Author Topic: LeCroy Probus reverse engineering  (Read 31551 times)

0 Members and 4 Guests are viewing this topic.

Offline ollopaTopic starter

  • Regular Contributor
  • *
  • Posts: 149
  • Country: 00
Re: LeCroy Probus reverse engineering
« Reply #50 on: April 13, 2025, 03:46:33 am »
That's awesome!  Are you willing to share the design?
 

Offline heize0

  • Contributor
  • Posts: 39
  • Country: cn
Re: LeCroy Probus reverse engineering
« Reply #51 on: April 13, 2025, 04:40:17 am »
Yes. I wish it can help.
Tek TCP202 current probe isn't sensitive to the +-15V supply voltage, so I used the +-12V suplly rails on the Probus directily and it works well.
 
The following users thanked this post: Someone, Martin72, taras309

Offline heize0

  • Contributor
  • Posts: 39
  • Country: cn
Re: LeCroy Probus reverse engineering
« Reply #52 on: April 13, 2025, 04:52:04 am »
I use the easyEDA to do the design. I found it's a little weird after conversion. So I attached the Gerber files.
 
The following users thanked this post: Martin72, zhongzuocheng520, taras309

Offline dmderev

  • Contributor
  • Posts: 39
Re: LeCroy Probus reverse engineering
« Reply #53 on: April 13, 2025, 06:37:00 am »
Hi, for those interested, I am attaching the results of reverse engineering of HFP2500 probe and the protocol on I2C it is using. The contents of EEPROM is published on this forum somewhere.
One interesting thing - this probe has RGB LED that turns on the color matching that of the trace on the screen. However, I did not reverse engineer how exactly the LEDs are connected. I guess that there is some transcoding in PIC firmware. But if someone can suggest a simpler circuit that converts the bits as they are sent by the scope to 3 LED wires, it will be great. The codes are in attachment...
 
The following users thanked this post: tv84, bson, Martin72, zhongzuocheng520, eeglow

Offline zhongzuocheng520

  • Contributor
  • Posts: 23
  • Country: cn
Re: LeCroy Probus reverse engineering
« Reply #54 on: April 26, 2025, 07:35:41 am »
NB啊!兄弟 :-+ :-+ :-+ :-+
 

Offline eeglow

  • Newbie
  • Posts: 4
  • Country: us
Re: LeCroy Probus reverse engineering
« Reply #55 on: January 18, 2026, 01:14:02 am »
Thanks for posting this.

For those interested the transistors are probably (both obsolete):
N0 NXP BFR505
N2 NXP BFS520

In addition, on your schematic, it may be that R11 connects to -5V and not 0V.  This would match the BFR505's larger VCEO spec. 

Either that, or this thing must do some really weird DC offsetting on both sides of the probe/scope to meet the +/-8V FS input range, and +/-20V with offset.

This is a great analysis of how to build relatively simple probes with great specs.  I doubt that all the parts together on that probe board cost $1.  Ideally we would all be given active probes with new scopes.

Another similar circuit is found in another thread with this Rigol schematic, though not as high bandwidth.  http://rigol.codenaschen.de/images/0/0c/DS1052E_HW58_PCB_Schematics_-_Ch1_analog_front-end.jpg

This thread has some good discussion as well https://www.eevblog.com/forum/projects/biasing-of-jfet-and-npn-transistor-for-bandwidth/







 

Online SiliconWizard

  • Super Contributor
  • ***
  • Posts: 17799
  • Country: fr
Re: LeCroy Probus reverse engineering
« Reply #56 on: January 18, 2026, 01:26:08 am »
That's cool, I have a couple 1 GHz LeCroy active probes and would like to be able to use them on other scopes. I'll look into that.
 

Offline eeglow

  • Newbie
  • Posts: 4
  • Country: us
Re: LeCroy Probus reverse engineering
« Reply #57 on: February 04, 2026, 04:47:19 am »
An interesting device to EXTRACT and understand is the  CA10 Current Sensor Adapter.

I have never seen one, but its certainly a great target for eeprom and schematic dump..... 

https://www.eenewseurope.com/en/probe-adapters-simplify-interfacing-teledyne-lecroy-scopes/

"A simple interface provides a user with the ability to program the CA10 to contain the specifications of the current measurement device so as to automatically correct for the gain or attenuation and display results in Ampere units."
 

Offline Kampfkuchen

  • Newbie
  • Posts: 5
  • Country: de
Re: LeCroy Probus reverse engineering
« Reply #58 on: March 29, 2026, 11:04:53 pm »
Unfortunatelly the CA10 occurs heavy errors. 4 scopes just crashes and restarts the software.

