WIRELESS PENETRATION TESTING

An attacker doesn’t need to be inside to be on your network.

Your corporate Wi-Fi reaches past your walls, into the car park, the lobby, the building next door. From there, an attacker can clone it, capture a staff login, or pivot from your guest network into the corporate one. We attack your wireless the way someone parked outside would.

How a wireless pentest works
87%
of our clients renew annually
150+
organisations across multiple European countries
7/10
confirm findings their previous provider did not find
Want to know what your Wi-Fi actually exposes? Share your main concern and your email.

Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.

Trusted by network and security teams in highly regulated environments

Discover exactly how the car park becomes a foothold.

wifi pentest demo
TARGET · ACCESS TO THE INTERNAL VLAN
PHASE 01 OF 05
RADIO RECONNAISSANCE
airodump-ng wlan0mon CH 1 · 6 · 11 · 44 · 153 ESCANEANDO
BSSIDPWRBCNCHENCESSID
AC:84:C6:11:8F:21 -42 507 44WPA2-Ent CORP-WIFI
AC:84:C6:11:8F:22 -51 391 1WPA2-PSK CORP-GUEST
AC:84:C6:11:8F:23 -66 220 6WPA2-PSK CORP-IOT
00:1B:21:7C:3E:55 -63 188 11OPN ACME-PRINTERS
F0:9F:C2:2A:11:80 -71 102 153WPA3 OfficeBuild-3
site survey · acme-hq · planta 3 2,4 / 5 / 6 GHz
kismet · passive scan wlan0mon · no Tx
00:00:04BEACON CORP-WIFI · −42 dBm · WPA2/AES · PMF off
00:00:09PROBE client 78:4F:43:91:2C:0A → CORP-WIFI
00:00:12BEACON CORP-GUEST · captive · PSK · 802.11n
00:00:15BEACON ACME-PRINTERS · OPEN · model HP-LJ
00:00:18WPS branch-AP · WPS PIN config enabled
00:00:22PROBE 6 hidden SSIDs · vendor Cisco-Meraki
SCAN SUMMARY 6 SSID · 4 AP · 22 clients · controller identified (Cisco WLC)

Radio does not respect your reception desk. If your Wi-Fi is reachable from the car park, so is your attack surface, and the attacker can take their time, unseen, from a laptop in a parked car.

The classic wireless attack is simple to picture. An attacker stands up a fake copy of your corporate Wi-Fi. A staff laptop, if it does not properly check it is talking to the real Wi-Fi server, connects and hands over a domain login. We prove each step your network team can reproduce.

WHAT WE TEST
  • Whether your Wi-Fi can be cloned (Evil Twin and rogue access points)
  • How Wi-Fi logins are checked (802.1X, WPA2-Enterprise, WPA3, RADIUS / NPS)
  • Whether a staff login can be captured (handshake, server certificate)
  • Whether guest and device networks are isolated (segmentation, VLAN hopping)
  • The guest sign-in experience (captive portals and their bypasses)
  • Legacy and convenience features (WPS, weak pre-shared keys)
  • The management layer (controller and access-point admin interfaces)
  • Whether Wi-Fi leads inside (pivot from wireless into the internal network)

Why a CTO, CISO or network lead books a wireless pentest.

A wireless pentesting is normally a rogue access point found in the office, a new site, a PCI DSS wireless requirement, a controller upgrade, or a near-miss in a branch forces the question.

TAP A SITUATION
Suspected exposure Rogue AP detected in the office

Something looked off on the radio. You need to know what is still exposed.

The question is not ‘do we have findings’ but ‘are there other paths’. We focus the engagement on the suspected exposure, confirm it is closed, and surface every adjacent path an attacker could take.

  • Targeted scope around the suspected exposure
  • Adjacent paths mapped: SSIDs, 802.1X, isolation, controller, IoT
  • Reproducible proofs of concept for the incident-response team
  • Live findings to your responders, not the final report
Compliance & audit PCI DSS 4.0 wireless requirements

An auditor does not accept a configuration screenshot.

