How an external network pentest works
The real sequence of an external network penetration test: scope and rules of engagement, reconnaissance, perimeter analysis, exploitation, reporting and retest, plus what the test will not cover.
A wireless pentest is the one engagement where the attacker needs no credentials, no link and no invitation into your building. This is the sequence we run, in order, and what lands on your desk at the end.
Every other test in this series starts with something you hand over: a URL, a cloud account, a binary. A wireless pentest starts with what your building broadcasts. Radio does not stop at the wall, so the first attacker in the queue is someone in the car park.
So it runs on site, across the 2.4, 5 and 6 GHz bands, answering three questions in order: what can be seen from outside, what can be joined, and where joining leads. The third turns a Wi-Fi finding into a business finding.
A "dual connected" client sits on a wired network and a wireless LAN at once, and the risk NIST names is that an attacker who gains wireless access to that client then uses it to attack resources on the wired network (NIST SP 800-153). Wireless is rarely the prize. It is the door.
Nothing is switched on until the paperwork is right. The rules of engagement for a wireless test carry constraints the other disciplines never meet, because the medium is shared with people who are not your staff.
Two of those are published guidance, not house style. NIST tells assessors not to scan devices owned by neighbouring organisations within range, and to focus on identifying and locating potential rogue devices rather than actively scanning them. It adds that the detection system’s administrators may need warning of pending scanning, so they are ready for the alarms (NIST SP 800-115, section 4.4.2).
Grey box is the normal starting position: you give us the SSIDs and the sites, we get no corporate credentials.
Reconnaissance here is genuinely passive to begin with. Passive scanning tools transmit no data and do not affect the operation of the deployed devices (NIST SP 800-115, section 4.4.1), so the opening hours cannot break anything. That pass produces:
Then we pick the routes worth the time. An industrial unit on WPA3-Enterprise with no guest network is not a shared office block with an open events SSID left up since 2023.
This is where the engagement stops resembling a network test. It splits by what your SSIDs run.
The question is how cheaply the key comes off, and since 2018 that has not needed a four-way handshake at all. The PMKID attack lifts the PMKID from the RSN information element of a single EAPOL frame, needing neither a full capture nor a client to connect; its author expected it to work against 802.11i/p/q/r networks with roaming enabled (hashcat, August 2018).
The target is the trust decision the client makes, not the key. NIST is blunt: an attacker can easily defeat weak authentication methods by setting up a rogue access point, which is why the guidance is to use EAP-TLS whenever possible (NIST SP 800-97). Where certificates authenticate only the authentication server, the client needs a copy of that certificate to authenticate it. If your devices do not check it, a look-alike access point collects the exchange and your PKI never gets a say.
Captive portals and controller consoles are web applications, tested against the OWASP Web Security Testing Guide. Firmware counts too: CVE-2023-25717, affecting Ruckus ZoneDirector, SmartZone and Solo access points, sits in the CISA KEV catalogue, added on 12 May 2023. And where WPS survives, a design flaw cuts the PIN search space from 108 to about 11,000 attempts: the access point reveals whether the first half is right, and the last digit is a checksum (CERT/CC VU#723755).
Findings are only findings once proven, inside the limits agreed in phase one. What earns its place most often:
Protocol flaws get named precisely. CVE-2017-13077 allows reinstallation of the pairwise transient key temporal key during the four-way handshake, so an attacker within radio range can replay, decrypt or spoof frames; NVD scores it 6.8 on CVSS v3.0. CVE-2019-9494 affected SAE in hostapd and wpa_supplicant up to version 2.7, where timing differences and cache access patterns leaked enough for full password recovery. Vendor updates exist for both, and both are still live in estates whose access points were never updated.
Then we follow it. A credential captured over the air is worth reporting; the same credential used for lateral movement into a file server is worth fixing this quarter.
The deliverable has to work for two audiences who read nothing alike.
For an audit folder, traceability matters as much as the findings: scope, method, dates and signed retest evidence. That expectation is converging across frameworks.
Then the retest, which wireless needs more than most. A fix here is usually one controller or RADIUS change that has to propagate to every access point and client profile, and propagation is where fixes fail quietly: one site on an older firmware branch, one SSID missing from the profile. Nothing in the console says so.
A single site is typically a few days of on-site testing, plus scoping before and the retest after. Multiple sites, or a complex controller and segmentation setup, run one to two weeks. The range moves with the number of sites and the distance between them, the number of SSIDs and distinct configurations behind them, whether 802.1X is in play, and how complete the inventory is on day one.
On cadence rather than duration, NIST recommends a technical wireless LAN security assessment at least annually, plus periodic assessments at least quarterly unless continuous monitoring already collects everything those assessments would produce (NIST SP 800-153, section 3.4).
Four documents give the engagement its spine, named in the report so an auditor can follow the shape. PTES for the structure: seven sections running from pre-engagement interactions through intelligence gathering, threat modelling, vulnerability analysis, exploitation and post-exploitation to reporting. NIST SP 800-115 for the method: four phases, planning, discovery, attack and reporting, with the wireless scanning guidance quoted throughout this article in its section 4.4. NIST SP 800-97 for how 802.11 authentication should be chosen. OWASP WSTG v4.2 covers the portal and controller interfaces, and MITRE ATT&CK names the techniques.
If any of this looks like a problem you are carrying, half an hour on a call scoping it with a senior pentester is worth more than reading another article.
Hablar con un pentester seniorPick a time that suits you. You tell us what you need and where you are, and we explain how we work and how we can help.