How Does Wand‑Enhancer Disable Telemetry? Inside the Binary Patching Strategy
Wand‑Enhancer disables telemetry by applying a binary patch defined by the EPatchType.DisableTelemetry enum value, which the .NET version.dll proxy injector uses to strip telemetry calls from the Wand client at runtime.
Wand‑Enhancer is an open-source modification framework for the Wand application that intercepts and rewrites the client’s behavior before it executes. One of its core security features is the complete elimination of telemetry reporting, implemented through a type‑safe patching system and a low‑level DLL proxy. This article examines the source code to explain exactly how the tool achieves telemetry isolation without relying on external services or registry hacks.
The Telemetry Patch Flag (EPatchType.DisableTelemetry)
At the heart of the telemetry removal system is a strongly‑typed enumeration that tells the patcher which modifications to apply. In WandEnhancer/Models/PatchConfig.cs, the EPatchType enum defines the DisableTelemetry member with the integral value 4:
public enum EPatchType
{
// ... other patch types ...
DisableTelemetry = 4,
// ...
}
When the patcher initializes, it reads a HashSet<EPatchType> from the PatchConfig.PatchTypes collection. If DisableTelemetry is present in that set, the engine enters a specialized code path that targets the telemetry subsystem of the Wand binary.
Configuring Telemetry Removal via the Settings UI
End users control telemetry disabling through the graphical settings interface. The view‑model backing SettingsPopup.xaml.cs binds a checkbox labeled “Disable telemetry” to the active PatchConfig instance. When the user enables this option, the view‑model adds EPatchType.DisableTelemetry to the PatchTypes hash set:
// Example: Enabling the telemetry patch programmatically
var config = new PatchConfig
{
PatchTypes = new HashSet<EPatchType> { EPatchType.DisableTelemetry }
};
This configuration is then serialized and passed to the patch engine, ensuring the telemetry stripping logic is applied during the next launch cycle. The UI also reflects the current state by checking config.PatchTypes.Contains(EPatchType.DisableTelemetry) before rendering the checkbox.
Runtime Binary Patching via the version.dll Proxy
The actual disabling mechanism occurs inside the version.dll proxy injector, a .NET assembly that Wand‑Enhancer places alongside the original client executable. When Windows loads the client process, it resolves the version.dll dependency and inadvertently loads the enhancer’s proxy, which gains execution context within the Wand address space.
According to the repository’s architecture, the proxy performs the following actions when EPatchType.DisableTelemetry is active:
- Signature Scanning – It scans the mapped Wand executable memory for known telemetry export patterns and function prologues associated with analytics reporting.
- NOP‑ing Call Sites – It overwrites the discovered call instructions with NOP (No Operation) sleds or redirects them to a dummy return stub, effectively neutering the telemetry emission code without crashing the host process.
- Service disablement – It terminates any background threads or timer‑based tasks that would silently batch and transmit usage data, ensuring zero network traffic reaches telemetry endpoints.
Because the patch operates on the in‑memory image of the binary, the modifications are non‑persistent and vanish when the process exits, leaving the original files on disk untouched.
Network Isolation and Update Guarantees
The README explicitly states that the .NET patcher does not initiate outbound connections to check for updates or transmit analytics. This design choice ensures that even if the user forgets to enable the explicit DisableTelemetry flag, the patcher itself remains air‑gapped from external services:
The .NET patcher does not contact any update or telemetry service; it only modifies local files.
Additionally, the CHANGELOG notes that a previously exposed “telemetry removal” option was removed from the UI because telemetry is now fully disabled by default when the patch is applied, making the protection automatic and redundant toggles unnecessary.
Implementation Example
Below is a complete example demonstrating how to programmatically verify that telemetry suppression is active:
using WandEnhancer.Models;
// Load existing configuration
var patchConfig = PatchConfig.Load();
// Check if telemetry is disabled
bool isTelemetryDisabled = patchConfig.PatchTypes.Contains(EPatchType.DisableTelemetry);
Console.WriteLine($"Telemetry patching enabled: {isTelemetryDisabled}");
// Apply patches if needed
if (!isTelemetryDisabled)
{
patchConfig.PatchTypes.Add(EPatchType.DisableTelemetry);
await Enhancer.ApplyPatchesAsync(patchConfig);
}
Summary
EPatchType.DisableTelemetryis defined inPatchConfig.csand serves as the canonical flag for telemetry suppression.- The Settings UI (
SettingsPopup.xaml.cs) exposes this flag through a simple checkbox that manipulates thePatchTypescollection. - At runtime, the
version.dllproxy patches the Wand process memory to neutralize telemetry call sites and background services. - The architecture guarantees zero network contact by design, with the README and CHANGELOG confirming that no external telemetry or update traffic occurs.
Frequently Asked Questions
Does Wand‑Enhancer modify the Windows Registry to disable telemetry?
No, Wand‑Enhancer does not rely on registry modifications. It uses in‑memory binary patching via the version.dll proxy to neutralize telemetry functions at the code level, ensuring the changes are process‑specific and do not alter system‑wide registry keys.
Is the telemetry patch applied automatically or do users need to enable it?
While the patch can be enabled manually through the settings UI in SettingsPopup.xaml.cs, the CHANGELOG indicates that recent versions automatically apply telemetry suppression when the enhancer is active, rendering a separate toggle redundant and guaranteeing protection by default.
What happens if the Wand client updates to a new version?
The version.dll proxy uses signature scanning rather than static offsets, allowing it to locate telemetry code patterns even after minor client updates. If a major update changes the binary layout significantly, the PatchConfig system allows maintainers to update the detection signatures without rewriting the core patching engine.
Does the telemetry disabling affect other Wand features like crash reporting?
The DisableTelemetry patch specifically targets analytics and usage tracking exports. According to the source architecture, crash‑reporting facilities are handled by separate patch flags; users can combine DisableTelemetry with other EPatchType values to fine‑tune which diagnostic systems remain active.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →