drop system evtx csv and registry export · detect secure boot disabled or bypassed · identify code integrity violations at boot · surface bootkit and rootkit enablement through secure boot manipulation · runs locally
Security 4826/4688 · Code Integrity 3001/3002/3004/3023 · System 7045 · UEFISecureBootEnabled registry
drop system evtx csv · security evtx csv · registry export (multi-file)