drop uefi secure boot variables + boot log · analyze violation vectors · runs locally
drop uefi secure boot variables + boot log · local only
heuristic screener · vendor schema varies · not definitive proof