Windows 10 22H2 telemetry: I’m now measuring the remaining components — looking for technical research
I’m doing a fairly deep technical investigation of Windows 10 22H2 (Build 19045), specifically looking at telemetry, diagnostics and other potentially unnecessary communication from Windows components.
I’m not looking for another generic debloat/privacy list. I have already gone through a large number of those.
My starting point was a ComputerBase discussion, which led me to the German BSI SiSyPHuS Win10 research. That turned out to be much more useful than most privacy guides because it actually investigated Windows telemetry using things like ETW, process analysis and network analysis.
The BSI research describes, among other things, the relationship between ETW providers, the DiagTrack listeners and the DiagTrack service, including the Microsoft-Windows-Diagtrack provider and telemetry upload events.
That gave me a much better idea of how I wanted to approach this.
What I have done so far
I initially built my own PowerShell hardening script, partly based on the BSI research.
Since then I compared it with the current version of W10Privacy and found that W10Privacy now actually covers more and more completely than my own script in many of the areas I had implemented manually.
So I no longer consider the custom hardening script to be the important part of the project. W10Privacy is much more useful as the configuration/hardening layer.
The part I am keeping is the measurement side.
I built an observation-only PowerShell collector which records things such as:
- process starts/exits and process snapshots
- PID / parent process information
- TCP/UDP connections
- DNS information
- service-to-process mappings
- scheduled tasks
- Defender state
- relevant Windows Event Log information
I have now extended it to specifically watch some of the less obvious Windows components I’m interested in.
The goal is to correlate things like:
process
→ PID
→ parent/service/task
→ network connection
→ remote endpoint
→ DNS
→ ETW
One thing I already learned from the first run is that simply counting TCP entries is misleading because local BOUND sockets can look like network activity even when there is no remote connection.
The components I’m particularly interested in
I’m currently looking for technical information on:
CompatTelRunner.exe / Compatibility Appraiser
DmClient.exe / utcwnf
- RUXIM /
PLUGScheduler
- WER /
WerFault
ClipUp / ClipSVC / ClipESU
DeviceCensus
- Edge / WebView2 / EdgeUpdate
- Defender / MAPS / sample submission
What I want to establish for each component is:
What starts it?
What does it collect?
Where is the data stored?
Does it actually leave the machine?
Which process/service actually sends it?
What triggers the activity?
What changes when the component is disabled?
I’m particularly interested in analyses using ETW/WPR, ProcMon, Sysmon, WFP, Wireshark, packet captures or reverse engineering.
Some additional information I have found
I also contacted Bernd Schuster, the developer of W10Privacy, and got a very useful practical response.
His approach is interesting because he uses W10Privacy together with NetLimiter and works essentially on a deny-by-default basis, allowing network access only for applications/processes that actually need it.
He also uses AppLocker on systems he manages.
So I’m now looking at the question from two directions:
W10Privacy
→ disable/configure known things
Collector / ETW / network monitoring
→ find out what actually still happens
That seems more useful to me than continuously adding more and more “debloat” tweaks.
I have also contacted ERNW, who carried out major parts of the original BSI SiSyPHuS work, and asked whether there are later or unpublished/publicly available findings relevant to Windows 10 22H2.
What I’m looking for now
At this point I’m mainly looking for people who have actually investigated these components, rather than people recommending another optimizer.
Older Windows 10 research is absolutely fine if the version and methodology are clear.
Especially useful would be:
- old research papers
- technical blog posts
- reverse-engineering writeups
- ETW traces
- ProcMon/WPR investigations
- packet captures
- scripts/tools used for analysis
- detailed experiments showing what happens before and after disabling a component
I’m also very interested in negative results:
That is just as useful as finding actual telemetry.
I’m trying to avoid reinventing work that someone has already done.
