUID extractor. For any other pattern, the regex extractor lets you write your own and runs it safely in your browser.
Frequently asked questions
How do I extract all MAC addresses from a log?
Paste the log above and click Extract. Every address in colon, hyphen or Cisco form is listed, rewritten to one format, deduplicated and classified.
Does it handle Cisco dotted MAC addresses?
Yes. The Cisco form 001a.2b3c.4d5e is matched alongside the colon and hyphen forms, and all three are normalised to whichever output format you choose.
Can it tell me the vendor of a MAC address?
It shows the OUI — the first three bytes, which identify the vendor — but it does not resolve that to a company name. Doing so would need a database or a request to a third-party service, which would send your addresses off your device.
What does 'locally administered' mean?
The second bit of the first byte is set, meaning the address was assigned by software rather than burned into hardware. Randomised phone Wi-Fi, virtual machines and hand-set addresses all show up this way.
Is my log uploaded to a server?
No. Matching runs entirely in your browser. Nothing you paste is transmitted, which matters because MAC addresses are stable device identifiers usually logged next to IPs and usernames.
Why is a 12-character hex string not matched?
Bare hex with no colons, hyphens or dots is indistinguishable from any other 48-bit value, so it is not treated as a MAC on purpose. Add separators if it really is an address.
What is the difference between unicast and multicast here?
The lowest bit of the first byte. Unicast addresses one device; multicast addresses a group. The tool labels each and can filter to unicast only.