p0f: TCP Packet Fingerprinting
lcamtuf.coredump.cx
lcamtuf.coredump.cx
The fingerprint file dates to 2014, well before Windows 10, and about Linux kernel 3.12. There's lots of things it just doesn't identify.
Application layer or session layer stuff like encryption is irrelevant, the fingerprints are largely based on differences at the transport layer and below.
You can also do some nice fingerprinting at the TLS layer based on stuff like what ciphers are offered, the order of them, etc.
This was the type of technique I was thinking of - https://murdoch.is/talks/eurobsdcon07hotornot.pdf
2014