Australia Based · Operating Internationally · OSCE / OSCP Certified
☏ 1300 859 443
Wireless penetration testing

Wireless Penetration Testing

Senior-led testing of your Wi-Fi for what it really is — a door into your network an attacker can approach from the car park, the lobby or the building next door. We attack your wireless the way they would, then test what they can reach once inside — and hand you a prioritised, evidence-backed report with a free retest.

  • On-site RF & over-the-air testing
  • WPA2 / WPA3 & 802.1X (EAP) coverage
  • OSCE / OSCP-certified testers
  • Free remediation retest included
Maps to WPA2 / WPA3 802.1X / EAP PCI-DSS 11.3 SOC 2 ISO 27001
Why it matters

Your network perimeter now extends to the car park.

Wi-Fi doesn't stop at your walls — its signal reaches the street, the lobby and the floor above, so an attacker never has to get past reception. A weak pre-shared key, a spoofable SSID or a flat guest network turns a coffee-shop laptop into a foothold on your internal LAN. We test the radio and what sits behind it, the way a real attacker would, before they do.

On-site RF
Tested over the air on location — the only way to prove real wireless exposure and range.
Free
Remediation retest included — we confirm each fix actually holds.
What we test

The radio, the authentication, and the network behind it.

A wireless assessment is only useful if it follows the signal all the way to what it protects — so we test the air, the auth and the pivot, not just a scan of nearby SSIDs.

  • Rogue APs & Evil Twin

    Spoofed access points, captive-portal phishing and forced-deauthentication attacks against your users.

  • WPA2 / WPA3 & PMKID

    Handshake and PMKID capture, offline cracking, and downgrade or KRACK-class weaknesses.

  • 802.1X / Enterprise (EAP)

    PEAP / EAP-TLS configuration, certificate validation and credential-relay weaknesses.

  • Pre-Shared Key

    PSK strength, shared-key reuse and the blast radius of a single leaked passphrase.

  • Client-Side Attacks

    Karma / known-network attacks, probe-request abuse and man-in-the-middle against roaming devices.

  • Guest & Segmentation

    Guest-to-corporate isolation, VLAN hopping and whether wireless can reach systems it shouldn't.

  • Segmentation & Pivot

    What an attacker on the wireless can actually reach on the internal network once associated.

  • Rogue & Shadow Devices

    Unauthorised APs, hotspots and IoT radios extending your attack surface without approval.

How an engagement runs

From site survey to retest — a disciplined, four-phase engagement.

  1. 01

    Scope & site survey

    We agree the sites, SSIDs, in-scope networks and constraints, and plan safe on-site testing windows.

  2. 02

    Recon & capture

    On location we map the RF environment, identify APs and clients, and capture the handshakes we need.

  3. 03

    Manual exploitation

    We hand-test each attack class and, where authorised, pivot from the wireless onto the internal network.

  4. 04

    Report & free retest

    You get a prioritised, evidence-backed report; after you remediate, we retest to confirm every fix — at no extra cost.

What you get

A report your engineers can act on — and your auditors accept.

  • Prioritised findings

    Every issue risk-rated by real business impact and ordered so you fix what matters first.

  • Reproducible evidence

    Step-by-step proof-of-concept per finding — captures, positions and ranges, not vague claims.

  • Developer-ready remediation

    Specific, actionable fix guidance for your network and identity teams, not a generic checklist.

  • Executive summary

    A plain-language overview for leadership, boards and clients requesting assurance.

  • Free remediation retest

    We re-test your fixes and confirm they hold — included with every engagement.

  • Attestation letter

    A summary letter you can share with customers, partners and auditors on request.

Compliance mapping

Evidence that maps to the frameworks you report against.

One engagement, structured so its output slots straight into the assurance work you already have to do.

How this engagement maps to common compliance frameworks
Framework How this engagement maps
PCI-DSS 11.3 & 11.2 Satisfies the wireless penetration-testing and rogue-AP detection requirements for cardholder environments.
SOC 2 Provides the independent pentest evidence auditors expect for the Security trust-services criteria.
ISO 27001 (A.8.20-8.21) Supports the network-security and network-controls requirements in your ISMS.
Essential Eight Evidence for the network-hardening and access-restriction expectations of the ACSC maturity model.
Wireless policy Validates that your wireless security policy holds up under real over-the-air attack.
Common questions

What teams ask before a wireless test.

Does the test have to be done on-site?

Yes — wireless is a radio-frequency attack surface, so we test over the air on location. That's the only way to prove real signal range, rogue-AP exposure and what an attacker within range can actually do.

Do you test WPA3 and 802.1X / enterprise Wi-Fi?

Yes. We cover WPA2 and WPA3, pre-shared-key and 802.1X / EAP (PEAP, EAP-TLS) networks, including certificate validation and credential-relay weaknesses.

Will you try to pivot into our internal network?

Where you authorise it, yes — the real risk of weak Wi-Fi is what it exposes behind it, so we test what an attacker who gets onto the wireless can then reach internally.

Is the testing safe for our users and business?

Yes. We agree rules of engagement and testing windows up front and use controlled, targeted techniques — we don't indiscriminately knock your users offline.

How long does a wireless penetration test take?

Most engagements run a few days per site depending on the number of SSIDs, networks and locations. We confirm timing and travel at scoping.

Can we use the report for PCI-DSS, SOC 2 or ISO 27001?

Yes. The report and optional attestation letter are written to satisfy auditor, customer and PCI wireless-testing requirements.

Do you provide wireless penetration testing across Australia?

Yes — on-site anywhere in Australia, scheduled from our Sydney base. See penetration testing across Australia for coverage, methodology and the engagement process.

Get a scoping call

Get a fixed-price scoping quote.

A senior tester scopes the right engagement and sends a fixed quote — no automated sales funnel, no obligation.

Core Sentinel Contact Form

A senior tester replies personally — no obligation, no automated sales funnel.