An official reference letter from a SOC Manager, based on 5 years of work as a SOC Consultant, Analyst, and Trainer:



Certificates of Appreciation from EC-Council CyberTalks, awarded to me for sharing valuable insights as a guest speaker during the webinars titled “Deep Packet Inspection Analysis: Examining One Packet Killers” and “How Web Protocol Weaknesses Enable Layer 7 DoS Attacks”, signed by Lata Bavisi, President of EC-Council University:




I have successfully earned the Cyber 5W Certified Digital Forensic Analyst (CCDFA) certification, which is based on a fully hands-on and operational examination process. The certification required the independent execution of a complete forensic investigation, in-depth analysis of digital artifacts, and the preparation of a professional investigative report based on a realistic incident scenario. The examination assessed not only technical forensic skills, but also proper evidence handling in accordance with international standards, analytical reasoning, and the ability to clearly document findings and conclusions in a structured forensic report. The certification process concluded with a mandatory 30-minute final review and evaluation session conducted by the CYBER 5W Examination Committee, during which the report, applied methodologies, analytical reasoning, and final conclusions were thoroughly reviewed and assessed. In addition, I have been included in the Cyber 5W Hall of Fame (https://cyber5w.com/hof/c5w-digital-forensic-analysis-course), which confirms my proficiency in conducting full-scale digital forensic investigations, working with evidentiary material, producing high-quality forensic documentation, and making sound analytical decisions in real-world operational scenarios.

Official recognition from the CyberWarFare Labs Team confirms my exceptional proficiency in bridging offensive and defensive security operations. The Certified Purple Team Analyst certification reflects my ability to conduct comprehensive security assessments, identify vulnerabilities, analyze threats, and respond to incidents in an organized and effective manner by combining offensive and defensive expertise to strengthen organizational resilience. In their feedback, the CyberWarFare Labs Team emphasized that my examination report was completed to an exceptionally high standard and ranks among the best and most comprehensive analyses of offensive and defensive operations they have evaluated.

I have successfully achieved a score of 98% (with Merit) in the Certified Blue Teamer – eXpert (CBTeamerX) examination, demonstrating a high level of proficiency in real-world intrusion investigation and advanced blue team operations. The exam is a fully practical 7-hour assessment focused on analyzing a realistic multi-stage attack scenario across both on-premises Windows Active Directory and cloud environments. It requires strong expertise in correlating diverse data sources such as SIEM logs, Sysmon telemetry, disk images, and malware samples, while reconstructing the full attack chain from initial compromise to final impact. Achieving 15 correct answers out of 16 questions reflects solid capabilities in areas including disk forensics, malware analysis, log correlation, and cloud security investigation, including a ransomware scenario that required reverse engineering the executable, identifying key elements within the code, extracting additional data from the disk image, combining these findings to reconstruct the decryption logic, and successfully recovering an encrypted file.

Official recognition from the CyberWarFare Labs Team highlights my exceptional performance in incident investigation and analysis. This acknowledgment underscores my ability to effectively utilize methodologies and tools to identify, assess, and respond to security incidents. My skill in connecting the dots, analyzing complex scenarios, and delivering actionable insights demonstrates a deep understanding of the subject matter. This commendation reflects my aptitude in cybersecurity and my potential to achieve even greater success in this field.


Official recognition from CyberDefenders highlights my exceptional performance in a comprehensive cybersecurity certification exam, showcasing my expertise across multiple domains, including Network Forensics, Disk Forensics, Memory Forensics, Perimeter Defense, and Threat Hunting. Achieving sub-scores of 90.0% in Network Forensics, 95.0% in Disk Forensics, 100.0% in Memory Forensics, 95.0% in Perimeter Defense, and 90.3% in Threat Hunting contributed to an impressive overall score of 92.66%. This accomplishment reflects my well-rounded proficiency and deep understanding of these critical areas, underscoring my ability to excel in the field of cybersecurity.


Official recognition from the Hack The Box (HTB) team highlights my successful attainment of the Certified Defensive Security Analyst (CDSA) certification. This achievement reflects my ability to effectively detect and document adversarial activity in a structured, methodical manner. The examiner specifically commended the clarity, structure, and ease of understanding in my detection report, underscoring my capability to produce well-organized and actionable documentation in a real-world defensive context. This recognition affirms my proficiency in threat detection, incident reporting, and strengthens my competencies in defensive operations and defensive cybersecurity incident analysis.


Official recognition from the Hack The Box (HTB) team confirms my successful attainment of the Certified Penetration Testing Specialist (CPTS) certification. This accomplishment reflects my ability to perform structured penetration testing, accurately document vulnerabilities, and deliver clear and professional reporting. The examiner highlighted the strong quality of my report, noting the precise descriptions of each vulnerability, the well articulated impact, and the actionable yet neutral remediation recommendations in line with the independence expected from third party pentesters. The clarity, structure, and professional presentation of the report were specifically commended. This recognition affirms my growing proficiency in offensive security, vulnerability assessment, and delivering high quality technical documentation for real world engagements.


Official recognition from the CyberWarFare Labs Team confirms my advanced expertise in offensive security operations and professional Red Team reporting. The Certified Red Team Specialist certification reflects my ability to conduct realistic adversary simulations within complex, multi-segmented enterprise environments, apply advanced exploitation techniques across Active Directory, certificate services, and authentication infrastructures, and execute the full Red Team lifecycle aligned with the MITRE ATT&CK framework and real-world TTPs used in critical infrastructure environments. In their feedback, the team emphasized that my submission was exceptionally well-prepared and that the overall quality of the report was truly commendable. This recognition validates technical depth, operational maturity, and the ability to deliver structured, high-quality Red Team documentation under realistic enterprise conditions.

Official recognition from the CyberWarFare Labs Team confirms the strong quality of the penetration testing report I prepared as part of the Certified Cyber Security Engineer (CCSE) certification. The certification demonstrates my proficiency in advanced penetration testing, exploitation techniques, and real-world cybersecurity operations across diverse environments.

GNFA Certification Achievement Announcement issued by GIAC Certifications, confirming that Michał Sołtysik has successfully earned the GIAC Network Forensic Analyst (GNFA) certification. The announcement highlights Michał’s accomplishment as part of a celebratory post recognizing newly certified cybersecurity professionals and includes a personal reflection on the demanding, hands-on path leading to the successful completion of this advanced forensic exam.


WCNA Certification™ Welcome Letter issued by Laura Chappell, Founder of Protocol Analysis Institute, Inc., confirming that Michał Sołtysik achieved the WCNA Certification™ (formerly known as Wireshark Certified Network Analyst™) on October 25, 2023, with the exam taken at a proctored testing center.

Official acknowledgement from Didier Stevens (Microsoft Most Valuable Professional and Senior Handler at SANS Internet Storm Center) and Dr. Johannes Ullrich (the Dean of Research for SANS Technology Institute, a SANS Faculty Fellow, founder of the Internet Storm Center – DShield.org, the winner of Best Security Podcast in 2014, the winner of Best Technical Security Blog in 2009 and 2010, recognized as one of the Top 50 Most Powerful People in Networking by Network World Magazine and one of the Top 5 Influential Security Thinkers by SC Magazine, the recipient of the ISSA’s 2018 President’s Award for Public Service and awarded a number of research grants by NASA and the Department of Energy) of my contribution in solving the mystery behind the “MGLNDD_*_*”.