Oh wow! I played around with getting a sim900 firmware running against qemu and open source tower implementations for finding exploits.
But this goes way farther than I had even planned! Connecting it to fuzzing infrastructure is super duper neat. I was just using it as a reproducible target to manually get it into weird states.