drop tpm 2.0 event log · parse measured events + attestation claims · runs locally
drop tpm 2.0 event log · local only
heuristic screener · vendor schema varies · not definitive proof