Disable DNS cache service so that all your apps resolve DNS themselves (can only be done via the registry, change the service's startup type from 2 (auto) to 4 (disabled)).
In CIS, create a new group for all files under c:/windows.
Create a rule denying all in/out requests to that group.
Create a rule allowing only DHCP and NTP requests (255.255.255.255:67 and <whatever-timeserver-you-trust>:123) for svchost.exe (place that rule above the one for c:/windows to ensure precedence).
Use third-party utilities instead of the likes of ping.exe, e.g. hrping.
Refer to CIS documentation in case of any troubles.
Enjoy your privacy-hardened windows.
I'm currently using Binisoft (now Malware Bytes) Windows Firewall Control to block unwanted traffic. I'm quite happy with it.
The amount of traffic that it regularly blocks is insane. Windows and installed apps constantly want to chat with their cloud friends.
Someone else has some suggestions?
The issue is you can only control your firewall at home. Whenever you are out you are pretty sure that MS and Apple bypass any rule you'd put on the local firewall.
I prefer running sane operating systems.
For example an internal app starts up fine and works, but then can't connect to github. Instead of showing cert errors, I've had ones show errors that make it appear that you may have a DNS problem or that the connection to github itself was broken.
Not at all.
Of course you won't have access to some services in that case, like Windows Update, etc. One particular weird thing I have noticed is that the process that checks CRL on behalf on others is LSASS. So basically you have some extra tuning to do to get a system to your liking if using just the Windows Firewall, after you block everything but "Core Networking" (and programs you want to authorise), but it looks reasonable. I would suggest saving the initial state before you go that route, though.
If you trace connections you will find funny things, like cl.exe phoning home.
Yank your internet cord out and start windows.
It can be easily configured to block any host or path.