Offensive security

Wi-Fi Penetration Testing

On-site wireless assessment covering rogue APs, WPA handshake attacks, and guest-network escape.

On-site
Physical RF assessment
WPA2/3
Handshake & PMKID attacks

Security testing

In plain terms Testing

What this is

On-site wireless assessment covering rogue APs, WPA handshake attacks, and guest-network escape.

Why it can hurt you

A guest Wi-Fi network that isn’t actually isolated from corporate is a walk-in attack vector for anyone in the parking lot.

Security testing

Why it matters to you Testing

The problem

A guest Wi-Fi network that isn’t actually isolated from corporate is a walk-in attack vector for anyone in the parking lot.

Physical-proximity risk closed

No walk-in attacker within range gets a foothold.

Guest-network confidence

Visitors get internet, not a path to the domain controller.

Security testing

How we do it Testing

Rogue AP detection

Survey for unauthorized access points and evil-twin setups.

Handshake capture & cracking

WPA2/WPA3 handshake and PMKID attacks against production SSIDs.

Network isolation testing

Verify guest and corporate SSIDs are truly segmented at the switch.

Security testing

What we typically find Testing

Weak pre-shared keys

Dictionary-crackable passphrases on production SSIDs.

Guest network escape

Guest VLAN able to reach internal corporate resources.

Rogue access points

Unauthorized APs bridging into the corporate network.

No scanner dump. A fixed problem.

Every finding is reproduced by hand and comes with a working proof of concept.

Security testing

What lands on your desk Testing

Site survey report

RF map with every access point and its risk rating.

Remediation plan

Configuration fixes prioritized by exposure.

Security testing

What you get out of it Testing

Physical-proximity risk closed

No walk-in attacker within range gets a foothold.

Guest-network confidence

Visitors get internet, not a path to the domain controller.

Security testing

Step by step Testing

1. Rogue AP detection

Survey for unauthorized access points and evil-twin setups.

2. Handshake capture & cracking

WPA2/WPA3 handshake and PMKID attacks against production SSIDs.

3. Network isolation testing

Verify guest and corporate SSIDs are truly segmented at the switch.

Find out what we would find.

A scoping call is thirty minutes, costs nothing, and ends with a fixed price and a date. If we are not the right people for the job, we will tell you that too.