Secure Boot
Defense · Distilled (purple) · Formal Methods corpus
Boot-time chain of cryptographic verification — firmware checks bootloader, bootloader checks kernel — refusing to run any component that isn’t signed by an approved key. Blocks rootkits before the OS even starts.