Community reverse-engineering of the CAN bus on the Triumph Speed 400 / Scrambler 400 X (the Bajaj-built 398 cc platform). Raw capture data + a decode reference, so others don't have to start from scratch.
Unofficial and community-maintained. Not affiliated with or endorsed by Triumph. All sniffing here is listen-only (the node never transmits to the bus). Use at your own risk.
| property | value |
|---|---|
| bit rate | 500 kbit/s (confirmed) |
| identifiers | 11-bit standard |
| ECU | Bosch (shared Bajaj platform; closely related to the KTM 390 family) |
| active when | key on, even engine off — ~32 IDs broadcast at rest |
Because most of the bus is live with just the key on, a lot can be mapped without running the engine (brakes, switches, lights, wheels); rpm/throttle/gear/coolant need the engine running.
triumph-speed-400-can/
├── data/ raw CAN captures (CSV: ms,ID,dlc,byte0,…; one line per payload change)
├── docs/ decode.md — the signal / ID reference (what each frame means)
└── README.md
| file | conditions |
|---|---|
data/2026-07-11_baseline_key-on_engine-off.csv |
key on, engine off, stationary — the at-rest baseline |
data/2026-07-11_stimulus_engine-off.csv |
key on, engine off, deliberate inputs (brakes, clutch, gears, lights, switches) |
data/2026-07-11_ride_engine-running.csv |
engine running + a short ride (idle, revs, gear shifts, a mid-ride stall) |
Format: ms,ID,dlc,byte0,byte1,… — ms is the logger's uptime in
milliseconds, ID is the 11-bit identifier in hex, dlc the data length, then the
payload bytes in hex. One line is written only when a frame's payload changes,
so a steady frame appears once and a busy one appears on every change. (This keeps
the logs compact; it is not a full every-frame trace.)
Privacy: captures were scanned for VIN/serial before publishing — none of the periodic broadcast frames here carry identifying data.
See docs/decode.md for the current ID map and per-signal
decode (confidence-rated). Reverse-engineering is ongoing; contributions of new
captures and corrections are welcome.
An ESP32-S3 (Adafruit QT Py) with a listen-only TWAI/CAN front-end
(TWAI_MODE_LISTEN_ONLY — never ACKs or transmits) sniffing the bus, logging every
changed frame. See the parent project for firmware details.
blalor/ktm-can— KTM (Bosch ECU) CAN decode; the 400's map is related but offset.iDoka/awesome-automotive-can-id— collected CAN IDs across makes.
Add captures under data/ (same CSV format, note the conditions), or open an issue
with corrections to the decode. Please scrub any VIN/serial before sharing —
the periodic frames here don't contain it, but diagnostic/UDS responses can.
Data and documentation: CC BY 4.0. Attribution appreciated.