In both cases: Brave and System, the tracker blocker identified some network traffic that corresponds to a know tracker.
The blocker is looking at all the traffic, including what any web page might contact or what you might do with system.
On web browsers, many web page trackers are linked to the web browser even if the tracker call comes from a web page and not the program of the web browser itself.
Regarding the system, I have no certainty or example as to what user action might lead to a tracker call but you are probably right when thinking about wifi captive portal.
So its rather reassuring to see that /e/ OS does not white list all the traffic from the system processes. Traffic is handled indiscriminately.
Though bear in mind that this method of tracker blocking does not prevent whatsapp or google to get your most intimate data if you use their software, apps or web sites, as your data will already be in their server.
There is also a trend for website owner to transmit our data from their server and not from the client side, be it a web-browser or app. This new server-side leak cannot be prevented.