$0.00
0

Cart

Flipper Add-On: Modbus

Sniff and inject Modbus RTU packets on industrial networks you're authorized to test — straight from your Flipper Zero's RS485 Modbus add-on.

$20.00

In stock

In the box

Flipper Add-On Modbus board only

Not included

The Flipper Zero itself is not included — board only, nothing else ships in the box.

You also need

A Flipper Zero (sold separately), and qFlipper, Flipper Lab, or the Flipper mobile app to install the free companion .fap app.

What Is the Flipper Zero RS485 Modbus Add-On?

The Flipper Zero RS485 Modbus Add-On is a hardware board plus a companion Flipper app (flipper-rs485modbus) that lets you sniff and inject packets on Modbus RTU industrial networks. Electronic Cats frames it for authorized security testing, aimed at researchers auditing industrial Modbus networks they are authorized to test, since Modbus RTU has no built-in authentication or encryption. The board runs on the official Flipper Zero firmware (keep it on the latest version; custom firmware such as Unleashed is no longer required) and installs like any other Flipper app: download the .fap file from GitHub and load it through the File Manager, no compiling required. From the Main Menu you can open Settings, Sniffer, Sender, Read LOG, or About to build and send Modbus requests and see how a peripheral responds.

Manually Test How a Modbus Peripheral Responds

Want to test how a Modbus peripheral responds to a specific command? Open the Sender menu and build a request packet by hand — peripheral ID, function code, start address, and any extra fields — or replay one from the buffer of recently-sniffed requests, then send it as Master. The peripheral’s response (function, ID, byte count, register values) shows up in the output console, and the same flow lets you inject or tamper with data on the bus. It’s built for security researchers auditing Modbus networks they are authorized to test — Modbus RTU has no built-in authentication or encryption, so this shows exactly what an unauthenticated device on the bus can do.

Listen to a Modbus RTU bus without touching it

Situation: you need to see what actually travels on an industrial Modbus RTU bus you are authorized to inspect. What you do: attach the RS485 Modbus Add-On to the Flipper Zero, open the app’s Sniffer and let it listen on the RS-485 line without transmitting anything. Result: the traffic is captured and available in Read LOG for inspection, with no interference on the bus — Modbus RTU has no authentication or encryption, so this is also the quickest way to show what an attacker on the wire would see.

Start in 10 minutes

  1. Go to the GitHub repository’s release section and download the latest .fap file.
  2. Connect your Flipper to qFlipper, Flipper Lab, or the Flipper mobile app (if Experimental Options are enabled).
  3. Using the File Manager, navigate to the Apps folder.
  4. Upload the .fap file to the Apps folder (any subfolder is fine, e.g. “Misc”); the app then appears in the Flipper’s app list.
Weight0.02 g
Dimensions18.5 × 12.5 × 1 cm
Interface / protocol

RS-485 physical layer, Modbus RTU protocol

Flipper firmware

Official Flipper Zero firmware, latest version (Unleashed no longer required), Custom firmware with the same API version as the compiled app also works

Firmware license

MIT License

Hardware license

CERN-OHL

Firmware version

v1.1.3.4 (published 2026-01-02)

First released

v1.1.0.0, April 2024

I need a case for my board.
3D-printable STL case files are provided in the repo’s case/ folder — currently for the Marauder, SubGHz, and MagSpoof add-ons. There isn’t one for the RS485 Modbus board yet.
Contact the Electronic Cats Support Team through the Contact Us page at electroniccats.com/contact/.