Skip to content
Service 15

Wireless Penetration Testing

Testing of your Wi-Fi estate the way a nearby attacker would: join, intercept, and see how far a wireless foothold actually goes.

In range is in scope

A wireless network is a perimeter you cannot put a fence around. Anyone in the lot, the lobby, or the office next door can see it, and a surprising number of the controls people trust on that perimeter — a pre-shared key, a MAC whitelist, a hidden SSID — do not do what the policy says they do.

We test that estate from the position of someone who is close, not someone who already has a port. The question is whether they can join, whether they can listen, and whether that foothold is a dead end or a path into the rest of the network.

What we test

Association and encryption. Which SSIDs are reachable, how they authenticate, and whether the secret that protects them would survive a determined neighbour.

Controls that look like locks. MAC filtering, hidden networks, captive portals, client isolation. We have walked past a MAC whitelist in minutes on a live engagement — the address is broadcast, and copying it is not a feat. That write-up is MAC Address Whitelisting Failure.

Rogue and evil-twin conditions. Whether a lookalike access point would be noticed, and what a client would hand it.

What the foothold is worth. Getting on the WLAN is the opening. The finding is what that position can reach — a file share, a management interface, a path that belongs on an internal network penetration test.

What this is not

It is not IoT penetration testing. Device radios, firmware, and companion apps are a different engagement.

It is not a promise that we will “audit the controller config” and leave. A configuration dump is useful homework. This is a test of whether the air, as deployed, holds.

What you receive

A report of which networks we could join, which controls failed, and what that position was worth inside the estate — with the change that closes each path. We retest once you have remediated, the same as any other penetration test.

Common questions

Wireless Penetration Testing — what clients ask

Is this just cracking the guest network password?
Guest PSK is one check, and it is often the least interesting one. The engagement is about what a nearby attacker can actually do: join a network they should not, sit between a client and an access point, bypass a control that looks like a lock (MAC filtering is the usual example), and see whether that foothold reaches anything that matters. A password that falls in an hour is a finding. A password that falls and leads nowhere is a different finding.
Do you have to be on site?
For the wireless piece, yes — or close enough that the radios you care about are in range. We agree sites, hours, and which SSIDs are in scope before anyone sits in the car park. Once a foothold exists, the internal follow-through can look like an [internal network test](/services/network-penetration-testing/), and we will tell you if that work should be scoped as its own engagement.
How is this different from IoT or network testing?
[IoT testing](/services/iot-penetration-testing/) is the radio and firmware of a product — BLE, Zigbee, a UART header, the cloud the device phones home to. This engagement is the corporate Wi-Fi estate: SSIDs, encryption, client isolation, rogue access points, and the path from a parking-lot association to an internal resource. Network testing assumes you are already on the wire. Wireless testing is how an attacker gets there without a badge and without a VPN.

Strengthen your defenses.

Tell us what you need tested. We’ll come back with scope, timeline, and a fixed price.

Request a quote