Thought I would share some progress I've made on poking around at Trimble Thunderbolt devices.
I've got a red-label Tbolt, S/N 12176159 DoM 03/12/2001. It has application 2.20 on it and one of the 37265 Trimble-branded OCXOs in it.
I've managed to extract the firmware from my unit non-destructively. I've attached the firmware dumps here, since they don't seem to be out in the wild anywhere I can find. One of them is a dump of the bootloader in the mask ROM of the main CPU, the other is a dump of the Am29F400 external flash chip. On the red-label Tbolts at least, the main CPU is a MC68330/MC68340 derivative with some custom hardware blocks onboard.
I noticed that Trimble released two similar products around this era, the Palisade and the Lassen. Both of these have firmware updates and flash tools available; looking at these tools showed a pretty similar pattern in how they were programmed - there's a TSIP packet (0x1E 0x54) that will cause the unit to jump to a ROM-monitor-like interface. The red-label Thunderbolt behaves like a Palisade device. It has a few commands which can read, write, and jump to arbitrary addresses. You can dump the flash, or upload a program that will erase and write to the onboard flash and jump to it - this is how the Palisade's flash tool works.
The command and monitor is similar on the Lassen, though it has a different CPU (another Trimble ASIC with an Epson C33 core) and a different TSIP packet to trigger it. I am curious whether the gold Thunderbolts have the Lassen-style CPU. From squinting at the markings in eBay photos... maybe? I don't have one to compare with, though. If anyone is willing to try the scripts below against a gold Thunderbolt, particularly one running firmware 3.0, I'd appreciate it.
These Python scripts will probe for both styles of bootloader, and dump the bootrom and flash from Palisade-style boards:
bootloader probe script -
https://gist.github.com/berg/186e46234e0d041dd7f693c3087e225edump script -
https://gist.github.com/berg/243c9912016051b8e378210af4f8259dThese run easily from `uv run` and take a pyserial-style name for the serial port.
Note that while I do not have any expectation that this will break your device, you do so at your own risk. You will need to reboot your device after/between running the scripts (this may be undesirable for you!)