Point-in-Time Penetration Testing
Raxis Strike
A fixed window, full depth, a report you can hand to an auditor.
Best when you have an annual audit or a new site to sign off.
Two networks. One name.
From the parking lot, a senior U.S. engineer stands up an access point using your network’s name. A device that never checks the certificate cannot tell the difference, and once it connects, its credentials are ours.
Networks in range
Same name. A device that never checks the certificate cannot tell them apart.
Known nameWPA2 securedAuto-joinCapture log
Evil twin. Creds captured. Critical.
Nothing replaces skill. Illustrative scan, synthetic credential. A trusted name is not a trusted network.
We stand up an access point with your SSID and see which devices, and which credentials, come to it.
Legacy encryption, weak PSKs, and PEAP setups that never check the server certificate.
Guest networks are meant to stay separate. We test whether a misconfiguration lets us cross to production.
We capture WPA handshakes and crack weak passphrases offline, with no lockouts and no noise.
A crafted access point that captures and rewrites legitimate traffic once a device connects.
Printers, IoT, and workstations bridging wireless and wired, quietly joining the two networks.
01
We map the SSIDs, encryption, and access points in range, and the devices talking to them.
02
Evil twins, handshake capture, and deauthentication, run from a distance the way a real attacker would.
03
Captured hashes and handshakes go to our cracking rigs offline, so nothing touches your lockout policy.
04
We prove what the wireless foothold reaches on the internal network, and leave a card where we land.
Passphrases that fall to an offline crack in minutes.
PEAP and EAP setups where devices never check the network’s certificate, the flaw an evil twin lives on.
Unapproved APs, planted or well-meaning, with weaker security than the network they extend.
Guest networks that reach production through a shared switch or a misconfigured VLAN.
WEP and WPA still enabled on a forgotten SSID.
A device on both wireless and wired, bridging an attacker straight past the perimeter.
Raxis Strike
A fixed window, full depth, a report you can hand to an auditor.
Best when you have an annual audit or a new site to sign off.
Raxis Attack
Unlimited manual testing all year, findings live the moment we confirm them.
Best when you add access points and sites through the year.
A concise readout for leadership and auditors.
Each with a severity rating, reproduction steps, and clear remediation.
The whole path, from the SSID in range to the system we reached.
We verify your fixes and deliver a clean final report, at no extra cost.
Our stories are based on real events encountered by Raxis engineers. Some details have been altered or omitted to protect customer identities.
Wireless attackers don’t need to be inside your building, and neither does our team. Sitting in a car in the guest lot, with a large antenna hidden inside it, our pentester got to work.
Using the Aircrack-ng suite to find target SSIDs, he picked the one that looked like the employee network. Then he stood up a rogue access point with Hostapd-wpe, mimicking that SSID, and watched devices connect and hand over their user accounts and NTLM hashes. He fed the hashes to Hashcat, cracked one, and logged in to the real wireless network with the password.
The client had tools that flagged the rogue access point, but by the time the alert surfaced, our pentester was already on the legitimate employee network, looking around. Had their devices been required to check the certificate of the network before joining, none would have connected to our access point in the first place. With the Raxis report in hand, they closed the gap so a real attacker couldn’t do the same.
It is a test of your Wi-Fi and the networks behind it, run the way an attacker outside your building would: surveying the access points in range, attacking their encryption and authentication, standing up rogue access points, and measuring what a wireless foothold can reach on your internal network.
An evil twin is a rogue access point broadcasting the same name as a network your devices already trust. Many devices, especially with enterprise Wi-Fi that never validates the server certificate, will connect automatically and hand over credentials. It is one of the most reliable ways onto a corporate wireless network, and one of the first things we test.
Testing needs an antenna within range of your building, but not necessarily our engineers. We often run wireless engagements remotely through the Raxis Transporter, a small device your team plugs in, which gives our testers the same reach as an onsite visit. When onsite testing fits better, we do that too.
We avoid disruptive techniques by default. Some wireless tests use short, targeted deauthentication to capture a handshake; we scope and time those with you, and password cracking happens offline with no effect on your users. Our goal is to prove risk, not to disrupt your network.
Both, and the boundary between them is often where the risk lives. Guest networks are meant to stay isolated from production; we test whether a misconfiguration lets an attacker cross from the guest SSID to your internal systems.
Most wireless engagements run a few days to a week, including reporting, depending on the number of sites, SSIDs, and whether internal pivoting is in scope. We give you a firm timeline once scope is set.
Senior US-based Raxis engineers holding certifications such as OSCP and OSCE. No outsourcing, and no junior testers learning on your network.