@JustCuriose
Something popped up into my mind when I saw your post :
You didn't mention the 3 letter word that Microsoft now wants to be present : TPM. A physical chip on the motherboard.
Without it, there is no direct access to Windows 11.
Its all (among others) about protecting safe booting - and protecting the boot process.
Checkout Youtube and look for Lojax. I didn't found any in-depth articles (videos) but it's pretty nasty.
On the other hand : if a boot virus is present on your system, some one had to have access to your system, with root rights, and install it. IMHO, the moment they login, the system is already considered 'dead'