Manual checks that need a lab machine (driver / TPM). CI dotnet test does not require these.
- Full scan completes (user-mode path)
- Advanced / result shows kernel evidence Unavailable (informational)
-
challengeEvidencepresent with DenyCritical / DenyDefault / AllowListedEligible decisions -
spdmEvidence.availabilityUnknown or Unsupported (not treated as suspicious) -
measuredBootEvidenceUnknown/Unsupported when TBS/TPM unavailable (not suspicious) - Export schemaVersion
1.5; no "Attested" label in UI - PnP history off by default; with Home checkbox / config opt-in,
pnpHistory.optInEnabledtrue - Kernel tab shows BAR type/base (and size when probe succeeded)
- Kernel evidence Available/Partial for some BDFs; protocol 2 advertises
CapQueryBarSizeProbe - Network-class BAR sizes may be non-zero; storage/GPU/bridge/USB host sizes stay 0 (probe denied)
- DOE (0x2E) devices (if any) appear under
spdmEvidencewithdoePresent: trueandNotIntegrated - IOCTL
SafeDeviceResetstill fails: Cap unset; critical classes auditSafeDeviceResetDeniedCritical; othersSafeDeviceResetDenied - No FLR / device reset occurs
- If a stock
10EE:0666device is present:STOCK_PCILEECH_IDENTITY(+ triage hint); default caps →PCILEECH_DEFAULT_CAP_LAYOUT; multi-signal →DMA_SIGNAL_CLUSTER - Result screen shows DMA / CFW review summary when any DMA codes fire; Findings tab DMA / CFW only filter works
- DSN ext-cap devices (if any):
deviceSerialNumberHexinkernelEvidence; zero/dup →PCI_DSN_WEAK_SIGNAL(≤ Medium)
-
measuredBootEvidenceSupported or Partial withpcrBank: sha256and PCR indexes 0-7 (or subset) - Export privacy
IncludePcrDigests=falseomits digest hex - UI shows Measured Boot / PCR as evidence availability, never "Attested"
- Upload with schema
1.5(and1.4…1.0) accepted - Admin review remains human-only (no auto-ban)