Skip to main content
Home/Services/Wireless Network Penetration Testing
Security Testing

Wireless Network Penetration Testing

Identify vulnerabilities in your wireless infrastructure before attackers do

PCI-DSS SOC 2 HIPAA ISO 27001 NIST 800-53
engagement log Wireless Network Penetration Testing testing
day 01scopetargets confirmed · rules of engagement signedagreed
day 01reconattack surface mappedcomplete
day 02findingWeak WPA2-PSK Passwordscritical
day 03findingRogue or Unauthorized Access Pointshigh
day 04triagereviewed and countersigned by a Lorikeet pentesterpublished
day 04delivertickets opened in your tracker201
afterretestfixes verified · included in scopeno charge
retest included human countersigned report your auditor accepts
3-5 daystypical duration $6,000fixed scope, from 8deliverables 8methodology stages
Scope

What this engagement covers

The service

Our wireless penetration testing assesses the security of your WiFi networks, access points, and wireless client configurations. We identify rogue access points, weak encryption, misconfigured authentication, and attack paths that could allow unauthorized network access.

What we test

We assess your wireless network architecture including WPA2/WPA3 Enterprise and Personal configurations, RADIUS authentication, guest network isolation, rogue access point detection, wireless IDS/IPS effectiveness, Bluetooth exposure, and client-side wireless security. We test from both the perspective of an outsider and a connected guest.

Method

How we run it

We perform passive and active wireless reconnaissance to map your radio environment, identify all access points and SSIDs, and detect rogue or unauthorized devices. We then attempt to crack wireless credentials, bypass captive portals, perform deauthentication attacks, exploit EAP vulnerabilities, and pivot from guest to corporate networks.

01

Passive wireless reconnaissance and SSID mapping

02

Access point enumeration and fingerprinting

03

Rogue access point and evil twin detection

04

WPA2/WPA3 credential attacks

05

EAP and RADIUS configuration testing

06

Guest network segmentation bypass attempts

07

Captive portal security assessment

08

Bluetooth and peripheral wireless scanning

Deliverables

What you receive

Findings land in your tracker as you go, not only in a PDF at the end. Retest is in scope, not a change order.

  • Wireless environment mapping and heat analysis
  • Access point inventory and configuration review
  • Rogue access point detection results
  • Authentication and encryption assessment
  • Guest network isolation test results
  • Wireless client security analysis
  • Captive portal bypass assessment
  • Remediation plan with configuration guidance
Typical results

What we usually find

The issues this engagement surfaces most often. Yours will differ, but this is the shape of it.

Weak WPA2-PSK Passwords Rogue or Unauthorized Access Points Insufficient Guest Network Isolation Missing WPA3 or 802.1X Enterprise Auth Captive Portal Bypass Vulnerabilities EAP Downgrade and Credential Capture VLAN Hopping from Wireless Networks Legacy Protocol Support (WEP, WPA)
Fit

Who this is for

Corporate Office Environments
Retail and Hospitality Businesses
Healthcare Facilities
Educational Institutions
Warehouse and Manufacturing Sites
Any Organization with Guest WiFi
Standards this supports

Findings are mapped to PCI-DSS, SOC 2, HIPAA, ISO 27001, NIST 800-53, so the report drops into an audit package rather than needing to be translated first. If you need the readiness work behind one of those, that is a separate engagement.

Next

Scope it in one call

Tell us what is in scope and we come back with a fixed price and a start date. No discovery-call maze, no hourly estimate that moves.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!