Would deguard work?
It works by making the device run in CSM mode and disabling ME.
but I do not know how to
The Readme.md already pretty much clear what you have to do.
Change the value at offset 0x102 to 93 (HAP and DCI bit enabled) with hex editor. This should be under the flash descriptor. Then, use the output ME from Deguard to perform clean dump.