What you'll gain

🛡️
Break in with proof, not promises

Everyone says cybersecurity has millions of unfilled jobs, so a beginner assumes a cheap certificate is a ticket in. It is not: the shortage is real at the experienced level, while the entry door is crowded — some junior roles draw thousands of near-identical applications. This course is for the person who wants to break in anyway, and it is honest about how. Built from a source-graded 2026 research pass over the SOC analyst role and market, the home-lab build, the core detection skills, the certifications and hiring path, and a dated scam-and-ethics museum, it turns on a handful of hard truths. First, you break in with proof, not promises: a verifiable home SOC lab, documented investigations and detections you built beat a bare exam pass, because hiring managers want to see you can spin up a SIEM, ingest logs and catch a threat. Second — and this is Lesson 1, before any tool is installed — you practise only on systems you own or have written permission to test; your lab must be isolated; in Nigeria, unauthorised access to a computer is a crime under the Cybercrimes Act 2015 (amended 2024), and a single grey-hat act ends a trust-based career for good. Third, the whole job is a loop you practise at home: feed a SIEM real telemetry (Windows Event Logs, Sysmon, Linux and network logs), read normal from suspicious, triage the alert as a true or false positive, map it to the MITRE ATT&CK framework, and write a detection — then tune out the noise. Fourth, the tools are free and fit a modest laptop: VirtualBox, a Wazuh SIEM that runs in 8 GB of RAM, Sysmon, Atomic Red Team, Kali against your own victim VM, and free hosted ranges when your machine is small. Fifth, the market and the money: the ~4.8 million workforce gap is concentrated at the experienced level, so entry is earned, not handed out; one well-chosen certificate (a Security+ for recruiter keywords or a hands-on blue-team cert) plus a portfolio and persistence is the combination that works — collecting every cert is not, and the ISC2 CC is no longer free. You will learn what a SOC analyst does across the three tiers, build the lab, master the Windows event IDs and Sysmon events that matter, the frameworks (ATT&CK, the Cyber Kill Chain, the Pyramid of Pain, the SANS and NIST incident-response lifecycles), alert triage and detection engineering with Sigma, phishing-email analysis, and how to build the portfolio and pass the hands-on interview. Two learners travel with you: Kemi, a Lagos help-desk officer making the classic feeder-role move into a bank SOC, and Uche, a fresh graduate on an 8 GB laptop using hosted ranges and a verifiable portfolio to overcome the remote-hiring trust barrier. The honesty spine is a dated museum of how newcomers get burned — coding-bootcamp job-guarantee actions by U.S. regulators (BloomTech, Career Step), diploma mills, fake recruitment portals, and the North-Korean remote-worker fraud that has hardened identity checks for everyone — with the bright-line rules a serious learner never breaks. Where a figure could not be verified — a Nigerian SOC salary survey, a local bootcamp-fraud case, a foreign remote-pay dataset — the course says so rather than invent it. Orientation and capacity-building, not legal advice; accessing any system you do not own is a crime, and the market is selective, not closed — a first role takes months of hands-on practice and persistence.

🎓
A certificate that proves it

Pass a real exam and earn a publicly verifiable certificate employers trust.

🔁
Practice until it sticks

Unlimited practice mode + spaced-repetition flashcards, then unlimited exam retakes.

♾️
Lifetime access

Keep the lessons and every future update to this course, forever.

What you'll cover

10 modules · 18 lessons · timed certification exam

1. Orientation — the honest map 2 lessons

What a SOC analyst actually does across the three tiers, why the “talent shortage” does not mean easy entry, and the one rule you must accept before you install a single tool.

  • What a SOC analyst does · 18 min
  • The two hard truths · 20 min
2. Build the home lab 2 lessons

Standing up four VMs on one laptop on an isolated network, and choosing the SIEM and the hardware that fit the machine you already own.

  • The lab architecture · 20 min
  • Hardware and the SIEM · 18 min
3. Feed the SIEM — telemetry 2 lessons

The logs that make a SIEM useful: the Windows event IDs and Sysmon events that matter, the Linux and network sources, and why an analyst correlates all three.

  • Windows event logs and Sysmon · 22 min
  • Linux, network and correlation · 16 min
4. Read the logs — normal vs suspicious 1 lessons

The pattern recognition that makes an analyst employable: telling a benign admin action from an attack, in context, rather than memorising event IDs.

  • The analytical judgement · 20 min
5. The frameworks that structure the work 2 lessons

MITRE ATT&CK, the Cyber Kill Chain and the Pyramid of Pain give the work a shared language; the incident-response lifecycle gives it a process.

  • ATT&CK, the Kill Chain and the Pyramid of Pain · 20 min
  • The incident-response lifecycle · 16 min
6. Triage and detection engineering 2 lessons

The two crafts at the heart of the job: deciding whether an alert is a true or false positive, and writing the detections that raise them — portably, with Sigma.

  • Alert triage · 18 min
  • Detection engineering with Sigma · 18 min
7. Two hands-on skills 2 lessons

Phishing-email analysis and the detection-writing loop — the two most portfolio-worthy things you can practise in the home lab.

  • Phishing email analysis · 18 min
  • The lab detection loop · 18 min
8. Certs, portfolio and getting hired 2 lessons

Which certificate to buy first on a budget, why a portfolio beats a stack of certs, and the realistic routes into a first SOC role — locally first, then remote.

  • The certs that matter, budget-first · 20 min
  • The portfolio and getting hired · 18 min
9. The scam, failure and ethics museum 2 lessons

A dated catalogue of how newcomers get burned — training scams, fake jobs and the remote-worker fraud that hardened hiring — and the bright-line rules a serious learner never breaks.

  • Training scams and fake jobs · 20 min
  • The bright lines · 14 min
10. Your 90-day break-in plan 1 lessons

A phased, honest plan to go from zero to a job-ready portfolio in about three months — and a clear-eyed view of how long the search really takes.

  • The phased 90-day plan · 18 min

Frequently asked

Is the certificate verifiable?

Yes. Every certificate carries a unique ID and a cryptographic signature. Anyone — an employer or a client — can confirm it instantly on our public verification page, with no login.

Who teaches this course?

A vetted expert author — Sankofa Skills Studio. Every expert course is reviewed and fact-checked before publication, and the author earns a revenue share on your enrolment.

How long do I have access?

Lifetime. Once you enrol you keep access to the lessons, practice mode and flashcards — including future updates to this course.

What happens if I don't pass the exam first time?

You can retake it — up to 5 attempts, with a 12-hour wait between attempts. Practice mode is unlimited, so rehearse with the same verified question bank until you're ready.

Can my team enrol together?

Yes. Talk to us about group and organisation rates — certifying a whole team is faster and cheaper than one at a time.