Hunt in the Cloud with Splunk
Investigate AWS security threats hands-on with Splunk
Beginner
Lab duration
30-60 minutes
Overview
We created this beginner-friendly lab to give hands-on experience with using Splunk to investigate security threats in AWS.
Objectives
In a large logistics company that leverages AWS for its global operations, the IT department has noticed a concerning trend of service outages. They have asked you to investigate this trend using the recent AWS CloudTrail logs and Splunk. Your mission is to identify if their are any unusual activities or anomalies that could be causing this.
Prerequisites
- Basic experience with log analysis
Learning outcomes
- Using Splunk to piece together a timeline of events in a breach
Real-world context
Splunk is a widely used and powerful tool that allows defenders to accurately tell the story of what happened in a compromise or security incident.