Exploiting UEFI boot script table vulnerability
blog.cr4.sh
blog.cr4.sh
The chipsec tool looks pretty useful for evaluating your setup: https://github.com/chipsec/chipsec
Also the UEFI parser https://github.com/theopolis/uefi-firmware-parser looks to be really useful if you want to dig deeper.