Blocking rules are self-contained in the
data folder of the repository.
These rules are based on domains or IPs detected during the capture process.
They are separated into 3 distinct categories that must be chosen carefully if you wish to apply them:
Spy rules block Windows telemetry and can be found in
Update rules block Windows Update and can be found in
Block third party applications like Skype, Bing, Live, Outlook, NCSI, Microsoft Office, ... and can be found
ONLY use if you know what you do
Be aware that these rules can also block Windows Update and other services.
Therefore, no support will be provided on them.
- DNSCrypt: a protocol for securing communications between a client and a DNS resolver.
- ESET Firewall: a proprietary firewall solution.
- Kaspersky Firewall: a proprietary firewall solution.
- OpenWrt: an open source project used on embedded devices to route network traffic.
- P2P: a plaintext IP data format from PeerGuardian.
- Proxifier: an advanced proxy client on Windows with a flexible rule system.
- simplewall: a simple tool to configure Windows Filtering Platform (WFP).
How it works?¶
To capture and interpret network traffic, QEMU virtual machines are used on the server virtualization management platform Proxmox VE based on:
- Windows 11 Pro 64bits with automatic updates enabled.
- Windows 10 Pro 64bits with automatic updates enabled.
Traffic dumps are cleaned monthly and compared with the current rules to update hosts and firewall rules.
Following tools are used to capture traffic:
Created: 2020-08-14 00:18:56