Hacker News new | ask | show | jobs
by p1peridine 1537 days ago
It's not easy but it is possible. You'd have to disable Windows update, IE and Edge, SMB, MRT, Defender, AutoLoggers, WMP DRM, GWX, SmartScreen, WER and change a bunch of registry keys. Disable certain services and scheduled tasks.

DiagTrack and all of it's sub-components have to be completely disabled and replaced with decoy files.

To verify, you'd have to monitor certain APIs via WinDbg and trace certain EventProviders using Windows Performance Recorder over a period of 24 hours to make sure there are no escalation issues (DiagTrack).

Pro-tip: if the EventLog (view them using Event Viewer) is not full of errors that constantly reappear you haven't disabled Telemetry properly.