To access material, start machines and answer questions login.
Amazon Web Services () is one of the most used cloud providers, and many companies worldwide, including TryHackMe, heavily use its compute, storage, databases, networking, and services. This room explains the tools to monitor the AWS cloud environment for threats and provides best practices on auditing AWS activities in by the .
Tip: It is a good idea to create your own AWS account and test each service as you go through the tasks. While this room focuses on the SIEM perspective, seeing how things appear in the AWS console will help you better understand the material. AWS has a free tier that you can try by following the link (opens in new tab). Just be mindful of the costs going beyond the free tier.
Learning Objectives
- Explore control plane, managed services, and workload security
- Practice using and for threat detection
- Learn about cloud log sources, such as and logs
- Gain a broad overview of how to log and monitor AWS as a SOC
Prerequisites
- Complete the Cloud Security Pitfalls room
- Complete the : The Basics room
- Preferably, complete the Introduction to AWS module
- Preferably, complete the SOC Level 1 Analyst path
Lab Access
Start the lab by clicking the Start Lab Machine button below. You will then have access to the Splunk Web Interface. Please wait 4-5 minutes for the Splunk instance to launch. To access Splunk, follow this link:
Set up your virtual environment
Start the lab and continue to the next task!
Ready to learn Cyber Security?
The AWS Security Logging room is only available for Premium or Max subscribers. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.
Already have an account? Log in

