Need your AWS lab account? Go to the self-service login →
AWS Partner
Varonis Systems · Proprietary & Confidential

Extra Challenges

Finished early? These deepen the investigation muscle.

E1 Suspicious activity

  1. Investigation → Activities, filter AWS.
  2. Find the failed logins and failing queries.
  3. Find an AssumeRole event; use the Session link to see the real actor.

E2 Effective permissions for a user

  1. Pick any AWS user; Access Review → New Report, Type=File, Tags=sensitive.
  2. Open Access Graph, Permission Source, Permission Summary.
Staleness needs time
Stale users / keys / policies require 90–180 days, so they won't appear in a fresh account. On real environments these are often the biggest wins.