Offensive security assessments

Wi-Fi Pentesting

Wi-Fi security assessment evaluates the security of wireless networks and their clients to determine whether an attacker within radio range can gain unauthorized access, intercept traffic, or pivot into the internal network. The goal is to validate encryption, authentication, segmentation, and physical signal exposure.

What we assess

Coverage areas included in this engagement. Select a topic for methodology depth and business impact.

TopicSummary
WPA/WPA2 Cracking CheatsheetWe validate this area during scoped assessments, documenting impact and remediation guidance.

How we run it

Documented phases aligned to industry frameworks. Every step produces evidence your engineering team can replay.

Unauthenticated

- Collect details using airodump-ng / Kismet / WiFi Analyzer: SSID, BSSID, channel, encryption type, WPS status - If WPS is enabled → assess WPS exposure; if no

  • Collect details using airodump-ng / Kismet / WiFi Analyzer: SSID, BSSID, channel, encryption type, WPS status
  • If WPS is enabled → assess WPS exposure; if not → proceed with other authentication methods
  • Identify encryption type: Open / WEP / WPA2 / WPA3 (note handshake + authentication type)
  • Check WiFi signal leakage beyond intended physical boundary (office perimeter)
  • Use airodump-ng to monitor target AP and clients; identify active stations
  • Check for captive portal:

If Enterprise Setup (802.1X)

- Identify WPA2/WPA3-Enterprise deployment - Determine EAP method (PEAP / EAP-TLS / TTLS / others) - Validate certificate authentication behavior (trusted / unt

  • Identify WPA2/WPA3-Enterprise deployment
  • Determine EAP method (PEAP / EAP-TLS / TTLS / others)
  • Validate certificate authentication behavior (trusted / untrusted / pinned)
  • Identify RADIUS dependency and authentication flow
  • Assess misconfigurations in enterprise authentication policy
  • Evaluate rogue AP / Evil Twin feasibility (only in authorized scope)

Authenticated (Access to Network Obtained)

- Enable before connecting; inspect traffic (DNS / HTTP / SMB / mDNS / ARP) - Identify internal service discovery protocols (Avahi / mDNS, NetBIOS, SSDP) - Map

  • Enable before connecting; inspect traffic (DNS / HTTP / SMB / mDNS / ARP)
  • Identify internal service discovery protocols (Avahi / mDNS, NetBIOS, SSDP)
  • Map internal devices (printers, IoT devices, smart TVs, Macs)
  • Check VLAN / subnet segmentation between users, servers, and sensitive systems
  • Validate outbound traffic restrictions (DNS / HTTP / HTTPS filtering)
  • Check whether restricted content or services (malicious sites, Tor, etc.) are blocked or allowed

Certification spotlight

Our operators hold industry-recognized offensive security credentials. For this engagement we lean on the certification below.

CompTIA PenTest+ certification badge

Primary certification

PenTest+

CompTIA

Why this matters for your engagement

CompTIA PenTest+ validates hands-on offensive methodology across networks, applications, and cloud targets. We apply this framework to scope, execute, and report findings with reproducible evidence your engineering team can action.

Also held
CompTIA Security+
CompTIA CySA+

Risk areas we cover

High-level risk themes for this engagement. Cards with an arrow open the matching topic page.

What you receive

Every engagement concludes with actionable output your security and engineering teams can operationalize.

Findings report

Documented vulnerabilities with severity ratings, affected assets, and reproducible evidence your team can action.

Remediation guidance

Prioritized recommendations mapped to risk and effort, with clear ownership for engineering and operations teams.

Retest scope

Defined retest window for critical and high findings so you can confirm fixes before auditors or leadership review.

Compliance and trust

Findings are mapped to severity frameworks and can support SOC 2, ISO 27001, HIPAA, and GDPR evidence requests. Review our security practices and subprocessors in the Trust Center.