Here is a good link on Logical Channels, I am assuming the firmware is capable of decoding some point of entry into network MU.  http://gsmfordummies.com/tdma/logical.shtml

is there a tutorial in applying patches in both osmocombb mobile or layer23?

Is using it as a BTS a key to accessing these RF channels without seeing the normal ARFCN dumps?

thanks.