Faced the task of reading the entire memory to find traces of the chipset preload. For example, you can make a memory dump through the dmem command in the efishell. But there is a problem: the dump is a decrypted (debug) table when the binary itself is needed.
An important point of this task is that the memory should be as empty as possible. Therefore, the procedure must be carried out before loading the operating system.