Penetration testing of
wireless networks
Wi-Fi is the only part of your infrastructure someone can walk up to from the car park. We check whether it can be entered without credentials, whether the guest network is genuinely separated, and whether employee laptops obediently connect to an access point we set up outside the building.
- WPA2 and WPA3, both Personal and Enterprise
- Verification of guest network and personal device isolation
- Client device testing, not just access points
Wireless networks
- OSSTMM (wireless section)
- PTES
- NIST SP 800-153
- MITRE ATT&CK
What exactly we check
We tailor the scope to your environment, but these areas are always covered.
Authentication and encryption
WPA2 and WPA3 configuration, EAP methods in the Enterprise variant, RADIUS server certificate validation on the client side, key quality in the Personal variant, support for older and weaker modes.
Evil Twin and impersonation
An access point using the same network name, attempts to capture domain credentials, a captive portal imitating the login page, forcing a downgrade to a weaker authentication method.
Network isolation
Whether corporate resources are reachable from the guest network, whether devices on the same network can see each other, how personal phones and IoT devices are treated.
Client devices
Preferred network lists broadcast by laptops and phones, automatic connection to open networks with a known name, KARMA-style attacks, behaviour after losing signal.
Access points and controllers
Management panels and default credentials, firmware currency, active WPS, management reachable from the user network, broadcast and transmit power configuration.
Coverage and physical layer
Measuring coverage outside the building and beyond the controlled area, detecting rogue access points connected to the corporate network, resistance to deauthentication and jamming.
What we find most often
Examples from our projects in this area. Client names and technical details stay in the reports.
- A corporate Wi-Fi key crackable within a few hours
- Clients accepting any RADIUS server certificate, allowing domain credentials to be captured
- A guest network with access to internal servers
- No client isolation: guest devices can see each other
- The same key in use for years, known to former employees and contractors
- An access point with the default administrator password
- Active WPS allowing authentication to be bypassed
- Corporate network coverage reaching the car park and the neighbouring building
Selected tools
Tools take care of the repetitive work. The conclusions and attack chains are built by hand.
How the test runs and what you get
The testing process, the report format and the retest rules are the same across every scope.
See the full process and report contentsFrequently asked questions
Do you have to be on site?
Yes, this scope requires being within range of the network. One or two days on location is usually enough. The rest of the work, including controlled cracking of captured hashes, is done remotely.
Will the test disrupt our Wi-Fi?
Most of the work is passive. Tests that can briefly disconnect devices, such as deauthentication, are run in an agreed window and against a limited set of devices.
Do you capture employee passwords?
In the Evil Twin scenario we capture credential hashes to prove the attack works. We do not recover passwords beyond what is needed to demonstrate the vulnerability, and the captured material is deleted when the project closes. That rule is written into the contract.
Do you test multiple locations?
Yes. For a distributed network we usually propose a full test at headquarters and a shorter review at selected branches, because configuration tends to be copied and the same mistakes repeat everywhere.
Other testing scopes
We combine scopes into a single project whenever that works better for your environment.
Web applications and APIs
We detect vulnerabilities from the OWASP Top 10 (including SQL Injection, XSS, SSRF, BOLA). We audit customer portals, e-commerce systems, CRMs and complex environments based on microservices and APIs (REST, GraphQL).
View scopeMobile applications
Reverse engineering of iOS and Android applications (including Flutter and React Native). We verify secure on-device data storage, correct server communication and flaws in authorization logic.
View scopeInternal infrastructure
We simulate an attack, for example from the perspective of a malicious employee or a compromised workstation. We examine network segmentation (VLAN), Active Directory, file servers and password policies.
View scopeExternal infrastructure
We attack internet-facing systems and services. We verify firewall configurations, VPN server vulnerabilities, outdated software versions and DNS misconfigurations.
View scopeCloud environments
We verify the security of resources in AWS, Azure and Google Cloud Platform. We focus on IAM permission errors, storage bucket (S3) leaks and Serverless vulnerabilities.
View scope