Open-source 5G NR sniffer and downlink injector framework built on srsRAN. Passively captures unencrypted MAC-NR messages between a gNB and a UE (with Wireshark support) and can inject crafted MAC-NR packets to a target at specific post-connection states (registration/authentication/RRC) — used for modem crashes, downgrades, fingerprinting and auth-bypass research without a rogue base station. Heavy host requirements; FR1 sub-6 GHz on a USRP.