Offline Analysis of Historical Bitcoin Transactions

Choose a study mode

Play Quiz
Study Flashcards
Spaced Repetition
Chat to Lesson

Podcast

Play an AI-generated podcast conversation about this lesson

Questions and Answers

Which of the following wallets is known for being a multi-chain wallet?

  • Electrum
  • Bitcoin Core
  • Exodus (correct)
  • BTCRecover

Which of the following wallets is known for being a thin client?

  • Bitcoin Core
  • Exodus
  • Electrum (correct)
  • BTCRecover

Which of the following wallets stores its data in encrypted Secure Container (.SECO) files?

  • Electrum
  • Exodus (correct)
  • BTCRecover
  • Bitcoin Core

Which of the following wallets allows users to password protect and encrypt their wallet data?

<p>Electrum (D)</p> Signup and view all the answers

Which of the following wallets is a full node client and requires a full copy of the BTC blockchain to run correctly?

<p>Bitcoin Core (B)</p> Signup and view all the answers

Which command can be used to filter out irrelevant lines from the output of a command?

<p>findstr (D)</p> Signup and view all the answers

What information does the 'pslist' command provide?

<p>Process name and identifier (A)</p> Signup and view all the answers

What does the 'netscan' command identify?

<p>Processes connected to and talking to the network (D)</p> Signup and view all the answers

What do the IP addresses identified by 'netscan' indicate?

<p>The content viewed on the internet (B)</p> Signup and view all the answers

What do Virtual Address Descriptors (VAD) describe?

<p>The slivers of a process in memory (B)</p> Signup and view all the answers

Which command should be used to combine multiple .dmp files into a single file?

<p>copy /b *.dmp bitcoin-qt.dmp (A)</p> Signup and view all the answers

What is the purpose of BTCScan.py?

<p>To extract crypto artefacts from the process space (C)</p> Signup and view all the answers

Why is it important to remove duplicates from the csv file?

<p>To ensure only unique addresses are considered (C)</p> Signup and view all the answers

What is the purpose of the User Assist registry key in Windows?

<p>To track user activities and program usage (A)</p> Signup and view all the answers

Why is being able to attribute an address to a specific user and software valuable in a cryptocurrency investigation?

<p>To understand the addresses provenance (B)</p> Signup and view all the answers

Which of the following is NOT a magic value used to locate valuable artifacts in MetaMask?

<p>balance (D)</p> Signup and view all the answers

What is the purpose of the seedword recovery tool in MetaMask?

<p>To recreate the seed phrase (A)</p> Signup and view all the answers

Where can the necessary wallet data for Chrome extensions be found?

<p>Google/Chrome/Default/Local Extension Settings/[Chrome Extension Hash] (C)</p> Signup and view all the answers

Which Chrome extension has the hash 'nkbihfbeogaeaoehlefnkodbefgpgknn'?

<p>Crypto MetaMask (A)</p> Signup and view all the answers

Where can the wallet data for TronLink be found in Google Chrome?

<p>Google/Chrome/Default/Local Extension Settings/ibnejdfjmmkpcnlpebklmnkoeoihofec (A)</p> Signup and view all the answers

Which command can be used to determine the profile of a RAM image in Volatility?

<p>imageinfo (B)</p> Signup and view all the answers

Where are Bitcoin wallet files saved in the default data directory on Windows Vista and 7?

<p>C:\Users\YourUserName\Appdata\Roaming\Bitcoin\Wallets (D)</p> Signup and view all the answers

What is the magic value at offset zero for all raw Bitcoin data?

<p>f9beb4d9 (D)</p> Signup and view all the answers

Which tool can be used to search for Bitcoin wallet files by file names, contents, and regular expressions?

<p>Agent Ransack (A)</p> Signup and view all the answers

Which script can be used to extract Bitcoin addresses, private keys, and Xpriv/Xpub keys by scanning drives, directories, and/or files using RegEx?

<p>BTCScan (B)</p> Signup and view all the answers

Where can you find the MetaMask log file on Windows Chrome?

<p>C:\Users\USER_NAME\AppData\Local\Google\Chrome&quot;User Data&quot;\Default\Local Extension Settings\nkbihfbeogaeaoehlefnkodbefgpgknn (C)</p> Signup and view all the answers

What is MetaMask primarily used for?

<p>Interacting with web3 compatible sites (B)</p> Signup and view all the answers

Which EVM blockchains are supported by MetaMask?

<p>Ethereum (ETH) and Binance Smart Chain (BSC) (B)</p> Signup and view all the answers

What can be found within the MetaMask log file?

<p>Encrypted copy of the wallets seed phrase (A)</p> Signup and view all the answers

Where can you find the MetaMask log file on Mac Firefox?

<p>Library&gt;Application Support&gt;Firefox&gt;Profiles&gt; mqusl6b4.default-release-1653305409297&gt;storage&gt;default (D)</p> Signup and view all the answers

Flashcards are hidden until you start studying

More Like This

Cryptocurrency Wallets Quiz
10 questions

Cryptocurrency Wallets Quiz

WellRoundedSanctuary avatar
WellRoundedSanctuary
Cryptocurrency Wallets Quiz
10 questions

Cryptocurrency Wallets Quiz

WellRoundedSanctuary avatar
WellRoundedSanctuary
Cryptocurrency Wallets Quiz
10 questions

Cryptocurrency Wallets Quiz

WellRoundedSanctuary avatar
WellRoundedSanctuary
Cryptocurrency Wallets Quiz
10 questions
Use Quizgecko on...
Browser
Browser