intellicrack.sandbox.telemetry_blocking

In-guest blocking of a Windows guest’s own operating-system telemetry.

Sandbox Settings offers “Block telemetry endpoints”, and what an analyst wants from it is a capture in which every outbound flow belongs to the sample. A stock Windows guest talks to its vendor constantly, and that traffic is indistinguishable from a sample’s beaconing in a PCAP unless it is stopped at the source.

Two mechanisms are applied inside the guest, because neither is sufficient alone:

  • a hosts-file sinkhole for the published telemetry FQDNs. Name resolution is where a hostname is still a hostname; by the time a packet exists it carries an address that rotates across an enormous CDN, so a host-side or firewall filter cannot express “this endpoint” at all.

  • outbound firewall rules for the telemetry programs. The sinkhole is bypassed by anything that resolves without the hosts file - a client with a pinned address, or DNS-over-HTTPS - and blocking the executables covers that path regardless of how they resolve.

Deliberately absent: stopping or disabling the DiagTrack service. It is the obvious third mechanism and it is the one a sample can see. A guest whose telemetry service is missing does not look like the machine the sample expects to be running on, and this package spends real effort elsewhere on making the guest look stock.

build_windows_blocking_command()[source]

Build the guest argv that runs the blocking script.

powershell.exe is invoked with -EncodedCommand because the guest channels this package uses dispatch through cmd.exe, which mangles a multi-line script into an empty run that still reports success.

Returns:

Arguments for powershell.exe, excluding the executable.

Return type:

list[str]

build_windows_blocking_script()[source]

Build the PowerShell that blocks telemetry inside a Windows guest.

The script is idempotent: the hosts block it owns is delimited by HOSTS_BLOCK_MARKER and rewritten wholesale, and each firewall rule is removed before being recreated. Applying it to a guest that already has it leaves the guest in the same state.

Firewall rules go through the NetSecurity module when it is present and fall back to netsh advfirewall when it is not, because Windows editions that ship without the module still have the firewall.

Returns:

A complete PowerShell script. Its last line is a single pipe-delimited record prefixed with a marker, reporting how many hosts entries and firewall rules were written, which firewall backend was used, and any error encountered.

Return type:

str

parse_blocking_result(output)[source]

Extract the summary the blocking script printed.

The counts come back as integers and problems as a list, so a caller can tell “wrote nothing” from “wrote thirty-one” without reparsing text. A record whose counts are not numeric is rejected outright rather than reported as zero: a guest that garbled its summary has not been shown to have blocked anything.

Parameters:

output (str) – Captured standard output of the script.

Returns:

The parsed summary, keyed by _RESULT_FIELDS, or None when the script produced no readable marker line.

Return type:

dict[str, object] | None