A hands-on walkthrough of using Proxmox's built-in tcpdump to capture all network traffic from a fresh Windows 11 VM from the very first packet. By attaching to the VM's tap interface and saving a PCAP file, you can see exactly what Windows phones home to by default — even with a local account and minimal telemetry settings. The captured file is then analyzed in Wireshark and in SOCRATES (Security Onion Containerized Rapid Analysis), a Docker-based PCAP analysis tool by Security Onion's creator. Results show 76 DNS queries and multiple TLS connections to Microsoft and other services before any user interaction. The author concludes that blocking Windows telemetry is a cat-and-mouse game that updates can undo, and recommends avoiding Windows entirely if privacy is a concern.

8m watch time
97 Impressions