Services Methodology Why Us About Us Blog Get in Touch
← Back to Services
// 10 — WIRELESS

Wireless Security
Testing

On-site assessment of Wi-Fi infrastructure covering rogue access points, WPA2/3 attacks, 802.1X weaknesses, and network segmentation failures across corporate and industrial environments.

WPA2/3 AttacksPMKID CaptureEvil Twin802.1X / EAPRogue APsDeauth AttacksGuest NetworkKARMA Attack
Overview

Wireless networks provide a physical-perimeter-bypassing attack vector that is frequently underestimated. A poorly configured Wi-Fi network can allow an attacker in a car park or adjacent building to gain access to internal networks — without ever entering your premises. Our wireless security assessments identify these weaknesses before they can be exploited.

We conduct on-site assessments using specialist wireless hardware to simulate real-world attacker scenarios. This includes corporate SSIDs, guest networks, 802.1X enterprise authentication, rogue access point detection, and client-side vulnerability testing.

Wireless testing is especially important for organisations with warehouses, manufacturing sites, retail locations, or healthcare environments — where operational technology, POS systems, and medical devices often connect over Wi-Fi with minimal security controls.

Testing Methodology
01

Wireless Survey & Enumeration

Comprehensive survey of all wireless networks visible from in-scope locations — SSIDs, BSSIDs, channels, signal strengths, encryption types, and hidden networks. We identify and map out rogue access points, shadow IT wireless infrastructure, and misconfigured corporate SSIDs.

02

Encryption & Protocol Assessment

Identification of weak encryption configurations — WEP, WPA-TKIP, and vulnerable WPA2 implementations. Testing for PMKID attacks and four-way handshake capture against WPA2-PSK networks, and assessment of WPA3 transition mode downgrade weaknesses.

03

Enterprise Authentication (802.1X) Testing

Assessment of EAP implementation quality, certificate validation enforcement, and RADIUS server configuration. Testing for EAP downgrade attacks, rogue RADIUS server deployment, and client misconfiguration that allows credential interception over the air.

04

Evil Twin & Rogue AP Attacks

Deployment of rogue access points mimicking legitimate corporate SSIDs to test client association behaviour and automatic connection controls. Where clients connect, we assess credential and data exposure, including MFA token capture scenarios.

05

Network Segmentation Testing

Assessment of guest network isolation, VLAN segregation effectiveness, and client-to-client communication restrictions. We test whether wireless access grants inappropriate access to internal network segments, management interfaces, or sensitive systems.

06

Client-Side Vulnerability Assessment

Testing of client devices for automatic association with known SSIDs, probe request information disclosure, and susceptibility to deauthentication-based attacks and KARMA/MANA-style rogue AP attacks.

07

Reporting & Remediation

Technical report with RF survey data, attack evidence, and risk-rated findings. Remediation guidance covers controller configuration, RADIUS hardening, certificate deployment, and client supplicant policy recommendations.

What Makes Levantis Different

Wireless testing requires specialist hardware, real on-site presence, and deep expertise in 802.11 protocols. Our experienced operators bring purpose-built wireless attack platforms and conduct testing from realistic attacker positions — car parks, adjacent buildings, and public areas.

We cover the full wireless attack surface — from WPA2 cracking to 802.1X credential interception — and provide findings that your network team can action directly, with specific configuration recommendations for your wireless controller and RADIUS infrastructure.

// Attack Techniques

  • PMKID / Handshake Capture
  • WPA2 Offline Cracking
  • Evil Twin (hostapd-wpe)
  • EAP Credential Interception
  • Deauthentication Attacks
  • Rogue RADIUS Server
  • KARMA / MANA Attacks
  • WPS PIN Brute Force

// Environments

  • Corporate Office Wi-Fi
  • Guest / Public Networks
  • Warehouse & Industrial
  • Healthcare (medical device Wi-Fi)
  • Retail (POS networks)
  • OT / ICS Wireless Segments

// Standards

  • NCSC Wireless Security Guidance
  • PCI DSS Wireless Requirements
  • IEEE 802.11 Standards
  • NIST SP 800-97

// Typical Duration

  • Single site: 2-3 days (depending on size)
  • Multi-site: price on request
  • On-site travel included in scope

// Engage Us

Ready to scope an engagement? Get in touch for a no-obligation conversation.

Get in Touch

Test your wireless perimeter.

Wireless vulnerabilities bypass physical access controls entirely. Our on-site assessments simulate real attacker scenarios from outside your building.

Get in Touch