Aren't we chatty today, Windows 11
Continuing my work from the Web Browser telemetry article two years ago (which I plan to update, just to see the difference time does to telemetry data), I decided to make a log of all network connections a standard install of Windows 11 Pro (for ARM, 22H2, OS build 22621.1344) does.
The methodology is the same, standard setup without changing any of the default settings (Privacy ones, for example). Test device is a MacBook M1 laptop and Parallels Desktop, a clean user profile, all network connections blocked, application-level network connection whitelisting and only Little Snitch installed. So it’s actually Little Snitch that does all the heavy-lifting. Network traffic is routed through a VPN in Finland.
That’s 66 unique network connections to different hosts/domains for a clean install. Some are understandable, like Windows Update CDN, others like graph.microsoft.com and watson.events.data.microsoft.com are just the thing that would define Windows 11 as spyware. Definitely “more spyware” than DPRK’s Red Star OS.

config.edge.skype.comonTCPport443- Microsoft Skypectldl.windowsupdate.comonTCPport80- Windows Updatewww.msftconnecttest.comonTCPport80- Network Connection (NCSI)settings-win.data.microsoft.comonTCPport443- Used for Windows apps to dynamically update their configurationmsedge.api.cdp.microsoft.comonTCPport443- Microsoft Edgemsedge.f.tlu.dl.delivery.mp.microsoft.comonTCPport80- Microsoft Storefs.microsoft.comonTCPport443- Used to download fonts on demand239.255.255.250on UDP port1900cacerts.digicert.comonTCPport80- CRL and OCSP checks to the issuing certificate authoritiessdx.microsoft.comonTCPport443login.live.comonTCPport443- Microsoft Accountnav.smartscreen.microsoft.comonTCPport443- Windows Defender Smartscreensmartscreen-prod.microsoft.comonTCPport443- Windows Defenderslscr.update.microsoft.comonTCPport443- Windows Update, Microsoft Update, and the online services of Microsoft Storeocsp.digicert.comonTCPport80- CRL and OCSP checks to the issuing certificate authoritiescrl3.digicert.comonTCPport80- CRL and OCSP checks to the issuing certificate authoritiesfe2cr.update.microsoft.comonTCPport443- Windows Update, Microsoft Update, and the online services of Microsoft Storegeo.prod.do.dsp.mp.microsoft.comonTCPport443- Windows Updatego.microsoft.comonTCPport443- Windows Defenderstatics.teams.cdn.office.netonTCPport443- Microsoft Teamsdownload.windowsupdate.comonTCPport80- Windows Updatekv501.prod.do.dsp.mp.microsoft.comonTCPport443- Windows Updatefe3cr.delivery.mp.microsoft.comonTCPport443- Microsoft Storecp501.prod.do.dsp.mp.microsoft.comonTCPport443- Windows Updatego.microsoft.comonTCPport80- Windows Defendergeover.prod.do.dsp.mp.microsoft.comonTCPport443- Windows Updatelicensing.mp.microsoft.comonTCPport443- Used for online activation and some app licensingztd.dds.microsoft.comonTCPport443client.wns.windows.comonTCPport443- Used for the Windows Push Notification Services (WNS)dmd.metaservices.microsoft.comonTCPport80- Used to retrieve device metadataconfig.teams.microsoft.comonTCPport443- Microsoft Teamsteams.events.data.microsoft.comonTCPport443- Microsoft Teamsstatics.teams.cdn.live.netonTCPport443- Microsoft Teamsedge-conumer-static.azureedge.netonTCPport443dl.delivery.mp.microsoft.comonTCPport80- Microsoft Storemsedge.b.tlu.dl.delivery.mp.microsoft.comonTCPport80- Microsoft Storeedge.microsoft.comonTCPport443account.live.comonTCPport443acctcdn.msauth.netonTCPport443browser.events.data.microsoft.comonTCPport443login.live.comonTCPport443- Microsoft Accountlogincdn.msftauth.netonTCPport443- Microsoft OneDrivev10.events.data.microsoft.comonTCPport443- Diagnostic Datainference.location.live.netonTCPport443- Used for location datav20.events.data.microsoft.comonTCPport443fd.api.iris.microsoft.comonTCPport443www.bing.comonTCPport443- Cortana, apps, and Live Tilesonedscolprduks05.uksouth.cloudapp.azure.comonTCPport443- Azurer.bing.comonTCPport443- Cortana, apps, and Live Tilesth.bing.comonTCPport443- Cortana, apps, and Live Tilesteams.live.comonTCPport443- Microsoft Teamsassets.msn.comonTCPport443- Windows Spotlightedgeassetservice.azureedge.netonTCPport443arc.msn.comonTCPport443- Windows Spotlightg.live.comonTCPport443- Microsoft OneDriveofficeclient.microsoft.comonTCPport443- Microsoft Officeoneclient.sfx.msonTCPport443- Used by OneDrive for Business to download and verify app updatesmaps.windows.comonTCPport443- Maps applicationwatson.events.data.microsoft.comonTCPport443- Diagnostic Datawww.microsoft.comonTCPport80self.events.data.microsoft.comonTCPport443- Microsoft Officegraph.microsoft.comonTCPport443ris.api.iris.microsoft.comonTCPport443- Used to retrieve Windows Spotlight metadatafp.msedge.netonTCPport443- Microsoft OfficeHubwindows.msn.comonTCPport443- Windows Spotlightnav-edge.smartscreen.microsoft.comonTCPport443
Yeah …
permalink http://sizeof.cat/post/chatty-windows-11/
created March 10, 2023
words 735
tags #windows, #telemetry, #privacy
























