A ten-week certificate course in Tier 1 security operations, taught on a real SIEM inside Greyfern Security Operations, a fictional managed SOC with two clients: Tamarind Pay, a Lagos fintech, and Brasswick Manufacturing in Denver. Twelve alert classes with runbooks, 60 scripted incidents, the auto-closure sample every shift, the SIEM outage drill, and the ticket that carries what you do not know yet. Every lesson maps to CompTIA Security+ SY0-701 objectives. Two lanes chosen at enrolment: the Lagos SOC market, or the US market for work-authorised residents.
Start: October 12, 2026 · 11 AM WAT (Nigeria).
Fee: ₦200,000 for this track, or two ₦100,000 installments with the balance due three weeks later.
Format: Ten weeks: eight of lessons, assignments and one live class a week, then two practicum weeks of timed shifts on the track's job simulator. Your track’s live-session day and time are confirmed at enrolment.
The SOC, its tiers and its clients; the shift, the queue and the log; the analyst's line; the ticket someone else can act on; the tools of the desk; severity and priority; the two lanes.
The CIA triad; threat actors in outline; attack surfaces; the kill chain and MITRE ATT&CK; phishing, malware, brute force, web attacks, MFA fatigue and cloud misconfigurations as they appear in the logs.
Addresses, ports and DNS; HTTP and TLS in outline; the endpoint agent and the process tree; Windows event ids and Linux auth logs; the identity provider; service accounts; reading, never configuring.
What a SIEM is and is not; Wazuh from the console; searching and pivoting; saved searches; the second client in Elastic; reading a detection rule and its Sigma rule; noise, tuning and the auto-closure sample.
The four verdicts; the runbook in order; evidence and the chain; the phishing wave; the brute force that is a service account; the AI verdict you validate; the ticket; time to triage; escalations that bounce.
Incident response in outline; containment requested, never executed; the ransomware precursor; the manager who wants a ticket closed; the executive who wants a name; the SIEM outage drill; the six-hour miss reported as it is.
Least privilege and your own access; vulnerability findings as tickets and CVSS read not computed; CBN and the NDPA named for the Lagos SOC, CMMC, NIST 800-171 and SOC 2 named for the US client; evidence never leaves the environment; the analyst as a target.
The handover and the weekly report; metrics read honestly; the portfolio of simulator work; Security+ SY0-701 and confirming the live exam code before you book; the two markets honestly; interview questions answered with your own tickets; the capstone.
Timed shifts on Greyfern with alerts arriving at realistic rates on both clients, the auto-closure sample every shift, and every ticket graded on its evidence chain and its open questions.
More shifts including the SIEM outage drill, the six-hour miss reported as it is, the request you must refuse, and a tutor-marked capstone. Passing needs zero critical errors.
Plan for a computer, headset, reliable internet, a quiet practice space, and time for assignments. Review the student handbook for assessment, access, and policy details before payment.
Issued by SchoolRegistry Academy when the track’s assessment requirements are met. It is not third-party accreditation and does not promise job placement.
Questions: hello@schoolregistry.ng
Use Print → Save as PDF for a PDF copy. Course guide · September 2026.