for SecureBoot you could use the Linux shim bootloader, to boot your stick, or a tiny Linux that runs your code, right?
As for the shim bootloader: it only chainloads signed EFI binaries. To run a custom unsigned bare-metal dumper through it, you would have to use a known vulnerable version of shim (like the one from the BootHole vulnerability) to bypass the signature check for the next stage. It's possible in theory, but adds a massive layer of complexity compared to just using CSM.
Guys, I'm writing using a translator without AI now. Are you happy?