generated: '2026-08-28' method: searched source: > https://macadress.com/extensions plus registry metadata from splunkbase.splunk.com/api/v1/app/9581, api.github.com/repos/MISP/misp-modules and pypi.org/pypi/misp-modules/json note: > There is NO first-party client SDK for this API, in any language, and the provider says so on purpose: the docs open with "Three endpoints, plain JSON, no SDK required." Registry sweeps for a "macadress" package on npm, PyPI, RubyGems and crates.io all miss. What the provider does ship is integrations for the tools its buyers already run — a Splunk add-on, a MISP enrichment module, and an iTop/TeemIp extension — plus a licensed .deb of the server itself. No SDKs pointer is emitted in apis.yml, because these are host-application plugins, not client libraries, and crediting them as SDKs would misdescribe the surface. sdk_count: 0 package_count: 4 packages: - name: TA-macadress title: Macaddress vendor lookup kind: splunk-add-on official: true registry: splunkbase registry_url: https://splunkbase.splunk.com/app/9581 app_uid: 9581 version: 1.0.0 published: '2026-08-23' last_updated: '2026-08-23' license: Apache-2.0 language: Python install: 'Splunk Web -> Apps -> Manage Apps -> Install app from file (.spl), or install from Splunkbase' cloud_compatible: true fips_compatibility: false fedramp_validation: 'no' download_count_at_capture: 3 provides: 'A macaddresslookup custom streaming search command.' docs: https://macadress.com/extensions/splunk credential_handling: 'API key stored through Splunk''s encrypted storage/passwords endpoint, never written to a plain-text .conf file.' currency_note: > Published 2026-08-23 at 1.0.0 and last updated 2026-08-23, five days before this capture. Brand new rather than abandoned; the download count of 3 reflects a launch-week listing, not decay. - name: macadress_com kind: misp-expansion-module official: true registry: none (ships inside the misp-modules project) upstream_repo: https://github.com/MISP/misp-modules upstream_file: misp_modules/modules/expansion/macadress_com.py merged_pr: https://github.com/MISP/misp-modules/pull/804 merged_at: '2026-08-24' version: null published: null license: Apache-2.0 attribute_type: mac-address docs: https://macadress.com/extensions/misp currency_note: > version is null on purpose and it is a real finding, not a gap in our probe. The module was merged into MISP/misp-modules main on 2026-08-24 and is present in the repository today, but the newest published misp-modules release is 3.0.9 (PyPI, 2026-07-13) which predates the merge. So the module is NOT yet in any released version — the provider's own page says it is "shipping in the next misp-modules release" and that users must run misp-modules from git in the meantime. A consumer installing from PyPI today will not get it. containing_package: registry: pypi name: misp-modules version: 3.0.9 published: '2026-07-13' contains_macadress_module: false - name: macadress TeemIp/iTop extension kind: itop-teemip-extension official: true registry: none declared_url: https://github.com/samymassoud/macadress/tree/main/plugins/teemip version: null published: null status: unreachable docs: https://macadress.com/extensions currency_note: > DEAD LINK ON THE PROVIDER'S OWN SITE. Both https://github.com/samymassoud/macadress and the deeper /tree/main/plugins/teemip path return HTTP 404 (probed 2026-08-28), and the account samymassoud has no repository by that name in its public listing. The /extensions page and the /extensions/splunk page both link into that repository, so the source-code link behind two shipped integrations currently resolves to nothing. Nothing was saved and no version could be read because the artifact is not retrievable. - name: macadress self-hosted API + IEEE sync engine kind: server-binary official: true registry: none (commercial licence) distribution: .deb package version: null published: null docs: https://macadress.com/pricing license: commercial, starting at $999/year per deployment currency_note: > Licence-gated: the two binaries behind every lookup, distributed as a .deb to run on the customer's own infrastructure. No public registry, no public version number, so version is null after checking rather than unchecked. registries_searched: - registry: npm query: macadress result: no first-party package - registry: pypi query: macadress result: 404 Not Found - registry: rubygems query: macadress result: not found - registry: crates.io query: macadress result: 0 crates - registry: splunkbase query: app 9581 result: hit - registry: pypi query: misp-modules result: 'hit (3.0.9, 2026-07-13) — contains the module on main but not in the released version'