Penetration Testing

Wireless penetration testing that secures the airwaves.

Your wireless networks extend the attack surface beyond your walls. SubRosa tests WiFi infrastructure, protocols, and configurations, plus Bluetooth and RF, so an attacker cannot pivot in over the air.

WiFi · WPA2/WPA3 · Rogue AP · Bluetooth · RF

Wireless penetration testing, defined

What is wireless penetration testing?

Wireless penetration testing assesses the security of your WiFi and other radio-based networks: encryption and authentication (WPA2, WPA3, 802.1X/EAP), rogue and evil-twin access points, network segmentation, and RF technologies like Bluetooth, RFID, and NFC. The goal is to prove whether an attacker within radio range could get onto your network or pivot deeper, and to close the gaps that let them.

What we test

Every wireless vector that matters.

Specialized testing across all the wireless technologies and protocols in your environment.

WiFi security assessment

Encryption analysis, authentication bypass, and configuration review across your enterprise and guest WiFi networks.

Rogue AP & evil twin

Detection and exploitation of rogue and evil-twin access points to validate client behavior and wireless segmentation.

Protocol & enterprise auth

Testing of WPA2 and WPA3, 802.1X, and EAP enterprise authentication for weaknesses that enable unauthorized access.

Bluetooth & RF

Assessment of Bluetooth, RFID, and NFC devices and protocols for flaws in pairing, authentication, and data transmission.

How the engagement runs

From survey to proven access.

A wireless test answers one question: can someone outside your walls reach inside your network. This is how we establish that.

  1. 01

    Scoping and site survey

    We agree sites, networks and whether client-side attacks against staff devices are in scope. Guest networks are included deliberately — they are frequently the weakest segment and frequently assumed to be isolated when they are not.

  2. 02

    Mapping every signal you emit

    We survey from your car park and perimeter, mapping every SSID, its reach beyond your building, encryption in use and hidden or forgotten networks. Organisations are regularly surprised by a legacy access point nobody has owned for years.

  3. 03

    Attacking the authentication

    WPA2 and WPA3 handshakes, PSK strength, and enterprise authentication including certificate validation and credential relay. Weak EAP configuration that accepts an untrusted certificate is one of the most common and most serious findings we report.

  4. 04

    Rogue access point and evil twin

    We stand up a convincing clone of your network and establish whether staff devices connect to it automatically and whether credentials can be captured. This tests device configuration and user behaviour together, which is how the attack actually works.

  5. 05

    What the access reaches

    Getting onto the wireless network is only the finding if it leads somewhere. We test what the wireless segment can reach: whether guest is genuinely isolated, whether corporate wireless lands next to production, and how far lateral movement goes.

  6. 06

    Reporting and retest

    A report with signal maps, the attacks that succeeded, and configuration-level remediation, plus a complimentary retest once changes are made.

Why SubRosa

Into the RF attack surface.

RF-aware testing

We test the full radio attack surface, WiFi, Bluetooth, and RF, not just a WiFi password audit, because that is where attackers actually pivot.

Segmentation focus

We validate that a foothold on wireless cannot become a foothold on the rest of the network, testing segmentation and monitoring end to end.

Real exploitation

We safely exploit what we find to prove real impact and confirm your controls hold, rather than handing you a list of theoretical issues.

Every finding, tracked to closed.

From report to remediation.

Your wireless pen test findings land in Sable, prioritized, assigned, and tracked from open to retested, so remediation becomes a managed workflow instead of a PDF that gets forgotten.

Wireless findings in Sable
Wireless findingsWiFi · RF
  • Critical
    Evil-twin captures corp creds
    WiFi
    Open
  • High
    EAP misconfig allows bypass
    802.1X
    In progress
  • High
    No isolation from corp VLAN
    Guest
    Retested
  • Medium
    Legacy pairing on badge readers
    Bluetooth
    Open
WPA2/WPA3 · 802.1X · RFPrioritized · assigned

Common questions

What is wireless penetration testing?
Wireless penetration testing assesses the security of your WiFi and other radio-based networks: encryption and authentication (WPA2, WPA3, 802.1X/EAP), rogue and evil-twin access points, network segmentation, and RF technologies like Bluetooth, RFID, and NFC. It proves whether an attacker within radio range could get onto your network or pivot deeper.
Do you test more than WiFi?
Yes. Beyond WiFi and enterprise authentication, SubRosa tests the broader RF attack surface, including Bluetooth, RFID, and NFC, and validates that a wireless foothold cannot become a foothold on the rest of the network through weak segmentation.
Do you need to be on site for a wireless test?
For most of it, yes. The assessment starts outside your building — car park, street, neighbouring floors — because the point is establishing what an attacker can reach without entering. Some analysis happens remotely afterwards, but the survey itself has to be physically near your estate.
Is our guest network in scope?
It should be, and it is frequently where the finding is. Guest networks are widely assumed to be isolated from corporate and reasonably often are not, or are isolated in a way that a single misconfigured rule undoes. We test whether the isolation is real rather than taking the design at its word.
Does WPA3 mean we are secure?
It closes several attacks that worked against WPA2 and it is worth deploying. It does not address weak enterprise authentication configuration, devices that connect automatically to a cloned network, forgotten access points nobody owns, or a wireless segment that lands next to production. Those are configuration and architecture problems, and they are what the test is for.
What about Bluetooth and other RF?
In scope where you want them. Bluetooth, and where relevant other RF such as badge and building systems, extend the same principle — signal that leaves your building is attack surface, whether or not it is WiFi.

Secure your networks over the air.

Book a wireless penetration test and find out exactly what an attacker within range could reach, and how to shut it down.