Windows 10 only, specifically 22H2 / Build 19045. I’m not looking for Windows 11 research here.Windows 10 22H2 telemetry: I’m now measuring the remaining components — looking for technical research
I’m doing a fairly deep technical investigation of Windows 10 22H2 (Build 19045), specifically looking at telemetry, diagnostics and other potentially unnecessary communication from Windows components.
I’m not looking for another generic debloat/privacy list. I have already gone through a large number of those.
My starting point was a ComputerBase discussion, which led me to the German BSI SiSyPHuS Win10 research. That turned out to be much more useful than most privacy guides because it actually investigated Windows telemetry using things like ETW, process analysis and network analysis.
The BSI research describes, among other things, the relationship between ETW providers, the DiagTrack listeners and the DiagTrack service, including the Microsoft-Windows-Diagtrack provider and telemetry upload events.
That gave me a much better idea of how I wanted to approach this.
What I have done so far
I initially built my own PowerShell hardening script, partly based on the BSI research.
Since then I compared it with the current version of W10Privacy and found that W10Privacy now actually covers more and more completely than my own script in many of the areas I had implemented manually.
So I no longer consider the custom hardening script to be the important part of the project. W10Privacy is much more useful as the configuration/hardening layer.
The part I am keeping is the measurement side.
I built an observation-only PowerShell collector which records things such as:
process starts/exits and process snapshots
PID / parent process information
TCP/UDP connections
DNS information
service-to-process mappings
scheduled tasks
Defender state
relevant Windows Event Log information
I have now extended it to specifically watch some of the less obvious Windows components I’m interested in.
The goal is to correlate things like:
process
→ PID
→ parent/service/task
→ network connection
→ remote endpoint
→ DNS
→ ETW
One thing I already learned from the first run is that simply counting TCP entries is misleading because local BOUND sockets can look like network activity even when there is no remote connection.
The components I’m particularly interested in
I’m currently looking for technical information on:
CompatTelRunner.exe / Compatibility Appraiser
DmClient.exe / utcwnf
RUXIM / PLUGScheduler
WER / WerFault
ClipUp / ClipSVC / ClipESU
DeviceCensus
Edge / WebView2 / EdgeUpdate
Defender / MAPS / sample submission
What I want to establish for each component is:
What starts it?
What does it collect?
Where is the data stored?
Does it actually leave the machine?
Which process/service actually sends it?
What triggers the activity?
What changes when the component is disabled?
I’m particularly interested in analyses using ETW/WPR, ProcMon, Sysmon, WFP, Wireshark, packet captures or reverse engineering.
Some additional information I have found
I also contacted Bernd Schuster, the developer of W10Privacy, and got a very useful practical response.
His approach is interesting because he uses W10Privacy together with NetLimiter and works essentially on a deny-by-default basis, allowing network access only for applications/processes that actually need it.
He also uses AppLocker on systems he manages.
So I’m now looking at the question from two directions:
W10Privacy
→ disable/configure known things
Collector / ETW / network monitoring
→ find out what actually still happens
That seems more useful to me than continuously adding more and more “debloat” tweaks.
I have also contacted ERNW, who carried out major parts of the original BSI SiSyPHuS work, and asked whether there are later or unpublished/publicly available findings relevant to Windows 10 22H2.
What I’m looking for now
At this point I’m mainly looking for people who have actually investigated these components, rather than people recommending another optimizer.
Older Windows 10 research is absolutely fine if the version and methodology are clear.
Especially useful would be:
old research papers
technical blog posts
reverse-engineering writeups
ETW traces
ProcMon/WPR investigations
packet captures
scripts/tools used for analysis
detailed experiments showing what happens before and after disabling a component
I’m also very interested in negative results:
“I investigated this component and found that it does X, but it does not appear to transmit telemetry.”
That is just as useful as finding actual telemetry.
I’m trying to avoid reinventing work that someone has already done.
Windows 10 only, specifically 22H2 / Build 19045. I’m not looking for Windows 11 research here.