ECU simulation for diagnostic-tool development · macOS and Linux
ECUmulator Studio
An ECU that answers the way you need it to.
ECUmulator emulates the diagnostic side of a vehicle: you describe ECUs and their responses in JSON, load the vehicle into Studio or the command-line runtime, and connect your tester over CAN, Ethernet or an ELM327-compatible link. Change a VIN, add a response, try another address — without having to find a car with exactly that configuration.
ECUmulator is currently in a pilot phase: it ships to early customers with direct support from the developer, and the combinations those customers need are the ones that get built and tested first. If you have a particular tester, ECU or protocol stack in mind, get in touch — chances are it is either covered or next on the bench.
At a glance
| Protocols | UDS, KWP2000, OBD-II — real service logic: identification values, live data, DTCs, security access, routines, custom responses |
| Transports | Classic ISO-TP, ISO-TP/FD, SAE TP2.0 |
| CAN bench (macOS) | gs_usb, TouCAN, Tactrix OpenPort, PEAK USB FD adapters |
| CAN bench (Linux) | SocketCAN |
| CAN health (1.5) | Controller state and available error counters, shown separately from received traffic; adapter and firmware capabilities remain explicit |
| Network | DoIP, BMW HSFZ, ECUconnect TCP, ENET Service Broker |
| Serial-style | ELM327/STN emulation over TCP for AT-command testers |
| Logging | CAN logger stream with Zeroconf discovery, CANcorder-compatible |
| Vehicle Scan (1.4) | Read connected vehicles over CAN, DoIP or BMW HSFZ into editable specs; automatic Ethernet discovery, Standard and Deep inspection |
| Spec import | CAN logs (candump, candump CSV, generic CAN CSV, CL1000, ECUconnect, PCAPNG — auto-detected) and ODX/PDX |
| Tooling | Studio desktop app, native ecum runtime and ecp remote-control client, JSON control API, manpages — no Python required |
| Platforms | macOS 26+ (Apple Silicon and Intel) shipping now; Linux and Windows in pilot, on request |
New in 1.5: see the CAN controller’s health
Enable Show advanced CAN information in External CAN settings to see the controller’s state in a compact badge, available error counters and a separate indication of received traffic. The setting is off by default and takes effect immediately. Supported adapters report error-active, error-warning, error-passive and bus-off states. The same information is available through the native runtime and ecp.
Status reporting depends on the adapter and its firmware. Older candleLight firmware may report only state changes, so the controller state can stay Unknown even after a frame arrives. A USB write does not prove a CAN acknowledgement, and past error counts remain visible instead of disappearing when the bus recovers. The manual explains those distinctions and how to check an idle bus, missing acknowledgements and termination.
This release also fixes reception when opening PEAK USB FD adapters on macOS.
Vehicle Scan: from a vehicle to a repeatable test
Connect a vehicle, choose New → Read from a vehicle, and turn its diagnostic answers into an editable simulation. Vehicle Scan supports CAN, DoIP and BMW HSFZ. For CAN, select your adapter; for Ethernet, select an interface or let Automatic search all active interfaces, preferring link-local connections. Vehicles appear as they answer — no gateway address to look up and no search button to keep pressing.
Standard inspection reads responding ECUs, identification values, supported OBD-II data and fault memory. Deep inspection searches additional manufacturer-specific identifiers. BMW ECU software numbers are decoded from F101 responses, while the original bytes remain available for emulation. Save the spec, inspect or change its values, and test against those answers without keeping the vehicle connected. A separate report records requests, responses and gaps; interrupted scans can keep their partial results.
The scan uses default diagnostic sessions and read requests. It does not clear faults, unlock security, write coding or run actuator tests. It captures what the vehicle exposes: sleeping or protected ECUs, security algorithms and dynamic behaviour still need attention. Deep scans can take hours.
Ethernet scans read several ECUs in parallel and adapt to their response times. CAN starts with one request at a time; you can increase parallelism for a bench that supports it. BMW and VAG identifiers receive meaningful names, and captured fault data retains its format and freeze-frame indexes.
Follow the user manual (PDF) from your first emulation through scanning, connecting a tester and retesting edits.
Model the vehicle in JSON
A vehicle can contain several ECUs, each with its own addresses and responses, and an ECU can carry more than one protocol handler — the included authoring demo answers both UDS and OBD-II on the same CAN address pair. Static values give you repeatable tests; sequences and time-based values make a display or logging application do a little more work.
The spec is the model. ECUmulator won’t guess a real ECU’s behaviour from its name, and a capture only tells you about the requests and responses it contains — the importers give you a starting point that you can inspect and extend, not a black box.
Documentation you can hold ECUmulator to
The bundled demo vehicles cover OBD-II with 11-bit and 29-bit addressing, UDS, KWP2000 over ISO-TP and TP2.0, BMW HSFZ, Audi DoIP, and a combined OBD-II/UDS ECU. The combined demo ships with an English user guide with a spec-authoring tutorial and annotated source files: 24 live OBD-II PIDs, 16 UDS identifiers and four Mode 09 values, with UDS and OBD-II reporting the same VIN. The authoring tutorial pairs diagnostic requests with expected replies, backed by runtime regression tests.
The guide also lives in Help → Documentation inside Studio, with a printable offline export.
Studio or a terminal
Studio provides the spec editor and service controls. The same installer includes the native ecum runtime and the ecp remote-control client with its terminal UI, plus manpages for both. Everything your CI needs runs headless; nothing needs a Python installation.
This starts the included authoring demo on the first matching gs_usb adapter, using Classic CAN at 500 kbit/s:
ecum --vehicle /usr/local/cansole/share/specs/motorrad/bmw-motorrad-vehicle.json --socketcan gs_usbAdapters can also be selected explicitly (down to USB IDs), and the same selectors work through the JSON control API, which Studio and ecp use and which announces itself via Zeroconf. The authoring guide documents both start modes with requests and expected replies.
Get the pilot build
Download ECUmulator Studio 1.5.967 for macOS
macOS 26 or later · Apple Silicon and Intel · signed and notarized installer
The package installs Studio, the command-line tools, manpages and the demo specs. Running Studio requires the license supplied with your pilot delivery; licenses are currently issued directly, there is no online checkout yet.
Linux builds are part of the pilot programme — contact me with your distribution and CAN adapter. Windows is available on request for pilot setups; the public offering concentrates on macOS and Linux for now.
Who builds this
ECUmulator is developed by Michael Lauer — the same developer as CANcorder, which sits on the other side of the wire when you want to inspect the traffic. Pilot customers talk directly to the person writing the software: feature requests, stubborn diagnostic traces and licensing all go through the same address.