With PCI DSS 4.0 wireless requirements, DORA or NIS2 connectivity evidence or SOC 2 network controls on the line, the report has to survive scrutiny: traceable scope, a recognised methodology and signed retest evidence.

  • Methodology mapped to PTES, NIST SP 800‑115 and recognised wireless testing guidance
  • Separation between guest, device and corporate networks tested and documented
  • Execution certificate ready for the auditor folder
  • Retest evidence with timestamps, the controller configuration pinned, and signoff
Board & customer Enterprise customer demanded proof

Someone with authority asked, and ‘we’re fine’ isn’t an answer.

When the ask is for assurance, you need an external, expert-led wireless pentest and a deliverable that turns what reaches past your walls into business impact, in language a non-technical stakeholder can read.

  • Executive summary that lands without translation
  • Findings ranked by business impact and audit exposure
  • The path from outside the building to an internal system, proven step by step
  • Independence: external and expert-led throughout
Change / rollout New office or site

A new wireless surface just went live. Test it from the car park.

Every rollout changes what reaches past your walls and what it can reach back. We test on site the way someone parked outside would: the SSIDs, the way logins are checked, and the walls to the corporate network.

  • Scope tuned to the rollout, tested on site rather than from a configuration export
  • Server-certificate validation on 802.1X checked on the client devices you deploy
  • Guest and device isolation tested by attempting the crossing into corporate
  • Retest after the fix, so the rollout closes with the paths closed
By environment Healthcare clinical wireless

The environment decides the threat model, so the test follows the site.

Each site fails differently. We test yours where it lives, and where the inventory is incomplete we start by finding what is actually broadcasting before testing what it reaches.

  • Survey first: every broadcasting access point found, not only the ones on the list
  • Guest, device and corporate separation tested by attempting the crossing
  • Client devices tested as deployed, handhelds and fixed equipment included
  • Findings tied to network owners, with steps your team can reproduce on site

Ready to see what your Wi-Fi actually opens up?

Book a call
Thirty minutes with an experienced pentester.

A seven-phase method, for your wireless security pentesting.

Seven steps, run on site by the same operator you meet on the first call. What we do, in the order we do it.

What you actually get, and why it is different.

Most wireless reviews check the controller settings and stop. Here is where we go further.

On-site, by hand, against your real Wi-Fi

A senior specialist tests on your premises against your actual access points, SSIDs and controllers. No config-only review, no false positives, only what genuinely works over the air.

From the car park to internal data

We model the real worst case: Evil Twin, 802.1X bypass, captive-portal harvest, segmentation breach and the pivot from guest Wi-Fi to internal systems. You get proof of reach, not theory.

Mapped to the standard your auditor accepts

Every finding maps to PTES, NIST SP 800‑115 and the PCI DSS 4.0 wireless requirements, the evidence your auditors and enterprise customers actually ask for.

Multi-site retest

Optional multi-site mode: after a controller, RADIUS or SSID change, we re-test the diff against the same configuration to confirm closure and catch anything the change introduced.

Want to see what your next wireless pentest with us would look like?

We at Etnia highly value our collaboration with Asperis Security.
Sergi Leno, Systems Manager · ETNIA Barcelona

Loved by engineering and security teams.

Names, roles and companies on the record.

We at Etnia highly value our collaboration with Asperis Security. Their professionalism, approachability, quick response and ability to adapt to our needs have been key in every project. The quality of service and continuous support always give us peace of mind. Without a doubt, it is a pleasure to have them as technology partners.
Sergi Leno, Systems Manager
ETNIA Barcelona
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives. Thanks to their advice, we took the strategic step of completing our Microsoft ecosystem and reinforcing it with CrowdStrike for advanced mobile device protection, significantly raising our security level.
Jordi Bondia, IT Director
SALVI
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive. We especially value their ability to adapt to our needs and the depth with which they approach each project. Results are clear, structured and useful for decision-making and continuous security improvement. We like working with Asperis for the judgment and value they bring to every collaboration. Their work has helped us strengthen our security level.
Sergi Laencina Verdaguer, CISO
NPAW
With Asperis you don’t hire a service. You hire a partner. They don’t look to bill a project. They look to establish a relationship of trust, caring about the key points that affect your organisation’s security. Professionalism, know-how and diligence.
Juan Valer Tecedor, Software Engineer
GNOSS
READY WHEN YOU ARE

Want a real Wireless Pentesting scope?