And the CA10 is way more stupid than it appears. Have a look to the manual: https://cdn.teledynelecroy.com/files/manuals/ca10-user-manual.pdf
Everything is passive and the bandwidth is fixed by capacitors and inductors. First thought was, that this would be configurable through the menu - but you just tell the scope what you soldered.


But I have something to share:
We (me and two other guys) are working at the moment on a device for diy custom probes. My part is the EEPROM and software for configuration. The idea came from this thread and it was a very nice starting point to understand the code.
The whole project would be available at github (but at the moment, it is too messy to share and we want to have a usable release before publishing it).

I almost decoded nearly every register of the EEPROMs and would share the full investigations also in the GitHub project.

Important: Even if you know what every register does, it seems that you can't use the cool ones with a custom probe name. Very unfortunate.
But if you don't mind, use a known model, calculate the values and you are free to choose the coupling, attenuation, range, unit and some more.

I'm 99% sure to know how the coupling registers work (36, 38, 39 and 40 - but 39 seems to be a fallback for very old scopes). It is not that easy to describe, the logic is a bit more complicated.

(0x15) -> this byte is "Ω", \n is LF.
36 and 40 is the real configuration, 38 names the coupling
If 36 or 40 is "01" or "03" 38 becomes very relevant: "DC 1M(0x15)\n" -> DC 1MΩ, "AC 1M(0x15)\n" -> AC 1MΩ - nothing else will work and ends in GND coupling, also DC 50Ω is not possible.
If 36 is not 01 or 03, then 40 does the coupling configuration. 00 = DC 50Ω, 02 = DC 1MΩ, 04 = AC 1MΩ and 38 is the naming (shown in the coupling menu).
I'm not really sure, what happens if 36 or 40 isn't present - not tested at the moment.
In my tests 39 never does anything.

If you want more than one coupling, you just write them behind each other.
Like this:
36 02 04
40 02 04
38 "DC 1M(0x15)\nAC 1M(0x15)\n"
Important: Every name in 38 has to end with an LF. It will end in GND coupling, if you don't have the same amount of configurations. Also it is NOT possible to mix up 50Ω with 1MΩ - it ends in GND coupling for the DC 50 section.
I tested this with 5 couplings, worked. But yeah, how the heck do you want 5 times the same coupling...
If the scope knows the name, it shows a correlating symbol. Sometimes I saw a black one, sometimes I saw a yellow one - not sure what it depends on.
Optical coupling is also possible, with a laser as symbol - but seems to come from the probe-model and not the coupling register (OE6250G f.e.). Coupling is DC1M then.

Other registers I decoded:
03 version (the probe wasn't detected correctly after writing something into it)
14 is a register for the IO expander adresses, I guess. Changing them changed the I2C communication, while switching attenuations.
15 is for limiting the V/div value. I didn't investigate exact how it works, but it is a single-precision float and seems to work as a factor for the whole range or something. If you put 0.5 in this register, would half the maximum V/div range.
18 is the unit in ASCII - only W or A seems to work.
22 seems to be the measurement range. Also float32, BUT more than one. Mostly I saw positive and negative measurement range. If you have more than one attenuation, the range doubles the float values. Something like "150 -150 1500 -1500"
79 is also stuff for the IO expander, same as 14 but different situations -> not really investigated at the moment

This are only the registers I am mostly sure what they do (did not mention 01, 03, 04, 11, 41, 62 because they are well described before).

I think 14 and 79 are not so hard to decode anymore, but I want to find out how some probes tells the scope a manual changeable attenuation, because this would be very useful for our project - but at the moment, I think this isn't part of the EEPROM content.
I tried to find the configuration inside the scope - I think there has to be a database for each model... But can't find anything at the moment. If we manage to manipulate the database, or add own probes - this would be the holy grail for this project.
05, 21, 2A, 80, 81 are a secret to me.

Aside from that, I'm totally lost what tells the scope the maximum bandwidth. Some probes don't allow 200MHz (it's greyed out), but wasn't able to erase this. Maybe it is the probe-name.

We have differential probes with a switch for 100:1 or 1000:1, with fixed attenuation in the scope, it could be pain in the arse to work with. The HVDxxxx switches the attenuation with an IO expander through I2C, we thought about a electro mechanic switch, lol.
But one probe has a manual attenuation field, but in dB.

