UNTESTED: Set the HAP bit:
Positive Technologies discovered the presence of an undocumented HAP bit in the PCHSTRP0 field of the descriptor which, when set to 1, disables completely Intel ME just after the initialization. This is confirmed both by an analysis of the status of Intel ME after the setting of the bit and by reverse engineering the BUP module.
https://github.com/corna/me_cleaner/commit/350903a695851dda20b2be5d6099b58e377653b7
https://github.com/corna/me_cleaner
