1) Use SystemInternal's process explorer and track all network connections: (As admin: Add column to track the network tx, rx counts)
https://docs.microsoft.com/en-us/sysinternals/downloads/proc...
2) When I see some app, system that connect to network which I think it should not. I just block their network connections with Windows Firewall or uninstall those app.
There is a "netsh advfirewall firewall" command that can do this from command line.
3) BTW this works very well with Windows' own service too. I block svchost.exe, Edge, SerchIndex, etc from accessing internet. svchost.exe is allowed to access local subnet for file, print sharing. When I feel like upgrade to to latest version windows 10. I turn off the firewall rules for a few hours to allow the update to go thru.
4) Only Firefox and Chrome in my windows system are allowed to connect to internet full time. The CPU usage is normally < 15% and most of the time < 10% even when playing youtube @ 1080 resolution.
The latest Firefox Quantum has less CPU usage and faster also. I love it.
5) The WSL (Windows Subsystem for Linux) is getting better - X, xfce4-termnial now working good enough for me. I like accessing the Ubuntu shell in windows environment without the overhead of Virtualbox.I have a beloved 2015 MBP that I'm trying to keep alive, but it's becoming a little underpowered and it's not upgradeable. New MBPs are a non-starter with the port and keyboard situation and my coworkers all hate them. Then I have a maxed out XPS 13 which is a very nice and capable machine that suits me completely, except that it has a malicious OS that I have to constantly fight. And Linux doesn't support a lot of the tools I need.
So..... what's the solution here?
I started off in a dual boot situation, and i can't even remember the last time i went into my windows partition. It has to be less than 5 times in the past 3 years.
It is very fun to play with a full screen MacOS on a touch screen enable Laptop.
I just want this to work, but it doesn't. This was a Dell laptop that came preinstalled with Ubuntu, too.
Also Linux multi-screen/multi-DPI support is still bad.
The new 2017 models don't have much more horsepower. They just have a worse keyboard and a touch strip.
There may be Linux equivalents of the tools you use, but it would be difficult to say without you naming these tools specifically.
So..... what's the solution here?"
The solution is sitting in your hands. That XPS 13 can run Ubuntu (and probably Debian, Arch/Antergos, or any other major distro) flawlessly since Dell ships a version with Ubuntu preinstalled. Set it up to dual boot with Windows, and use VirtualBox's raw hard disk access feature to set up a Windows guest under Linux using the Windows partition as the VM's boot drive.
That way, you can slowly wean yourself off of Windows; use the VM for your Windows-only tasks with the option of booting natively into Windows for anything strictly hardware dependent, until you have replaced your Windows workflow with Linux. Even if you find you can't 100% escape Windows, at least you're not living in it so you're not being spied on all day.
> with the option of booting natively into Windows for anything strictly hardware dependent
IIRC, years ago, when Windows 7 was the latest Windows, this couldn't be done. Windows used to take offense if the hardware it was running on changed significantly from boot to boot. Has that changed with Windows 10?
I've recently moved to Mint with Win7 in a vm and its lack of GPU and DirectX support is not really workable. Basic apps are fine.
Well, yes, if you want to do any significant amount of gaming on a computer, you'd want a dedicated GPU. If integrated GPUs meet your demands for gaming, you're better of with native Linux games and Wine for Windows casual games.
> "I've recently moved to Mint with Win7 in a vm and its lack of GPU and DirectX support is not really workable."
It sounds like you're better served by dual-booting then. Running a VM isn't a solution for everyone, just another option for some.
Why do people continue to purchase products from companies that blatantly want to spy on them? Vote with your wallet and never go through a bizarre multi-step anti-spyware setup again.
And regarding (5)... well, the same thing I used to tell people about WINE applies, just in reverse. Unless you're butting up against a corporate policy or something, why pick the inferior, broken imitation when the real thing is right there?
Still you count as a happy Windows user and will reinforce the Microsoft position. This way they will be able to abuse 99% of their users, those that don't have the same competencies and time to spend on these countermeasures.
As for the WSL I stopped using it. This is an honey trap to let people use Windows as their primary OS by just giving them the developer goodies they like. I may consider it again if you can use it to develop a full-fledged Windows application that can access the windowing system and can be redistributed. You may have noticed that with WSL you cannot and the applications you may do remains nicely restricted to the linux subsystem.
A honey pot? I don't think that means what you think it means. If you are interested in developing full-fledged Windows applications, why in the world would you want to use WSL? You are not the kind of developer that WSL is designed for.
If you want to develop to a Windows target, then configure your WSL environment to do cross-compiling. That's up to you. If you can cross-compile in Ubuntu, then you can cross-compile in WSL. Just don't expect WSL to be anything but Linux.
https://github.com/caesarshift/msfw
I would run "msfw log --tail" to watch for blocked connections. If I wanted to allow the connection, I then added it as a rule.
It was alot of work to setup initially, and I even found some scenarios where adding a rule was not sufficient to allow the connection. I never understood why.