Skip to main content
Back to all walkthroughs
Room Icon

AWS Security Logging

Max room.

Dive into various AWS log sources and learn how they can help your SOC team.

medium

60 min

1,487

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

Amazon Web Services () is one of the most used cloud providers, and many companies worldwide, including TryHackMe, heavily use its compute, storage, databases, networking, and services. This room explains the tools to monitor the AWS cloud environment for threats and provides best practices on auditing AWS activities in by the .

Tip: It is a good idea to create your own AWS account and test each service as you go through the tasks. While this room focuses on the SIEM perspective, seeing how things appear in the AWS console will help you better understand the material. AWS has a free tier that you can try by following the link (opens in new tab). Just be mindful of the costs going beyond the free tier.

Learning Objectives

  • Explore control plane, managed services, and workload security
  • Practice using and for threat detection
  • Learn about cloud log sources, such as and logs
  • Gain a broad overview of how to log and monitor AWS as a SOC

Prerequisites

Lab Access

Start the lab by clicking the Start Lab Machine button below. You will then have access to the Splunk Web Interface. Please wait 4-5 minutes for the Splunk instance to launch. To access Splunk, follow this link:

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting the Lab Machine, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Lab machine
Status:Off
Answer the questions below

Start the lab and continue to the next task!