Wireless Penetration Testing

Two networks. One name.

From the parking lot, a senior U.S. engineer stands up an access point using your network’s name. A device that never checks the certificate cannot tell the difference, and once it connects, its credentials are ours.

Networks in range

  • ACME-Corp
  • ACME-Guest
  • ACME-Corp Rogue AP

Same name. A device that never checks the certificate cannot tell them apart.

Known nameWPA2 securedAuto-join

Capture log

Client joined
ACME-Corp (rogue)
Captured
MSCHAPv2 · jdoe
Cracked
Summer2026!
Reached
Employee Wi-Fi

Evil twin. Creds captured. Critical.

  • Known name What the device checks
  • Rogue AP Our access point, its name

Nothing replaces skill. Illustrative scan, synthetic credential. A trusted name is not a trusted network.

What We Test

Wireless is the one attack surface that leaves your building. We work it from where an attacker would actually sit, with one goal: reach the network behind it.

Evil Twin & Rogue APs

We stand up an access point with your SSID and see which devices, and which credentials, come to it.

Encryption & Auth Weaknesses

Legacy encryption, weak PSKs, and PEAP setups that never check the server certificate.

Guest-to-Corp Traversal

Guest networks are meant to stay separate. We test whether a misconfiguration lets us cross to production.

Handshake Capture & Cracking

We capture WPA handshakes and crack weak passphrases offline, with no lockouts and no noise.

Man-in-the-Middle

A crafted access point that captures and rewrites legitimate traffic once a device connects.

Dual-Homed Devices

Printers, IoT, and workstations bridging wireless and wired, quietly joining the two networks.

How We Test

Wireless is a low-risk, high-reward target: an attacker can work from far off with a high-gain antenna and little chance of being noticed. We work the same way.

01

Survey

We map the SSIDs, encryption, and access points in range, and the devices talking to them.

02

Attack

Evil twins, handshake capture, and deauthentication, run from a distance the way a real attacker would.

03

Crack

Captured hashes and handshakes go to our cracking rigs offline, so nothing touches your lockout policy.

04

Pivot

We prove what the wireless foothold reaches on the internal network, and leave a card where we land.

Findings We See in the Wild

What we find parked outside, most engagements.

Weak Pre-Shared Keys

Passphrases that fall to an offline crack in minutes.

No Server Validation

PEAP and EAP setups where devices never check the network’s certificate, the flaw an evil twin lives on.

Rogue Access Points

Unapproved APs, planted or well-meaning, with weaker security than the network they extend.

Guest-to-Corp Bridges

Guest networks that reach production through a shared switch or a misconfigured VLAN.

Legacy Encryption

WEP and WPA still enabled on a forgotten SSID.

Dual-Homed Devices

A device on both wireless and wired, bridging an attacker straight past the perimeter.

On Site or Remote, Through the Transporter

Wireless testing needs an antenna near your building, but it does not always need us there. The plug-and-play Raxis Transporter, built in-house, lets our engineers run a wireless engagement remotely with the same reach as an onsite test. Your team plugs it in; we get to work.

The Raxis Transporter, the plug-and-play device that runs a wireless penetration test remotely

Two Ways to Test Your Wireless

Same senior engineers, same manual tradecraft, same live findings. The difference is when you want us on it: once, for a fixed window, or all year.

What You Get

Written by the engineer who ran the attack, for the team that has to close it. Track findings in real time with Raxis One.

Executive Summary

A concise readout for leadership and auditors.

Technical Findings

Each with a severity rating, reproduction steps, and clear remediation.

Attack Storyboard

The whole path, from the SSID in range to the system we reached.

Included Retest

We verify your fixes and deliver a clean final report, at no extra cost.

Attack from the Company Parking Lot

Our stories are based on real events encountered by Raxis engineers. Some details have been altered or omitted to protect customer identities.

Wireless attackers don’t need to be inside your building, and neither does our team. Sitting in a car in the guest lot, with a large antenna hidden inside it, our pentester got to work.

Using the Aircrack-ng suite to find target SSIDs, he picked the one that looked like the employee network. Then he stood up a rogue access point with Hostapd-wpe, mimicking that SSID, and watched devices connect and hand over their user accounts and NTLM hashes. He fed the hashes to Hashcat, cracked one, and logged in to the real wireless network with the password.

The client had tools that flagged the rogue access point, but by the time the alert surfaced, our pentester was already on the legitimate employee network, looking around. Had their devices been required to check the certificate of the network before joining, none would have connected to our access point in the first place. With the Raxis report in hand, they closed the gap so a real attacker couldn’t do the same.

FAQ: Wireless Penetration Testing

What is wireless penetration testing?

It is a test of your Wi-Fi and the networks behind it, run the way an attacker outside your building would: surveying the access points in range, attacking their encryption and authentication, standing up rogue access points, and measuring what a wireless foothold can reach on your internal network.

What is an evil twin attack?

An evil twin is a rogue access point broadcasting the same name as a network your devices already trust. Many devices, especially with enterprise Wi-Fi that never validates the server certificate, will connect automatically and hand over credentials. It is one of the most reliable ways onto a corporate wireless network, and one of the first things we test.

Do you have to be on site to test our wireless?

Testing needs an antenna within range of your building, but not necessarily our engineers. We often run wireless engagements remotely through the Raxis Transporter, a small device your team plugs in, which gives our testers the same reach as an onsite visit. When onsite testing fits better, we do that too.

Will testing knock our users offline?

We avoid disruptive techniques by default. Some wireless tests use short, targeted deauthentication to capture a handshake; we scope and time those with you, and password cracking happens offline with no effect on your users. Our goal is to prove risk, not to disrupt your network.

Do you test guest and corporate networks?

Both, and the boundary between them is often where the risk lives. Guest networks are meant to stay isolated from production; we test whether a misconfiguration lets an attacker cross from the guest SSID to your internal systems.

How long does a wireless penetration test take?

Most wireless engagements run a few days to a week, including reporting, depending on the number of sites, SSIDs, and whether internal pivoting is in scope. We give you a firm timeline once scope is set.

Who performs the testing?

Senior US-based Raxis engineers holding certifications such as OSCP and OSCE. No outsourcing, and no junior testers learning on your network.

Request a quote

Tell Us What You Need Tested

We usually respond in one business day.

Please let us know what's on your mind. Include any details about your target environment, timeline, or compliance drivers.