Find out what a Modbus device actually exposes
Point the Scanner at a device and it finds the registers that answer, works out what the values look like, and builds a tag map you can take with you. It reads. It never writes.
Windows. Free for engineers — no account, no licence key.
What it does
Adaptive scanning
Quick, Balanced and Deep strategies narrow in on the ranges a device answers, instead of walking 65,536 addresses one at a time.
Register identification
Suggests data types and byte order from the values themselves, so a float split across two registers is recognisable.
Read-only by design
Function codes 01–04 and the read-only device identification. There is no write path in the tool.
Exports a tag map
io-tags.json, CSV and Excel, ready for the Polling Tool, the Gateway or your own documentation.
Background reading
What is a Modbus register?
Modbus exposes four separate tables of coils, discrete inputs, input registers and holding registers. What each one is, how wide it is, and why a value can span two of them.
Holding registers vs input registers
FC03 and FC04 look almost identical on the wire. What actually differs, why a device may implement both, and how to find out which one holds your value.
How to scan Modbus registers
Finding a device's real register map when the documentation is missing or wrong, without hammering the device or writing to it.
Moving from testing to production?
When the device is understood and the data needs to go somewhere continuously, Edge Gateway turns the same tag map into a deployed runtime.