My goal at the end is a python script where you can configure your fixed probe and write it to an EEPROM.
The goal of the whole project is to have an device you can plug in to the scope, plug in the probe through BNC and get power supply (5V, 9V or 12V).

I hope this is interesting for somebody.


« Last Edit: March 29, 2026, 11:10:36 pm by Kampfkuchen »
 

Offline ollopaTopic starter

  • Regular Contributor
  • *
  • Posts: 149
  • Country: 00
Re: LeCroy Probus reverse engineering
« Reply #59 on: March 30, 2026, 12:30:37 am »
Yes the list of probes is hard-coded into firmware.  Many of the probes have fixed parameters and don't obey changes in the EEPROM parameters, and you can't just make up a new probe that isn't in the hard-coded list.

The best approach is to emulate existing probes that do have variable parameters.

Edit:  The probe manager is a registered COM dll (off the top of my head, there are three or four probe related DLLs).  These are not encrypted, we should work on decompiling and reimplementing them to see what options are available for extension with custom DLLs.  LeCroy firmware is generally very well architected in terms of modularity and extensibility, hopefully it's possible to extend the existing interface.
« Last Edit: March 30, 2026, 12:37:09 am by ollopa »
 

Offline Kampfkuchen

  • Newbie
  • Posts: 5
  • Country: de
Re: LeCroy Probus reverse engineering
« Reply #60 on: March 30, 2026, 09:45:03 pm »
You're right - I checked it today and found many .dlls and a .tlb with correlating names (currentprobesmgr, passiveprobes...).

My problem is, I don't know this stuff at all. Never does anything with .dlls, COM-stuff or TLBs. So it is really not part of my knowledge and mostly I'm just search around without a structure.

A bit research offers some interesting possibilities for doing own probes. This is a good starting point: https://cdn.teledynelecroy.com/files/manuals/we-automation-manual-e.pdf
Also it could be possible through XDEV tools from Teledyne.

I will focus on the EEPROM probe configuration part. Maybe somebody with more knowledge about the topic above can bring some insights.

Does anyone have an idea how hard Teledyne would be annoyed of by the reverse engineering of their probes?


 

Offline taras309

  • Contributor
  • Posts: 11
  • Country: ua
Re: LeCroy Probus reverse engineering
« Reply #61 on: May 28, 2026, 06:07:31 am »
Yes. I wish it can help.
Tek TCP202 current probe isn't sensitive to the +-15V supply voltage, so I used the +-12V suplly rails on the Probus directily and it works well.

Hello heize0,

Thank you so much for sharing the design and Gerber files for the TCP202 to Probus adapter! It is exactly what I need, and it's great to know that using the direct +/-12V supply rails works perfectly for this probe.

I have a somewhat strange request regarding the manufacturing. I am trying to order these boards from JLCPCB, and I would really like to get them with a gold finish (ENIG) for a reliable connection. However, JLCPCB currently has a very specific pricing quirk: a 4-layer board with ENIG costs around $50+, whereas 6-layer and 8-layer HDI boards have ENIG included by default and cost only about $2 under their special promotional offer.

I actually tried to modify the Gerber files to add the extra layers myself, but unfortunately, I couldn't get it to work since I have very little experience with PCB CAD software.

Would it be possible for you to modify the source project and export an 8-layer (or 6-layer) version? The extra internal layers could simply be filled with solid GND copper pours and stitched with vias to pass the factory audit.

This modification would be a massive help and would allow anyone wishing to get high-quality ENIG boards to order them for just a couple of bucks.

Thanks again for your excellent work and contribution to the community!

Best regards,
Taras
 

Offline heize0

  • Contributor
  • Posts: 39
  • Country: cn
Re: LeCroy Probus reverse engineering
« Reply #62 on: May 30, 2026, 01:41:34 am »
You are welcome.
I ahve modified it to be a 6-layer board and a 2-layer board.
 
The following users thanked this post: taras309

Offline taras309

  • Contributor
  • Posts: 11
  • Country: ua
Re: LeCroy Probus reverse engineering
« Reply #63 on: June 02, 2026, 10:34:39 pm »
Hi heize0,

Thank you so much for the quick response, and for taking the time to create and share the 6-layer and 2-layer versions!

I have just placed my order on JLCPCB, and I am really looking forward to receiving the gold-plated (ENIG) 6-layer boards.

I have one quick question about the assembly, though: could you please clarify what exactly you used to create the 6-pin connector?

Thanks again for your effort, your help, and for making this available to everyone!

