ModbusBB 2.0 features
A Modbus master, simulator and command-line tool for Windows, grouped by what you're trying to do
Quick answer: ModbusBB 2.0 is a Windows Modbus master/client and slave simulator. It connects over Modbus TCP, RTU, ASCII, RTU-over-TCP and UDP, and you can run several connections at once, each with its own poll tabs. It decodes 11 data types in four byte orders and shows every raw TX/RX frame. Device Tools add FC08/17/22/23/43 and raw requests, and there is a built-in device register-map library. Trends, watchdog alerts, CSV logging and a scriptable CLI round it out.
Connections, transports & workspaces
Connect to as many devices and networks as you need at the same time. Each connection appears in the side tree, has its own settings and state, and holds any number of poll tabs.
- Five transports - Modbus TCP, Modbus UDP, RTU-over-TCP (for serial device servers), Modbus RTU and Modbus ASCII
- Full serial settings - COM port, 1200-230400 baud, 7 or 8 data bits, parity None/Odd/Even/Mark/Space, 1/1.5/2 stop bits
- Multiple connections - Add, rename and remove connections. Use Connect All / Disconnect All, and start or stop every poll at once
- Retries - Configurable timeout, retries per request (0-10, default 3) and retry delay
- Auto-reconnect with back-off - When a link drops, ModbusBB reconnects and resumes polling. You set the first delay, maximum delay, back-off factor and maximum attempts (0 = keep trying)
- Workspaces (.mbws) - One file holds every connection, poll, register setting and watchdog rule. Use New/Open/Save/Save As, the recent-files list, and auto-connect when a workspace opens
- Opens your 1.x files - Old connection profiles (.json/.mbprofile) and .mbcfg files load and convert automatically
- Built-in ping - Check that a device IP answers before you connect
Polls, data types & addressing
Each poll tab reads one block of coils or registers on a schedule. Every row can have its own name, format, byte order and scaling.
- Read/write function codes - FC01 coils, FC02 discrete inputs, FC03 holding registers, FC04 input registers, FC05/06 single writes and FC15/16 multiple writes
- Poll intervals from 100 ms to 1 hour - Start or stop each tab (F6), read once (F5), or start all polls together
- 11 data types - Unsigned/Signed 16-bit, Hex, Binary, Int32, UInt32, Float32, Int64, UInt64, Float64 and String
- Four byte orders - ABCD (big-endian), DCBA (little-endian), BADC (byte swap) and CDAB (word swap), for 32- and 64-bit values and strings. A Cycle Byte Order command tries each one
- Engineering values - Engineering value = raw × scale + offset, shown with its unit next to the raw value, hex and binary
- Address notation - 0-based (protocol), 1-based (register number) or Modicon (0xxxx/1xxxx/3xxxx/4xxxx), plus an optional hex address display
- Safe inline writes - Type into the Set Value column to write. Rows read with FC02 or FC04 are read-only, as are incomplete multi-register values and rows marked read-only in the register map
- Input validation - Unit ID, address, quantity, interval and write values are checked before anything is sent
Traffic monitor & communication log
See exactly which bytes went out and came back. That's the fastest way to tell a wiring problem from a wrong unit ID, address or byte order.
- Raw TX/RX frames in hex - Exact request bytes and the response bytes for every connection (MBAP, RTU with CRC, or ASCII), with timestamp, direction, connection and length
- Filter - By text (hex bytes, ASCII or connection name), by direction (TX/RX) and by connection
- Pause, copy, export - Freeze the view, copy selected frames, or export them to CSV or TXT. A row limit (default 5000) keeps memory bounded
- Communication log - Decoded transactions with response times and errors. Clear it or export it to a text file
- Error details - Modbus exception replies are shown by name (for example 02 Illegal Data Address), separate from timeouts and lost connections
Device Tools: diagnostics beyond read/write
Tools > Device Tools sends the less common function codes on any connection. You can set the unit ID, timeout and retries per request, and confirm writes before they go out.
- FC43 / MEI 14 Device Identification - Basic, regular, extended or individual objects (vendor, product code, revision, URL, model, and more). Multi-part replies are followed automatically. Copy or export the results to CSV
- FC17 Report Slave ID - Server ID, run indicator and additional data as hex and text
- FC08 Diagnostics - Echo test (sub-function 0) and other sub-functions
- FC22 Mask Write Register - AND/OR masks with a bit-by-bit preview and optional read-back
- FC23 Read/Write Multiple Registers - Write and read in one transaction. The write happens first
- Raw request - Any function code 1-127 plus data, or a full PDU. The transport adds the MBAP header or CRC/LRC. Exception replies are shown, and you can reuse requests from the history
Device register-map library
Tools > Device Library has register maps for nine common devices. Load one into the grid with names, formats, byte order, scaling and units, or export it as JSON or CSV.
- Energy meters - Eastron SDM120, Eastron SDM630, Schneider Electric PM5xxx, Carlo Gavazzi EM24
- Solar - SunSpec Common Model (ID 1), Growatt inverter (protocol V1.20), SMA inverter
- Drives - ABB ACS580, Schneider Electric Altivar
- Source and warning on every map - Each map names the document it was built from. Always check addresses, data types and scaling against your device manual, because maps differ between firmware versions and variants
- Also in the CLI -
library list,library show <id>andlibrary export <id> file.csv
Scans & connection statistics
Find devices and valid register ranges quickly, then measure how reliable the link really is.
