Skip to content

Latest commit

 

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

triumph-speed-400-can

Community reverse-engineering of the CAN bus on the Triumph Speed 400 / Scrambler 400 X (the Bajaj-built 398 cc platform). Raw capture data + a decode reference, so others don't have to start from scratch.

Unofficial and community-maintained. Not affiliated with or endorsed by Triumph. All sniffing here is listen-only (the node never transmits to the bus). Use at your own risk.

Bus facts (measured)

property value
bit rate 500 kbit/s (confirmed)
identifiers 11-bit standard
ECU Bosch (shared Bajaj platform; closely related to the KTM 390 family)
active when key on, even engine off — ~32 IDs broadcast at rest

Because most of the bus is live with just the key on, a lot can be mapped without running the engine (brakes, switches, lights, wheels); rpm/throttle/gear/coolant need the engine running.

Repository layout

triumph-speed-400-can/
├── data/     raw CAN captures (CSV: ms,ID,dlc,byte0,…; one line per payload change)
├── docs/     decode.md — the signal / ID reference (what each frame means)
└── README.md

Data captures

file conditions
data/2026-07-11_baseline_key-on_engine-off.csv key on, engine off, stationary — the at-rest baseline
data/2026-07-11_stimulus_engine-off.csv key on, engine off, deliberate inputs (brakes, clutch, gears, lights, switches)
data/2026-07-11_ride_engine-running.csv engine running + a short ride (idle, revs, gear shifts, a mid-ride stall)

Format: ms,ID,dlc,byte0,byte1,… — ms is the logger's uptime in milliseconds, ID is the 11-bit identifier in hex, dlc the data length, then the payload bytes in hex. One line is written only when a frame's payload changes, so a steady frame appears once and a busy one appears on every change. (This keeps the logs compact; it is not a full every-frame trace.)

Privacy: captures were scanned for VIN/serial before publishing — none of the periodic broadcast frames here carry identifying data.

Decode status

See docs/decode.md for the current ID map and per-signal decode (confidence-rated). Reverse-engineering is ongoing; contributions of new captures and corrections are welcome.

How the data was captured

An ESP32-S3 (Adafruit QT Py) with a listen-only TWAI/CAN front-end (TWAI_MODE_LISTEN_ONLY — never ACKs or transmits) sniffing the bus, logging every changed frame. See the parent project for firmware details.

Related work / references

Contributing

Add captures under data/ (same CSV format, note the conditions), or open an issue with corrections to the decode. Please scrub any VIN/serial before sharing — the periodic frames here don't contain it, but diagnostic/UDS responses can.

License

Data and documentation: CC BY 4.0. Attribution appreciated.

About

CAN info for the Triumph Speed 400

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors