No amount of EFI rootkit detection will ever remove the possibility that malicious code is running inside the Intel Management Engine (ME), because code inside the ME would run side-by-side with the bootloader and with unlimited permissions.
Unless Intel provides source code for the ME, it is impossible to 100% know whether unauthorized code is running.