- Slave scanner - Probes unit IDs 1-247 with live progress and cancel. A device that replies with a Modbus exception still counts as found
- Register scanner - Finds readable address ranges for a chosen function code
- Connection statistics (GUI) - For each connection: protocol, endpoint, state, retries, timeout, auto-reconnect, and OK/error counts for every poll
- Response and loss statistics (CLI) -
statssends N requests without retries. It reports valid responses, exception replies, timeouts, other errors and loss % (requests with no response at all), plus avg/min/median/p95/max response time - Connection state - Connected, Reconnecting and Connection lost are shown per connection, with the reason in the log
Modbus slave simulator
Tools > Modbus Simulator turns ModbusBB into a Modbus device, so you can test masters, HMIs, gateways and SCADA systems without hardware, including how they handle errors.
- TCP, UDP, RTU and ASCII - Listen on a TCP/UDP port or a COM port, with full baud, data bits, parity and stop-bit settings
- Multiple unit IDs - Each unit ID has its own coils, discrete inputs, holding and input registers
- Editable data - View and edit values in any format and byte order, with auto-refresh to watch what a master writes
- Value generators - Static, ramp, sine, random, counter and toggle, with min/max, period, step, format and byte order. Add demo set creates a ready-made example
- Exception injection - Answer matching requests (unit, function code, address range) with a chosen exception code
- Response delay and jitter - Test a master's timeout handling
- Request log - Every request with unit, function, address, quantity, result and delay
Live trend chart
Tools > Live Trends plots the values from the active poll tab over time.
- Multi-series - One line per register, which you can show or hide
- Zoom and pan - Mouse wheel zooms time, Ctrl+wheel zooms Y, drag to pan, draw a zoom box, double-click to reset
- History - Set the visible window (10 s to 1 h, or all), the points kept per series, and auto or manual Y range
- Sample interval - 0.1 s to 10 s, with pause, resume and clear
- Export - All buffered samples to CSV, or the chart as a PNG image
Watchdog alerts & actions
Rules check the decoded engineering value (format, byte order, scale and offset) of each polled sample, so thresholds use real units.
- Conditions - On change, greater than, less than, equals, not equals, inside range and outside range, with a tolerance
- Filters - By address, tag, connection, unit ID and function code
- Debounce and cooldown - Require N consecutive samples, set a minimum time between alerts, or fire only when the condition first becomes true
- Actions - Raise an alert, append a line to a CSV alert log, play a sound, or write a register or coil on the device
- Non-blocking - Alerts and actions run in the background and are listed in the Alerts tab, so polling never waits for a pop-up
CSV logging & register maps
Record evidence during commissioning and reuse your register documentation.
- Log the active tab to CSV - Timestamped rows while the poll runs, readable in Excel
- Export current data - Save the latest values of a tab to CSV
- Register maps - Import CSV or JSON with name, format, byte order, scale, offset, unit, min/max and read-only. You can also export the current map or create a template
- Hex and binary input - Enter addresses and values as decimal, 0x hex or 0b binary
Command-line tool for scripts and CI
ModbusBB.CLI.exe runs one-shot commands with the connection given inline, so you can use it from PowerShell, cmd, bash/WSL, scheduled tasks and test pipelines. Run it with no arguments for an interactive prompt.
- Commands - read, write, poll, scan, stats, devid, slaveid, diag, maskwrite, rw, raw, library, workspace run/show and simulate
- Same transports -
--tcp,--udp,--rtu-over-tcp,--rtu,--ascii, or a connection from a workspace with--profile - Machine-readable output -
--output table|json|csv. Poll and workspace runs write NDJSON (one JSON object per line) or one CSV row per sample - Hex trace -
--traceprints every TX/RX frame to stderr, and--dry-runshows a write or raw frame without sending it - Exit codes - 0 success, 1 runtime error, 2 usage error, 3 license error, 130 interrupted
- Scripting - Chain commands in a script and check the exit code after each one. There is no built-in batch file format, because your shell already does that job
Licensing & updates
A one-time $10 license covers GUI and CLI on up to three PCs.
- 3 device activations - Each PC is checked online against your key
- Self-service portal - See and deactivate devices to free a slot
- Offline use - Works for up to 30 days between online license checks
- 1.x keys work in 2.0 - Install over the old version. The stored key is found and re-activated on that PC (it needs internet once)
- Update check - At most once a day at startup. Update links only open the official HTTPS download page, and each release lists SHA-256 checksums on the download page
- Free trial - 30 days, all features, 15 minutes per session
Features FAQ
Can ModbusBB poll several devices at the same time?
Yes. Add one connection per device or network, and add poll tabs under each connection. All polls can run at the same time, each with its own interval from 100 ms to 1 hour.
Does ModbusBB show the raw Modbus frames?
Yes. The Traffic tab (View > Traffic Monitor) lists every transmitted and received frame in hex, with timestamp, direction, connection and length. You can filter, pause, copy and export it to CSV or TXT. In the CLI, add --trace to print the frames to stderr.
Does ModbusBB measure packet loss?
The CLI stats command does. It sends a set number of requests without retries and reports valid responses, exception replies, timeouts, other errors and loss % (requests with no response at all), plus response-time statistics. The GUI's Connection Statistics shows each connection's state and settings and the OK/error count of every poll.
Are the device library maps guaranteed to match my device?
No. Each map lists the public document it was built from, but register maps can differ between models, firmware versions and variants. Always check addresses, data types and scaling against your device manual before relying on them.
Can the simulator return Modbus exceptions?
Yes. In the simulator's Exceptions tab, rules answer matching requests with an exception code you choose. A rule can match a unit ID, a function code and an address range. You can also add a fixed response delay and random jitter to test timeouts.
Ready to try ModbusBB 2.0?
Download the free trial: 30 days with 15 minutes per session.