21H1 seems to be virtualized.
I notice that Task Manager no longer aligns with machine state and CPU usage.
Hyper-V is an inverted hypervisor, and the "host" OS runs as a "client" of Hyper-V.
In the "Era of Containerization", we will not be able to figure anything out. I've already discovered this on Linux, with Snaps. You can have software behaviors which are a function of which security ring they run in.
Microsoft laughs at your Process Lasso now. You're screwed.
We need a lot more documentation to be dealing with this era. If only Mark Russinovich was not being held hostage in a cheese factory... (He's the Sysinternals guy and used to write excellent tutorials on how stuff works. He used to write and sell books about Windows Internals.)
*******I think I'm going to have to install an "absolutely clean" copy of 21H1, just to see what the baseline behavior is. And go the reverse engineering route (add softwares, check for weirdness and added items where they don't belong).
I suspect (but don't know for sure), that 21H1 uses Hyper-V, even when Hyper-V is not switched on in Programs and Features : Windows Features.
It would use that for WDAG, when it uses a 2.4GB "mini-OS" as a container to run a copy of Office Excel. Or use it in some way when WSL2 Bash shell is installed and running.
(They changed the name to MDAG, but the hardware requirements to make it work, tell you what it's doing...)
One part of this I couldn't figure out, is what happens to machines not particularly set up to support Hyper-V ? Do they switch it off ? Do they block your upgrade to 21H1 ? No idea. I would have to run an "absolutely clean" install on a Core2 (non-HyperV) machine to see.
I'd much rather have some well-written articles on the topic, than do this via reverse engineering.
You can also run Windows 10 in a virtual machine, and then what happens to this container stuff ? The test cases are endless.
Paul