WindowsSpyBlocker favicon

WindowsSpyBlocker

WindowsSpyBlocker is a set of rules to block Windows spy / telemetry based on multiple tools to capture traffic located in the data folder. An application is also available to perform several extra operations. It is open for everyone and if you want to contribute or need help, take a look at the Wiki.

I use QEMU virtual machines on the server virtualization management platform Proxmox VE based on :

  • Windows 10 Pro 64bits with automatic updates enabled.
  • Windows 8.1 Pro 64bits with automatic updates enabled.
  • Windows 7 SP1 Pro 64bits with automatic updates enabled. I clean traffic dumps every day and compare results with the current rules to add / remove some hosts or firewall rules. Tools used to capture traffic :
  • qemu -net dump : capture
  • Wireshark : capture + logs
  • Sysmon : capture + logs
  • Proxifier : logs All traffic events are available in the logs folder. You can read the Telemetry page if you want more info about data collection.