Skip to main content
Back to all walkthroughs
Room Icon

Monitoring AWS Logins

Max room.

Explore AWS authentication, common IAM threats, and SIEM detection options.

medium

60 min

1,193

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

Monitoring the control plane is the first step in securing your cloud environment. And within the control plane, authentication is the first area to focus on: who is logging in to , from where, and which credentials they are using. This room walks you through the most common attacks against AWS identities and the defenses used to protect them.

Learning Objectives

  • Understand the concept of , access keys, roles, and policies
  • Learn how logs different methods of logins in AWS
  • Explore real-world cloud breaches and learn how to avoid them
  • Practice the acquired knowledge in a series of mini-challenges

Prerequisites

Lab Access

Start the lab by clicking the Start Lab Machine button below. You will then have access to the Splunk Web Interface. Please wait 4-5 minutes for the Splunk instance to launch. To access Splunk, follow this link:

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting the Lab Machine, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Lab machine
Status:Off
Answer the questions below

Launch the VM and complete the task!