Tell us your sites, your SSIDs and whether guest and corporate share hardware. An experienced consultant will reply.

Questions that come up before signing.

Wireless penetration testing is a manual security assessment of your Wi-Fi networks, performed on-site from the position of an attacker within radio range but outside your building. It checks whether your corporate Wi-Fi can be cloned, whether staff logins can be captured, whether guest and device networks are truly isolated, and whether a foothold on Wi-Fi leads into your internal network. The deliverable is a set of proven attack paths, ranked by business impact, each with a reproducible proof of concept.

No. A configuration review checks whether your controller and access-point settings match a standard or vendor best practice. A wireless pentest proves what an attacker actually achieves over the air: standing up an Evil Twin, capturing a domain login because a device does not verify the server certificate, or reaching an internal system from the guest network. A clean configuration and an exploitable network can coexist, which is why regulated multi-site estates run both, the review on the controller release cycle and the pentest against sites and segmentation.

An Evil Twin is a fake copy of a trusted Wi-Fi network, stood up by an attacker to trick devices into connecting to it instead of the real one. When a staff device connects, if it does not properly verify it is talking to the genuine Wi-Fi login server, it can hand over the user’s credentials. It is one of the most common and damaging wireless attacks because it needs no access to your network, only proximity, and we test your resistance to it directly.

Yes, at least in part, and that is by design. Wi-Fi is a radio medium, so an attacker has to be within range and so do we; a genuine wireless test means a specialist physically present at your site, with proper equipment across the 2.4, 5 and 6 GHz bands. Some preparation and reporting happen remotely, but the testing itself is on-site. For estates with many locations we agree a representative sample of sites during scoping rather than visiting every one, which keeps the engagement proportionate.

No, not without your consent. We work under documented Rules of Engagement, agreed windows and no-impact criteria, and our default posture is passive listening plus targeted, controlled tests rather than anything that floods the spectrum or disrupts users. Techniques that could affect availability are only used with prior approval and your team informed. We test on your real network without taking it down.

A single site typically takes a few days of on-site testing plus scoping and the retest; multiple sites, or a complex controller and segmentation setup, run one to two weeks. Travel and site access shape the schedule, so we plan it with you. We confirm the timeline in the proposal, delivered within 48 hours of the first call.

Price follows the number of sites, the number of SSIDs and the complexity of your authentication and segmentation. We quote a fixed price with no hidden fees and no obligation to renew. A single-site assessment sits at the bottom of the range; multi-site estates scale from there, with travel agreed up front. The retest that confirms your fixes is always included.

Grey box fits most engagements: you tell us your SSIDs and segmentation design, so we spend the time testing rather than discovering the basics. Black box mirrors a stranger in the car park with no prior knowledge, best for an honest exposure baseline. White box adds controller and RADIUS configuration for the deepest review. We work out which one fits you on the introductory meeting.

The senior specialist you meet on the first call runs it on-site, end to end. Our team holds OSCP, OSCE³, OSWE and OSEP credentials, works by hand with proper wireless equipment across 2.4, 5 and 6 GHz, and we are NASA Bug Bounty verified contributors. The same person scopes, executes and retests. That person is your point of contact throughout.

Ready to test what your network reaches?

Start with a no-obligation introductory meeting. We will review your sites, your SSIDs, your authentication and your segmentation, and define the right wireless pentest before the project begins.

Request a wireless pentest proposal.
An experienced wireless pentester replies within one business day. You talk to the person who runs the test.

Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.

Or email [email protected] directly.

OUR CLIENTS HAVE ALREADY DONE IT

We at Etnia highly value our collaboration with Asperis Security.

Sergi Leno, Systems Manager
ETNIA Barcelona

ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives.

Jordi Bondia, IT Director
SALVI

At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive.

Sergi Laencina Verdaguer, CISO
NPAW

With Asperis you don’t hire a service. You hire a partner.