Wouldn’t transparent TLS with self signed certificates solve this problem?
I’ll definitely try this in couple of weeks but I can’t be the only person to try this to uncover exact data that is being sent via Windows telemetrics.
Another alternative would be remote debugging the kernel and hooking into some of the undocumented API calls but that would take lots of effort.