Originally Posted by -W_O_L_F-
Oh yeah, it was right here on the forum.
The qfuse register is held in a 4KB starting at 0xFA700000. We should be able to read the shadow region at 0x00706000-0x00706FFFF if we can get tools to run.
The memory map graphic is a 2KB block (MSM8660), but it should be roughly analogous to the 4KB block (MSM8960 - lumia 920/1020/etc)
Working on finding the docs. Downloads aren't working now, and I can't find them on this computer.
Depending on the certs in there, there is an outside chance that I could con it into running Windows PE ARM so we would have the basis to run some good tools... but that is a very outside chance (IIRC the signing certs between RT and WP devices are from different CAs).