How to temporarily stop as much as possible Microsoft network traffic on a potentially compromised machine

BRiddle52 1 Reputation point
2024-09-19T14:35:05.7066667+00:00

I need to connect my potentially compromised Win10 machine to the network briefly to determine any attempted target endpoint addresses, while blocking the actual connections at the edge firewall. However, various Microsoft products are generating an excessive amount of attempted network traffic, making it difficult to sift through to recognize the attempts of interest. How can I temporarily stop as much as possible Microsoft network traffic on a potentially compromised machine to have a better chance of confirming if there is indeed malware - and, if so - determining what endpoints may be involved? If limiting that traffic isn't possible, is there a minimum set of clearly recognizable U.S. based URLs I could filter and allow through my firewalls and ProcMon filters that would allow unstoppable legitimate MS updates/license traffic to transit without contributing to gigantic ProcMon logs?

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
11,500 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,892 questions
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,155 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.