Best regards,
Taras
 

Offline heize0

  • Contributor
  • Posts: 39
  • Country: cn
Re: LeCroy Probus reverse engineering
« Reply #64 on: June 02, 2026, 11:59:31 pm »
Hi!
I used 6 goal-plated pins directly.
 

Offline taras309

  • Contributor
  • Posts: 11
  • Country: ua
Re: LeCroy Probus reverse engineering
« Reply #65 on: August 09, 2026, 12:54:01 am »
Hi!
I used 6 goal-plated pins directly.


I wanted to provide a quick update on my progress with the adapter. I recently received my 6-layer, gold-plated PCBs and they look fantastic (heize0 thank you again).

After an extensive search for high-quality, gold-plated cylindrical pins for the ProBus interface (that weren't prohibitively expensive), I settled on MILL-MAX p/n 800-10-064-20-001000. These fit well and provide a reliable connection.

I have soldered the first prototype, and I'm happy to report that everything works great! I tested the adapter with a Tektronix TCP202 current probe and it performed flawlessly. supply rails are stable.

I also tested it with a high-voltage differential probe, a Tektronix P5205. I converted this specific probe to the ProBus interface several years ago. However, I noticed that the automatic detection of the 50x and 500x attenuation settings does not work with the current adapter design.

This is expected behavior for older analog Tektronix probes like the P5205, as they use a specific resistor value on Pin 1 (DATA) of the TekProbe connector to indicate attenuation. To ensure compatibility, a future revision of the board should include a jumper or a microswitch to connect TekProbe Pin 1 to the LeCroy ProBus Ring detection pin 6.

I also have a few questions for @heize0 regarding their original design:

Your design includes jumpers P2 and P3, connecting the data buses of the Tek probe and the ProBus interface. As I understand it, I2C communication won't work without modifying the LeCroy software database. Did you succeed in making them communicate, or was this just a provision for future attempts?

Regarding the U3 footprint on your board: did you populate it? If so, did you try uploading an EEPROM image from a native LeCroy probe? I would be very interested in the results.

Thanks again for sharing this design with the community!
« Last Edit: August 09, 2026, 01:11:19 am by taras309 »
 
The following users thanked this post: Someone, jjoonathan

Offline heize0

  • Contributor
  • Posts: 39
  • Country: cn
Re: LeCroy Probus reverse engineering
« Reply #66 on: August 09, 2026, 12:33:21 pm »
You are welcome. Actually I use R1 and U3(burned with LeCroy's TCP202 firmware) directly I only have TCP202. I never try with other probes.
 

Offline taras309

  • Contributor
  • Posts: 11
  • Country: ua
Re: LeCroy Probus reverse engineering
« Reply #67 on: August 09, 2026, 06:19:13 pm »
Thanks for the clarification! That explains why the board was designed this way.

Could you clarify which specific native LeCroy probe model you used the EEPROM dump from for your TCP202?
 

Offline heize0

  • Contributor
  • Posts: 39
  • Country: cn
Re: LeCroy Probus reverse engineering
« Reply #68 on: August 10, 2026, 12:31:22 pm »
ollopa has already uploaded all firmware and I simply use this T-TCP202A.bin.
 

Offline taras309

  • Contributor
  • Posts: 11
  • Country: ua
Re: LeCroy Probus reverse engineering
« Reply #69 on: August 14, 2026, 01:04:53 am »
I thought the archive only contained Lecroy dumps, is this T-TCP202A.bin a dump of the Tek probe, or is it an adaptation for Lecroy so that the oscilloscope understands that a current probe is connected to it?
It looks like it's just a dump, LeCroy shouldn't work with it since there are simply no Tek probes in the oscilloscope firmware, how does your oscilloscope see the TCP202 probes?
« Last Edit: August 14, 2026, 01:10:30 am by taras309 »
 

Offline heize0

  • Contributor
  • Posts: 39
  • Country: cn
Re: LeCroy Probus reverse engineering
« Reply #70 on: August 14, 2026, 01:24:37 pm »
No. The firmware uploaded by ollopa actually works on LeCroy oscilloscope and will automatedly set it to be a TCP202 current probe and the unit becomes Ampere.
 
The following users thanked this post: taras309

Offline Kampfkuchen

  • Newbie
  • Posts: 5
  • Country: de
Re: LeCroy Probus reverse engineering
« Reply #71 on: August 16, 2026, 01:14:11 pm »
Just want to give a short update from my side...

Everything delayed more than we expected. But we have the new prototype and at the moment, everything looks good to go. Just want to tell the project is not dead.
 
The following users thanked this post: Momchilo, taras309


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf

 

-->